← All posts / Meta

Invisible Thieves: Infostealer Malware Is Draining Claude Subscriptions From Under Users

Hackers are using common infostealer malware to hijack Claude login sessions and silently burn through subscribers' paid token quotas — and Anthropic's usage dashboards can't show victims what was taken.

Invisible Thieves: Infostealer Malware Is Draining Claude Subscriptions From Under Users

On August 4, 2026, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something strange about his Claude Max 20x account. He hadn’t been working that day, yet his token usage was climbing. The next day he disabled everything attached to Claude and left it alone entirely. The consumption kept rising anyway. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” he told TechCrunch.

Something was eating his $200-per-month subscription from the inside. He just couldn’t see what.

The investigation

De Swardt contacted Anthropic and asked for an itemized list of what had consumed his tokens. The company didn’t provide one — but it agreed something was off. It suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his subscription.

The suspension itself wreaked havoc on his business. As a sole proprietor who helps small and mid-size businesses set up AI agents — a kind of forward-deployed engineer for hire, wiring up tasks like automatically loading purchase-order data from emails into accounting software — he runs his entire operation through Claude: daily admin, website design, coding. “Like everything is just running through AI these days,” he said.

After investigating, Anthropic told him it had found the culprit: a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The account, the company said, appeared to have been used by an unauthorized-looking third-party service to handle activity for other people — but it could not determine how that service obtained access. The evidence, Anthropic told him, was consistent either with credentials or session data being taken without his knowledge, or with the account having been connected to an outside service.

In plain terms: a thief had walked through an unlocked door and was quietly siphoning tokens while the meter ran on someone else’s bill.

He was not alone

De Swardt posted his experience on Reddit. Eighty comments later, a pattern emerged. One user claimed their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another watched usage jump from 0 to 49% in twelve minutes after nothing more than a couple of prompts and a web search. A third said their account burned through its maximum tokens every day for three consecutive days without any use at all — and filed a GitHub report that attracted its own chorus of similar stories.

Two of those users shared emails from Anthropic that put a name to the threat. “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the email read.

Infostealers are commodity malware that install themselves on a victim’s computer and harvest saved passwords, session cookies, and login credentials. They are picked up from ordinary places: pirated software, malicious ads, booby-trapped downloads. Crucially, Anthropic told affected users the malware did not come from using Claude itself — the compromise happened on the user’s machine, upstream of the service.

When Anthropic detected suspicious activity, it signed users out, invalidated existing authorizations, issued refunds in some cases, and warned them they might have malware. Notably, De Swardt never received one of those warnings. He insists he found no evidence his computer was compromised, and says he still has no way of knowing how the attacker got in.

The visibility gap

The deeper problem this incident exposes is not any single breach. It’s that account support tracks total usage but not itemized usage — even upon request. A subscriber cannot see what consumed their tokens, only how much is left. That means this kind of theft could run for months without detection, hidden inside a meter that offers no receipt.

De Swardt’s account was reinstated after roughly two weeks, but the experience soured him on the platform. He cancelled his subscription in favor of Cursor, citing its ability to use multiple models — including more affordable open-source options that, in his experience, work about as well. “It’s not that much different or better,” he said of Claude, adding that he can’t see going back “without [Anthropic] actually having resolved the issue in any way.” His verdict on the average user’s position was blunt: “I don’t think there’s any way that these people can protect themselves.”

Asked how users can identify misuse of their accounts, Anthropic declined to comment.

Why this matters beyond Claude

This is the dark side of the subscription-agent era. As AI coding agents and autonomous workflows become the primary interface between developers and compute, the session tokens that authorize them become high-value targets — functionally equivalent to a corporate credit card with no spending alerts. An attacker who hijacks a Claude session doesn’t need to exfiltrate data or deploy ransomware; they simply outsource their own workloads to someone else’s quota.

Three structural weaknesses compound the risk. First, session hijacking bypasses passwords entirely — infostealers grab the already-authenticated cookies, so password strength and even two-factor authentication on login may not help if the session itself is replayable. Second, metering without itemization means anomalies are invisible to the one person paying the bill. Third, agent workloads look legitimate by design: heavy, continuous token consumption is exactly what an earnest power user’s account produces.

For subscribers, the practical takeaways are limited but real: treat any unexplained jump in usage as a potential compromise, not a billing quirk; sign out of all sessions and rotate credentials if consumption moves without activity; and check your machines for infostealer malware, which often arrives via software downloads and malvertising. TechCrunch has published a companion guide on recognizing compromised accounts on popular AI platforms.

For the industry, the lesson is harder. The platforms selling agent compute are becoming infrastructure, and infrastructure gets attacked at the billing layer. Usage dashboards that show only a depleting percentage are no longer adequate — they are the security gap. Until AI accounts offer the equivalent of itemized billing, per-device session revocation, and anomaly alerts, every heavy subscriber is running an account that someone else might quietly be using.

The token theft era has begun quietly. The meters are running; the question is who is reading them.