Urgent.News

What's breaking now, across thousands of outlets.

AI

Hackers are stealing Claude tokens from subscribers

Last month, a Claude user noticed his account was consuming tokens even though he wasn't working. Anthropic has since warned users about hackers.

On August 4, Grant de Swardt, an AI consultant from East Sussex, UK, observed an unusual spike in token usage within his Claude Max 20x account, despite not having been actively using the platform. The next day, the token consumption continued to rise despite de Swardt disengaging all attachments and not interacting with Claude.

In his words to TechCrunch, "In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task." De Swardt sought clarification from Anthropic, the company behind Claude.

The corporation did not furnish a detailed usage breakdown but acknowledged there was an issue. Anthropic suspended de Swardt's paid subscription, invalidated all active sessions and server-side Claude Code tokens, and provided a partial refund of £44.49 for the remainder of his $200-per-month subscription. This incident resulted in significant disruption to de Swardt's business, which involves helping small and mid-sized companies establish AI agents for various tasks.

The root cause, Anthropic determined, was a compromised Claude session key being utilized to generate unauthorized Claude Code OAuth tokens. The company could not ascertain how the unauthorized access occurred, indicating it may have been due to credentials/session data theft without de Swardt's knowledge or the account being connected to an external service.

The suspension of de Swardt's account caused considerable business disruption. After a two-week period, his Claude account was reinstated, but the lack of a swift resolution and an itemized usage log left de Swardt dissatisfied with Claude. He opted for Cursor, which offers multiple models at more affordable prices, including open-source alternatives.

De Swardt found the experience with Claude to be inconsistent, with some users reporting sudden and unauthorized token consumption. Anthropic addressed this issue by identifying a malicious actor using infostealer malware to steal login sessions and access Claude accounts.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techcrunch.com →

More in AI

More from Tuesday 8 September →