Hackers Are Stealing Claude Max Tokens From Anthropic Subscribers
Hackers are quietly draining Claude Max subscriptions by stealing login sessions with infostealer malware , and victims like U.K.-based AI consultant Gra...

Hackers are quietly draining Claude Max subscriptions by stealing login sessions with infostealer malware, and victims like U.K.-based AI consultant Grant De Swardt say Anthropic's lack of itemized usage tracking let the theft go unnoticed until their $200-per-month token allowances mysteriously vanished. The attacks, detailed in user reports on Reddit and GitHub, expose a growing blind spot across AI subscription platforms: you can track total spend, but not who or what is consuming it. For the thousands of developers, freelancers, and AI tool reviewers now living inside agentic coding platforms, this is a wake-up call about who really controls your API keys, sessions, and monthly budget.
What Is Claude Max and Why Tokens Are Like Cash
Claude Max is Anthropic's premium subscription tier aimed squarely at power users: developers running Claude Code, businesses automating workflows with agents, and solo operators who treat the model like a 24/7 remote employee. At $200 per month for the "20x" plan (with higher tiers costing more), users get a large pool of tokens, the metered "fuel" every Claude request burns.
Image: Token theft exploits invisible session keys, not just passwords.
Claude Code, meanwhile, is Anthropic's agentic coding tool that lets AI autonomously edit files, run commands, and handle multi-step tasks. Here's the critical detail: Claude Code doesn't just use your password. It uses OAuth tokens and session keys minted when you log in, which are stored on your machine and exchanged silently in the background.
- Tokens are currency: Every prompt, code edit, and background agent task burns tokens from your monthly cap.
- Sessions are the keys to the vault: Steal a valid session and you don't need the password at all.
- Third-party connections multiply risk: Linking accounts to external services like cloud runners or dispatch tools expands the attack surface.
This architecture is powerful, but it also means a compromised laptop can hand a stranger a fully authenticated, cash-loaded account.
The Core News: How Claude Tokens Get Stolen
The incident began on August 4, when De Swardt noticed his Claude Max 20x account consuming tokens while he wasn't working. The next day, he disabled every integration attached to Claude, paused scheduled Cowork tasks, turned off Dispatch/cloud execution, and closed active Claude Code sessions. Usage still climbed from 45% to 55%.
Image: Agentic AI tools run autonomously, making unauthorized usage hard to spot.
Anthropic eventually confirmed the cause: a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. In emails shared by other victims, Anthropic warned that "a bad actor is using common infostealer malware to steal Claude login sessions from people's computers." Infostealers are a class of malware that silently harvest saved passwords, cookies, and session data, often picked up from cracked software, infected ads, or malicious downloads.
Victims report a consistent pattern:
- One Reddit user said their account was "auto-upgraded without my consent," their card charged, and usage jumped from 0% to 100% without them touching the account.
- Another watched usage climb from 0 to 49% in 12 minutes after only a couple of prompts and a web search.
- A third burned through max tokens every day for three days without using Claude at all, then filed a GitHub report where more users piled in with similar stories.
Anthropic's response, where it caught the activity, was to sign users out, invalidate existing authorizations, issue partial refunds, and warn about potential malware. De Swardt received a £44.49 partial refund for unused time, but his account stayed suspended for roughly two weeks — a business-killing delay for a sole proprietor running his entire operation on agents.
Why This Matters: The Stakes for AI Power Users
This isn't just one consultant's bad month. It exposes a structural weakness in how AI platforms report usage and how users can (or can't) defend themselves.
| Issue | The Problem | The Result |
|---|---|---|
| Usage transparency | Support tracks total tokens but no itemized breakdown by session, device, or app | Theft can run for weeks or months unnoticed |
| Session persistence | OAuth tokens and session keys stay valid on compromised machines | Infostealers get a free, authenticated pass |
| Autonomous agents | Claude Code, Cowork, and Dispatch run without user supervision | Unauthorized activity blends in with legitimate automation |
| Account recovery | Investigation and reinstatement took ~2 weeks | Freelancers and startups lose revenue while waiting |
| Malware vector | Infection comes from outside Claude, often via third-party tools | Users blame the platform but the entry point is their own device |
Image: The best defense is still device-level hygiene, not just platform features.
The deeper stakes: trust in agentic AI billing. As Claude, ChatGPT, and Gemini push autonomous agents that "work while you sleep," users need granular auditing to distinguish their own automation from a thief's. Right now, De Swardt argues, "there's no way that these people can protect themselves" — and Anthropic declined to explain how users can identify misuse.
Key Details: Technical Breakdown
How the attack chain works
- Infection: Malware lands on the victim's machine via a pirated tool, malvertising, or a poisoned download.
- Harvesting: The infostealer extracts saved passwords, browser cookies, and stored Claude session data.
- Token minting: The attacker uses the stolen session to generate valid Claude Code OAuth tokens server-side.
- Siphoning: The account is used as a proxy service to handle AI activity for the attacker's other clients or projects.
- Discovery: The victim notices token burn without any work of their own, then fights for an itemized explanation.
The transparency gap
De Swardt asked Anthropic for an itemized list of what consumed his tokens. The company didn't provide one. That's the crux: without per-session or per-device breakdowns, a user burning 55% of their allowance cannot distinguish a runaway agent from a hijacker.
What Anthropic did right and wrong
- Right: It identified suspicious activity in several cases, proactively emailed affected users, invalidated tokens, and issued refunds.
- Wrong: It didn't catch or flag De Swardt's case with the same warning, gave no itemized usage data, and took weeks to restore service.
Competitive Landscape: Security as a Differentiator
Anthropic is not alone in facing credential theft, but the response to it is becoming a competitive battleground for AI subscription platforms.
| Platform | Reported Token Theft | Usage Visibility | Key Defense |
|---|---|---|---|
| Anthropic Claude | Yes (session-key theft via infostealers) | Weak: total usage only | Session invalidation and refunds after the fact |
| OpenAI ChatGPT | Yes (credential stuffing, API key leaks) | Moderate: per-project API dashboards | Org-level API key monitoring and alerts |
| Google Gemini / Vertex | Yes (API key exposure in code) | Strong: per-key dashboards in Cloud Console | IAM-based key rotation and budgets |
| Cursor | Not the target of this campaign | Varies by model backend | Multi-model flexibility so users aren't locked in |
Image: Session tokens stored in browser and CLI profiles are prime malware targets.
The biggest casualty here may be Anthropic's lock-in argument. De Swardt's response is telling: he switched to Cursor, which lets him route through multiple models, including cheaper open-source options. His verdict — that competing models work "not that much different or better" — shows that a security scare plus poor transparency can erase a loyalty built on model quality.
What This Means for AI-Tool and AI-News Publishers
This story is a gift to anyone writing about AI tools, because it touches billing, security, agentic workflows, and vendor lock-in all at once. Here are concrete angles to pursue:
- Tutorial: How to audit your Claude or ChatGPT token usage today. Walk readers through checking usage dashboards, reviewing active sessions, and spotting anomalies. This targets the panic search spike around this story with a genuinely useful, evergreen resource.
- Buyer's guide: Best practices for securing AI subscriptions. Compare Anthropic, OpenAI, Google, and Cursor on session management, itemized billing, refund policies, and malware response. Include a comparison table like the one above; it's highly embeddable.
- SEO keyword targets: "Claude tokens stolen," "Anthropic account hacked," "Claude Max worth it," "infostealer malware AI accounts," and "how to check Claude token usage." Each maps to a different post.
- Opinion piece: "Your AI subscription is a honeypot." Argue that as AI plans become prepaid compute credits, they become prime targets for criminals needing free compute — and platforms must treat them like bank accounts, with transaction-level logs.
- Newsletter tie-in: Frame this as part of a broader series on "the hidden costs and risks of agentic AI," linking Claude Code token theft to cloud-account hijacking and crypto-wallet drain attacks for a compelling through-line.
- Tool roundup: Review security utilities (password managers, endpoint scanners for infostealers, browser session cleaners) specifically tuned for AI power users, with affiliate-friendly comparisons.
Challenges Ahead: Risks and Unresolved Problems
- No itemized billing: Anthropic still won't show users exactly what consumed their tokens, making detection reactive rather than preventive.
- Silent malware infections: Victims like De Swardt found no evidence their machines were compromised, meaning the entry point may be invisible to standard antivirus scans.
- Slow incident response: A two-week account suspension can be catastrophic for a solo operator whose entire business runs on agents.
- Refund inconsistency: Some users got proactive emails and refunds; others had to fight for partial compensation.
- Trust erosion across the category: If users can't trust usage meters, adoption of expensive agentic plans (which rely on unattended operation) will slow.
- Attribution gap: Anthropic itself couldn't determine how the attacker obtained access, highlighting how hard session theft is to trace after the fact.
Final Thoughts
The Claude token theft story isn't really about one malware family — it's about the mismatch between agentic ambition and legacy billing transparency. AI platforms are asking users to hand over $200 a month and autonomous control of their workflows, but they still track spending like a phone bill, not like a bank statement. Whoever ships real-time, itemized, per-session usage monitoring first won't just win a security feature race; they'll win the trust of every developer who currently has no idea what their AI is doing at 3 a.m.
FAQ
How are hackers stealing Claude tokens?
Attackers use infostealer malware that silently grabs saved passwords, browser cookies, and Claude session data from infected computers. Those stolen sessions are then used to mint unauthorized Claude Code OAuth tokens and siphon the victim's monthly token allowance.
How can I tell if my Claude account is being drained?
Watch for token usage climbing when you aren't working, sudden "auto-upgrades" or card charges, and usage spikes of 40-50% after minimal activity. The catch: Anthropic currently provides total usage only, not itemized per-session data, so anomalies are hard to trace.
Who is most at risk from these attacks?
Anyone running Claude Code or connecting third-party services is exposed, but the highest risk falls on freelancers, consultants, and startups who install many tools, click through integrations, and run agents unattended — especially those who've downloaded unofficial software.
What did Anthropic do for affected users?
In confirmed cases, Anthropic signed users out, invalidated existing authorizations and server-side tokens, issued partial refunds (De Swardt got £44.49 of his $200 plan), and warned them they may have malware. But responses were inconsistent, and reinstatement took around two weeks.
What should I do to protect my Claude or AI subscription?
Treat your device as the front line: avoid pirated software, use a reputable endpoint security tool, clear stored sessions regularly, revoke unused OAuth connections, enable any available two-factor authentication, and check your usage dashboard daily if you run agents.
Will AI platforms improve usage transparency because of this?
Pressure is building, but there's no announced timeline. Competitive pressure from rivals like Cursor and OpenAI's per-project dashboards may force Anthropic to ship itemized usage tracking faster than it otherwise would — making transparency a key feature to watch in the next release cycle.

