, , ,

Silent Token Theft: How Hackers Are Siphoning Claude AI Subscriptions

Artificial intelligence subscribers are facing a new cybersecurity threat as hackers target high-value API and session tokens. Grant De Swardt, an independent AI consultant based in East Sussex, U.K., recently discovered his premium Claude Max subscription was hemorrhaging tokens despite being completely idle. After disabling all connected integrations and local tasks, De Swardt watched his token consumption climb from 45% to 55% in a controlled test. Upon contacting Anthropic, the AI developer confirmed anomalous activity, suspended his $200-per-month account, and issued a partial refund, leaving the consultant’s business operations in temporary disarray.

Anthropic’s subsequent investigation revealed that a compromised session key had been used to generate unauthorized Claude Code OAuth tokens. The company suggested the account was likely utilized by an unauthorized third-party service to route activity for other users. This is not an isolated incident. Numerous Claude subscribers on platforms like Reddit and GitHub have reported identical experiences, with some witnessing their usage metrics spike from zero to maximum capacity within minutes, or finding their accounts automatically upgraded and charged without consent.

In correspondence sent to affected users, Anthropic attributed the security breaches to “infostealer” malware. This malicious software infects users’ local machines through compromised downloads or malicious advertisements, harvesting saved passwords and active session data. While Anthropic took steps to force logouts and invalidate compromised credentials, the lack of itemized usage logs has drawn criticism. Users argue that without detailed transaction histories, token theft can go unnoticed for months.

The disruption has prompted some professional users to abandon the platform entirely. De Swardt, whose business relies heavily on AI agents for administrative and coding tasks, migrated his workflow to Cursor, an alternative coding environment that supports multiple models, including open-source options. The incident highlights a growing vulnerability in the AI ecosystem, where session tokens are highly prized commodities on the digital black market, and developers currently lack the granular monitoring tools to help users protect themselves.

Key Takeaways

  • Bad actors are using infostealer malware to hijack active Claude login sessions and drain subscribers' token allowances.
  • Anthropic currently lacks granular, itemized usage tracking, making it difficult for users to detect token theft until significant usage spikes occur.
  • The security vulnerabilities and subsequent account suspensions have disrupted businesses, driving some professionals to switch to multi-model alternatives like Cursor.

Editor’s Analysis & Impact

The rise of token theft highlights a critical security gap in the rapidly expanding AI-as-a-Service (AIaaS) sector. As premium AI models become central to business operations, session tokens have evolved into high-value targets for cybercriminals looking to bypass subscription fees or power unauthorized third-party applications. Anthropic’s reliance on broad session invalidation rather than granular, user-facing security logs exposes a lack of maturity in enterprise-grade security features. To maintain user trust, AI developers must implement robust multi-factor authentication, detailed usage telemetry, and real-time anomaly detection. Until these platforms offer itemized billing and usage transparency similar to traditional cloud infrastructure providers, professional users will remain vulnerable to silent resource draining, potentially driving a shift toward self-hosted, open-source alternatives where security boundaries are easier to control.

Frequently Asked Questions

Q: How are hackers stealing Claude tokens?
A: Hackers are utilizing 'infostealer' malware, which infects users' computers via compromised software downloads or malicious online ads. Once installed, the malware harvests active browser session data and login credentials, allowing unauthorized access to the user's Claude account.

Q: What are the signs that an AI subscription has been compromised?
A: The primary indicator is an unexpected spike in token usage or account activity when the user is idle. Other signs include unauthorized account upgrades, unexpected credit card charges, or being suddenly logged out of active sessions.

Q: How can users protect their AI accounts from token theft?
A: Users should run regular malware scans on their local machines, avoid downloading unverified software, and clear active browser sessions periodically. Additionally, utilizing secure password managers and monitoring account usage dashboards daily can help detect anomalies early.

AI Disclosure: This article is based on verified data and official reports. Our Team and AI have cross-referenced every financial detail with primary sources to ensure total accuracy.