Hackers Are Stealing Claude Subscribers’ AI Tokens

Stolen browser cookies let attackers drain Claude Max accounts in minutes, exposing a gap in Anthropic’s usage transparency tools

Annemarije de Boer Avatar
Annemarije de Boer Avatar

By

Image: Flickr – Blogtrepreneur

Key Takeaways

Key Takeaways

  • Infostealer malware steals browser session cookies, minting OAuth tokens to drain Claude subscriptions.
  • One hijacked Claude account hit 49% usage consumed in just 12 minutes.
  • Anthropic lacks itemized usage logs, leaving subscribers unable to detect or prove token theft.

Grant de Swardt noticed something wrong the way you notice a gas leak — slowly, then all at once. His Claude Max 20x subscription was burning through usage while he wasn’t working. According to TechCrunch, Anthropic eventually told him a compromised session key had been used to mint unauthorized Claude Code OAuth tokens. His account had been effectively handed to a stranger. Not because Anthropic got breached. Because his machine did.

How a Stolen Cookie Becomes a Spare Key

Infostealer malware doesn’t need your password — it just needs the session your browser already saved.

Modern infostealer malware skips the front door entirely. It targets browser session cookies — the tokens that keep you logged in after authentication. Think of OAuth tokens as spare keys cut from a stolen master: one compromised session becomes a credential factory. Anthropic confirmed to affected users, as reported by TechCrunch and Malwarebytes, that bad actors used this exact mechanism to access Claude accounts and consume paid usage without detection, much as password vaults have been targeted through similar credential-theft exploits.

The documented damage:

  • At least one account went from 0% to 100% usage automatically; another hit 49% in 12 minutes
  • Anthropic’s response included signing users out, invalidating authorizations, removing saved payment methods, and issuing partial refunds
  • Anthropic confirmed the malware originated on users’ endpoints — not inside Claude’s systems
  • De Swardt’s account was reinstated, but he canceled his subscription anyway

“He had no way of determining how hackers gained access,” TechCrunch reported, “and did not think users had enough tools to protect themselves.”

The Structural Problem Isn’t Malware

When you can’t see what consumed your tokens, detecting theft is pure guesswork.

Infostealer malware is a known and well-documented threat. The deeper issue here is transparency. Anthropic reportedly tracks total usage but, according to TechCrunch, cannot provide fully itemized breakdowns on request. Imagine your credit card statement showing only a monthly total — no line items, no timestamps, no merchant names. That’s the diagnostic tool subscribers currently have.

Trust, once broken quietly, is loud to rebuild.

AI providers will face growing pressure to build session activity logs, anomaly detection, and line-by-line usage reporting, raising concerns similar to apps caught secretly tracking users without awareness. Professional subscribers — the ones running Claude Code automations and paying for Max tiers — cannot absorb that ambiguity. The Register reported on Anthropic moving to crack down on hijacked accounts, but the structural tooling gap remains unresolved.

Subscribers are advised to:

  • Scan their devices for infostealer malware
  • Audit active Claude sessions
  • Monitor usage dashboards regularly

AI subscriptions are high-value targets. The security tooling around them hasn’t caught up yet.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →