Hackers are draining Claude subscribers' AI tokens using stolen session cookies

By: Anton Kratiuk | today, 01:08

If you pay for a Claude Max subscription, your account could be quietly drained by hackers — even if your password is strong and two-factor authentication is switched on. A case first reported by TechCrunch shows the attack is real, the refund is partial, and Anthropic still can't tell you exactly how it happened.

The attack

Grant De Swardt, an independent AI consultant in East Sussex, noticed on August 4 that his Claude Max 20x account was burning through tokens on a day he hadn't touched the service. Disabling all connected tools the next day made no difference — consumption kept climbing. He contacted Anthropic, which suspended his account, wiped active sessions and Claude Code server tokens, and issued a £44.49 refund against his $200-per-month subscription. After roughly two weeks offline, the account was reinstated. He cancelled anyway.

Anthropic's investigation found that a compromised session key had been used to generate unauthorized Claude Code OAuth tokens. The company could not determine how attackers first got hold of that key, but pointed to credential theft or a compromised third-party service connection as likely routes.

The mechanism is a class of malware known as infostealers — tools like LummaC2, StealC, and RedLine that silently harvest browser session cookies, saved passwords, and other credentials from an infected device. As Malwarebytes explains, stealing an active session cookie lets attackers impersonate a logged-in user without ever knowing the password or triggering an MFA prompt. The session remains valid until explicitly revoked.

After De Swardt posted about the incident on Reddit, other Claude subscribers reported similar spikes in token usage they couldn't account for. In one case, 49% of a monthly token allowance was consumed in just 12 minutes.

The visibility gap

The harder problem is detection. Anthropic does not provide itemized usage logs — there's no per-request breakdown showing when tokens were used, from which IP, or for what task. That makes it nearly impossible to spot unauthorized consumption before it's too late, and difficult to prove it afterward. Competitors like OpenAI offer more granular usage dashboards, a gap that puts pressure on Anthropic to improve transparency for paying subscribers.

Anthropic has stressed that the malware itself is unrelated to Claude — it can arrive via infected software downloads or malicious ads on any site. The company notified some affected users directly, but the full scale of the campaign remains unknown.

What to do now

Check your Claude usage dashboard for unexplained spikes. If anything looks off, contact Anthropic support immediately and revoke active sessions. On the device side, run a malware scan — free tools from Malwarebytes or Windows Defender are a reasonable starting point. Avoid installing software from unverified sources, and treat browser-saved credentials as a risk even when MFA is enabled.