Anthropic warned Claude users about activity that hijacks saved login sessions on computers, then uses them to create unauthorized OAuth tokens, access accounts, and consume Claude and Claude Code quotas. The warning came after users reported increased consumption despite not running the service.
One case began on August 4, when Grant De Swardt, an independent AI consultant in East Sussex, UK, noticed that his Claude Max 20x account was consuming tokens even though he was not working that day. The following day, he stopped everything linked to the account and also stopped Cowork tasks and disabled cloud execution, but recorded usage increasing from 45% to 55% during a period when he had not run an active local task through Claude Code.
De Swardt contacted Anthropic and requested a detailed usage breakdown, but the company did not provide him with an itemized list. Instead, it suspended the paid account, revoked all existing sessions and Claude Code tokens on the server, and refunded him £44.49 for the remaining period of a subscription costing $200 per month. The company told him that the account appeared to have been used by an unauthorized external service to perform activity on behalf of other people, but it was unable to determine how access had been obtained.
How did the theft happen?
Anthropic later explained that a compromised Claude session key had been used to issue unauthorized Claude Code OAuth tokens. In warning messages sent to other users, the company said that a malicious actor was using common information-stealing malware to copy login sessions from users’ devices, then exploiting them to access accounts and consume quotas.
Information-stealing malware typically steals saved passwords, session data, and credentials. Anthropic said that the malware does not come from using Claude itself, but may reach a device through the download of an infected program or by clicking a malicious advertisement. When suspicious activity was detected, the company logged some users out, revoked existing authorizations, provided refunds to some of them, and warned them that their devices might be infected.
Why does this news matter?
Reported cases reveal a problem that goes beyond password compromise: a valid session can give an attacker the ability to consume a quota as if they were the user. De Swardt published his experience on Reddit, where other users reported usage rising from zero to 49% within 12 minutes, or the daily maximum being consumed for three days without using the service. One user also said that their account was automatically upgraded and their card was charged, according to TechCrunch.
In practice, the absence of a detailed log showing what consumed the tokens, when, and from which session makes theft more difficult to detect, particularly with subscriptions that have large limits. This point is supported by the experience reported by the source, and is not evidence that every unexplained increase in usage is caused by malware.
What remains unresolved?
De Swardt said that he found no evidence that his device had been compromised and that he had not received an explanation identifying how the attackers accessed his account. Anthropic restored his account after about two weeks, but he canceled his subscription and moved to Cursor, noting its support for multiple models. When TechCrunch asked Anthropic for guidance to help users identify abuse, the company declined to comment. Therefore, the mechanisms for verifying usage, the scope of affected cases, and ways to prevent this type of exploitation from recurring remain open questions.