Hackers are using infostealer malware to hijack Claude subscribers' login sessions and quietly burn through their token allowances, Anthropic has confirmed in warning emails sent to affected users. The scheme targets paid Claude Max accounts — including the $200-per-month 20x tier — by stealing session data from users' computers and then minting unauthorized Claude Code OAuth tokens against them. Because Anthropic's account support tracks total usage but not itemized usage, the theft can run undetected for months.
Grant De Swardt, an independent AI consultant in East Sussex, U.K., surfaced the pattern after noticing his Claude Max 20x usage climbing on August 4 while he was not working. The next day he disabled every integration attached to Claude and did not touch the tool. Consumption still rose.
“In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task.”— Grant De Swardt, Independent AI consultant
De Swardt contacted Anthropic and asked for an itemized breakdown of what was consuming his tokens. Anthropic could not provide one but agreed the activity was anomalous. It suspended his paid account, invalidated all sessions and server-side Claude Code tokens, issued a £44.49 partial refund for the remaining time on his subscription, and later told him a compromised session key had been used to mint unauthorized OAuth tokens.
Key facts
- 01Anthropic confirmed infostealer malware is stealing Claude login sessions and using them to mint unauthorized Claude Code OAuth tokens.
- 02One Max 20x subscriber watched token usage climb from 45% to 55% on August 5 while doing no work with the tool disabled.
- 03A separate user reported usage jumped from 0 to 49% in 12 minutes after only a couple of prompts and a web search.
- 04Anthropic suspended affected accounts, invalidated sessions, and issued partial refunds — one user received £44.49 against a $200/month subscription.
- 05Account support tracks total usage but not itemized usage, meaning token theft could run undetected for months.
The suspension broke his business. De Swardt works as a forward-deployed engineer for hire, building agents for small and mid-sized companies to do things like pull purchase-order data from emails into accounting software. As a sole proprietor, he also runs his own admin, website design, and coding through agents daily.
After he posted his experience on Reddit, 80 comments came in from other subscribers describing similar patterns. One user said their account was auto-upgraded without consent, their credit card was charged, and usage shot from 0% to 100% automatically. Another watched usage jump from 0 to 49% in 12 minutes after only a couple of prompts and a web search. A third said their account burned through max tokens every day for three days without them using it at all, and filed a GitHub report that drew more of the same accounts.
Two users in that GitHub thread posted the notification email Anthropic had sent them. The company said it had identified a bad actor deploying common infostealer malware to lift Claude login sessions from user machines, then reusing those sessions to consume account quota. Anthropic said the malware does not originate from Claude itself — infostealers spread through infected software downloads, malicious ads, and other standard vectors — and that when it detects suspicious activity it signs users out, invalidates existing authorizations, and issues refunds where appropriate.
De Swardt did not receive one of those warning emails. He says he found no evidence his own computer was compromised and still has no way to determine how the attacker got in. Anthropic told him the account appeared to have been used by an unauthorized-looking third-party service handling activity for other people, but could not determine how that service obtained access.
His Claude account was reinstated after about two weeks. He cancelled the subscription anyway and moved to Cursor, which lets him route work through multiple models including cheaper open-source options. In his testing the alternatives are close enough — he described the gap as not that much different or better — and he says he cannot justify returning until Anthropic ships tools that let users see what is consuming their tokens.
That visibility gap is the load-bearing problem. Anthropic declined to comment when asked how users can identify misuse on their own accounts. Without itemized usage logs or per-session attribution in the customer-facing dashboard, a subscriber has no way to distinguish their own agent runs from a hijacker's, which is exactly the condition an infostealer campaign needs to keep working.
The economics also favor the attacker. A stolen Claude Max 20x session is a $200-per-month resource that can be drained to zero in minutes, as the Reddit reports demonstrate, and the account holder eats the bill until they notice — or until Anthropic's fraud detection flags them, which in De Swardt's case took a support ticket and roughly two weeks of suspended service to resolve.
The Claude Code OAuth surface is what makes this campaign specifically painful rather than a generic credential-stuffing story. OAuth tokens minted from a stolen session survive password changes and MFA prompts until they are individually revoked, and Claude Code's agentic workloads are designed to run long, expensive tasks without a human in the loop — the exact profile an attacker wants when they are spending someone else's quota. Every frontier lab shipping agentic tooling on subscription pricing now has the same exposure. Anthropic is the one being tested first because Claude Code is where the paying power users live, and until the itemized-usage dashboard exists, the burden of proof is going to keep landing on the customer.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




