//
News / Law

Claude AI Users Hit by Token Theft: Security Flaws Expose Subscription Vulnerabilities

Q
qnews24h
Pham Van Quynh
September 9, 2026 Updated September 9, 2026 0 views· 11 min read
Claude AI Users Hit by Token Theft: Security Flaws Expose Subscription Vulnerabilities
Ảnh minh họa cho bài viết: Claude AI Users Hit by Token Theft: Security Flaws Expose Subscription Vulnerabilities Source: techcrunch.com
Quick summary
  • Multiple users of Anthropic's Claude AI, including an independent consultant, have reported unexplained and unauthorized high token usage on their accounts.
  • Anthropic has confirmed that compromised Claude session keys and the use of infostealer malware are enabling hackers to access accounts and siphon off paid tokens.
  • The absence of itemized usage tracking for Claude accounts makes it nearly impossible for users to detect or diagnose token theft, hindering early intervention.
  • The incidents are causing business interruptions for AI-reliant professionals and pushing some users to cancel subscriptions in favor of platforms offering greater transparency...

Imagine waking up to discover your digital assistant has been working overtime, but not for nefarious purposes directly benefiting you. This unsettling reality has gripped numerous subscribers to Anthropic’s Claude AI service, who are reporting a disturbing pattern of unauthorized token consumption and account breaches, leading to significant financial losses and operational disruptions in an increasingly AI-driven economy.

Quick summary

  • Multiple users of Anthropic's Claude AI, including an independent consultant, have reported unexplained and unauthorized high token usage on their accounts.
  • Anthropic has confirmed that compromised Claude session keys and the use of infostealer malware are enabling hackers to access accounts and siphon off paid tokens.
  • The absence of itemized usage tracking for Claude accounts makes it nearly impossible for users to detect or diagnose token theft, hindering early intervention.
  • The incidents are causing business interruptions for AI-reliant professionals and pushing some users to cancel subscriptions in favor of platforms offering greater transparency and security controls.

Why it matters

The unauthorized theft of AI tokens from services like Claude carries profound implications beyond individual financial losses. For the burgeoning ecosystem of AI-driven businesses, particularly small and mid-sized enterprises, it represents a direct threat to operational continuity and solvency. Many professionals, acting as 'forward-deployed engineers,' integrate AI agents deeply into their daily workflows, from automating administrative tasks to complex coding and data processing. A sudden, untraceable depletion of their AI resources can paralyze operations, destroy client trust, and force costly, time-consuming migrations to alternative platforms.

More broadly, this issue erodes trust in the security posture of leading AI platforms during a critical phase of mass adoption. As AI services become foundational infrastructure, users expect robust protection for their digital assets and clear visibility into resource consumption. The lack of itemized usage tracking, as highlighted by these incidents, represents a significant transparency gap that leaves users vulnerable and disempowered. This creates a critical challenge for AI providers to balance rapid innovation with stringent security and user-centric accountability, influencing user adoption rates and potentially shaping regulatory discussions around digital asset protection in the AI era.

Background

The rapid advancement and widespread adoption of generative AI models like Anthropic's Claude, alongside competitors such as OpenAI's ChatGPT, have ushered in a new paradigm for digital work and innovation. Businesses and individual professionals are increasingly integrating sophisticated AI agents into every facet of their operations, from customer service automation to software development and data analysis. This shift has given rise to a 'token economy' where access to these powerful models is typically monetized through subscription plans that allocate a certain number of computational 'tokens' for usage. These tokens represent the processing power and data exchanged with the AI, becoming a valuable digital commodity.

Historically, digital services have grappled with credential theft and account hijacking. However, the deep integration of AI into critical workflows means that the compromise of AI accounts has more immediate and far-reaching consequences than, for example, a compromised email account. Before these recent incidents, the industry was already keenly aware of the need for robust API key management and secure session handling, especially as AI systems began interacting with sensitive data and performing autonomous actions. The current wave of token theft underscores that despite these concerns, the security mechanisms around session data and usage transparency have not kept pace with the increasing value and criticality of AI resources, setting the stage for the vulnerabilities now being exploited by malicious actors.

Qnews24h insight

The recent wave of Claude AI token thefts signals a growing pains scenario for the rapidly expanding artificial intelligence industry, exposing a critical disconnect between the advanced capabilities of AI models and the foundational security and transparency features offered to users. Anthropic's response, while offering partial refunds and session invalidations to some, appears reactive rather than proactively preventative. The core issue lies not just with external threats like infostealer malware, which are pervasive across the internet, but with the internal lack of granular usage visibility within the platform itself. Without itemized logs, users are left in the dark, unable to identify rogue processes or compromised integrations, effectively operating blind in an environment where their digital currency is being silently siphoned away.

This situation creates a significant 'trust deficit' at a crucial juncture for AI adoption. As AI transitions from a niche technology to an essential business utility, platforms must prioritize user protection and empower them with diagnostic tools. The current opacity around token consumption is unsustainable; it not only impacts user finances but also undermines confidence in the reliability and security of these powerful, yet vulnerable, digital tools. The market's response, as evidenced by users seeking alternatives, will likely push for a new standard of transparency and accountability from all major AI service providers, making such incidents a litmus test for long-term industry viability.

Independent Consultant's Alarming Discovery

The problem first came to light for Grant De Swardt, an independent AI consultant based in East Sussex, U.K., in early August. De Swardt, who relies heavily on Anthropic's Claude Max 20x for his business, observed an anomalous surge in token usage despite not actively working with the AI that day. The following day, with all his Claude integrations and scheduled tasks explicitly disabled, the unauthorized consumption persisted. He recounted to TechCrunch that in a 'clearest controlled interval,' his usage climbed from 45% to 55% with no corresponding legitimate activity, confirming a clandestine operation draining his account.

Anthropic's Investigation and Initial Resolution

Perplexed, De Swardt sought an itemized usage report from Anthropic, a request the company could not fulfill. However, after reviewing his case, Anthropic acknowledged the unusual activity, suspended his paid account, invalidated all associated sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 from his $200-per-month subscription. The company subsequently informed him that the culprit was a compromised Claude session key, which had been used to 'mint unauthorized Claude Code OAuth tokens.' While Anthropic suspected a 'third-party service' was involved, the precise method of access for De Swardt remained undetermined, leaving open possibilities of either stolen credentials/session data or a connection to an unauthorized external service.

Business Disruptions and Wider Reports Emerge

For De Swardt, the account suspension inflicted considerable damage on his business, which revolves around setting up AI agents for small and mid-size companies. These agents automate critical functions, from loading purchase-order data into accounting software to handling daily administrative tasks, website design, and coding. 'Everything is just running through AI these days,' he emphasized, underscoring his deep reliance on the platform.

His experience was far from isolated. After De Swardt shared his ordeal on Reddit, dozens of users corroborated similar issues. One user reported an unauthorized auto-upgrade and a credit card charge, with usage skyrocketing from 0% to 100% without interaction. Another witnessed usage jump from 0% to 49% in mere minutes after minimal legitimate activity. A separate GitHub report detailed accounts burning through their maximum tokens daily for three consecutive days without user engagement, attracting more similar complaints.

The Role of Infostealer Malware

In some cases, Anthropic proactively identified the issue and alerted users directly via email. These communications warned that 'a bad actor is using common infostealer malware to steal Claude login sessions from people’s computers,' subsequently leveraging these sessions to access accounts and consume usage. Infostealers are a pervasive type of malware designed to pilfer saved passwords, session data, and other login credentials from a user's device, often acquired by downloading infected software or clicking malicious advertisements.

Anthropic clarified that the malware itself did not originate from using Claude. In these confirmed cases, the company signed users out, invalidated existing authorizations, issued refunds, and advised users to scan their systems for malware. Notably, De Swardt did not receive such an email and maintains he found no evidence of his computer being compromised, intensifying the mystery around how his account was breached.

Transparency Gap Fuels User Frustration

A central point of contention for affected users, including De Swardt, is Anthropic's inability or unwillingness to provide itemized usage logs. This lack of transparency means that even if a user suspects unauthorized activity, they have no granular data to pinpoint the source of consumption. This opacity allows token theft to persist undetected for extended periods, exacerbating financial losses.

De Swardt's Claude account was eventually reinstated after a two-week hiatus. However, the arduous process of seeking support combined with the persistent lack of usage insights ultimately led him to cancel his subscription. He has since migrated to Cursor, a platform that supports multiple AI models, including more cost-effective open-source options, offering him greater control and visibility. 'It’s not that much different or better,' he stated, expressing his reluctance to return without Anthropic fundamentally resolving the transparency issue. When TechCrunch sought comment on tools for users to identify misuse, Anthropic declined to respond, leaving users to grapple with ongoing uncertainty.

Sources

FAQ

What are Claude AI tokens and why are they valuable?

Claude AI tokens represent the units of computational processing and data exchange consumed when interacting with Anthropic's AI models. They are valuable because they are the currency used to access advanced AI capabilities for tasks like content generation, coding assistance, and data analysis. Subscribers purchase these tokens, typically as part of a monthly plan, to power their AI-driven applications and workflows.

How are hackers gaining access to Claude accounts and stealing tokens?

Hackers are primarily gaining access through two confirmed methods: exploiting compromised Claude session keys and deploying infostealer malware. Session keys, which authenticate a user's current login, can be stolen, allowing unauthorized parties to impersonate the legitimate user. Infostealer malware, often acquired through malicious downloads or ads, specifically targets and exfiltrates saved passwords, login credentials, and active session data from a user's computer.

What steps can users take to protect their Claude AI subscriptions from theft?

To protect their subscriptions, users should implement strong cybersecurity practices, including using unique, complex passwords, enabling multi-factor authentication (if available), and being vigilant about phishing attempts. Regularly scanning their computers for malware, avoiding suspicious downloads, and keeping software updated are also crucial. While Anthropic currently lacks itemized usage logs, users should closely monitor their overall token consumption for any unexplained spikes and report suspicious activity immediately to customer support.

Why it matters

The unauthorized theft of AI tokens from services like Claude carries profound implications beyond individual financial losses. For the burgeoning ecosystem of AI-driven businesses, particularly small and mid-sized enterprises, it represents a direct threat to operational continuity and solvency. Many professionals, acting as 'forward-deployed engineers,' integrate AI agents deeply into their daily workflows, from automating administrative tasks to complex coding and data processing. A sudden, untraceable depletion of their AI resources can paralyze operations, destroy client trust, and force costly, time-consuming migrations to alternative platforms. More broadly, this issue erodes trust...

Background

The rapid advancement and widespread adoption of generative AI models like Anthropic's Claude, alongside competitors such as OpenAI's ChatGPT, have ushered in a new paradigm for digital work and innovation. Businesses and individual professionals are increasingly integrating sophisticated AI agents into every facet of their operations, from customer service automation to software development and data analysis. This shift has given rise to a 'token economy' where access to these powerful models is typically monetized through subscription plans that allocate a certain number of computational 'tokens' for usage. These tokens represent the processing power and data exchanged with the AI,...

Qnews24h perspective

The recent wave of Claude AI token thefts signals a growing pains scenario for the rapidly expanding artificial intelligence industry, exposing a critical disconnect between the advanced capabilities of AI models and the foundational security and transparency features offered to users. Anthropic's response, while offering partial refunds and session invalidations to some, appears reactive rather than proactively preventative. The core issue lies not just with external threats like infostealer malware, which are pervasive across the internet, but with the internal lack of granular usage visibility within the platform itself. Without itemized logs, users are left in the dark, unable to...

References

Editorial information

XH
Qnews24h Editorial Team
Editorial desk

The editorial team reviews sources, adds context, and structures stories so readers can understand the news more clearly.

Article from QNEWS24H

Share:

Comments

(0)
User
You need to sign in to comment.
0/500

No comments yet. Be the first to share your thoughts.