Hackers Hijacking Claude AI Tokens From Paying Subscribers
- Investigations by affected subscribers and Anthropic revealed that hackers are hijacking paying user accounts via infostealer malware to generate unauthorized OAuth tokens, leaving users facing depleted monthly limits...
- According to reporting by TechCrunch, De Swardt first discovered the anomaly in East Sussex, U.K., when his token usage climbed while he was not working.
- Multiple users shared emails they received directly from Anthropic identifying a broader pattern of abuse.
Investigations by affected subscribers and Anthropic revealed that hackers are hijacking paying user accounts via infostealer malware to generate unauthorized OAuth tokens, leaving users facing depleted monthly limits and unexpected suspensions.
How Claude Token Hijacking Operates
According to reporting by TechCrunch, De Swardt first discovered the anomaly in East Sussex, U.K., when his token usage climbed while he was not working. To confirm his suspicions, he deliberately left his account untouched the following day, ensuring all automated agentic tools and scheduled tasks were paused, disabled, or completed. Despite this, his monthly token consumption jumped from 45% to 55%. When De Swardt contacted Anthropic to ask for an itemized usage list, the company did not provide itemization, according to TechCrunch. However, Anthropic agreed something was wrong, suspended his paid account, invalidated his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription. The company stated the account appeared to have been used by an unauthorized third-party service to handle activity for other people, though it could not determine how the attackers obtained access. Anthropic suggested the evidence was consistent either with credentials and session data being taken without the user’s knowledge, or with the account having been connected to an outside service that was itself compromised.

Malware Infostealers and Wider User Impact
Multiple users shared emails they received directly from Anthropic identifying a broader pattern of abuse. As reported by TechCrunch, emails sent by Anthropic to affected customers stated: We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.
Infostealers are a form of malware that installs on a user’s machine to harvest saved passwords, session data, and login credentials. Anthropic noted in its customer communications that the malware did not originate from using Claude itself, but rather from external sources such as infected software downloads or malicious ads.

Business Disruption and Account Recovery
The sudden account suspensions and token drains caused significant disruption for professionals relying on the AI platform. De Swardt operates as an independent forward-deployed engineer helping small and mid-size businesses set up automated agents, such as tools that load purchase-order data from emails into accounting software. As a sole proprietor running daily administrative tasks, website design, and coding through the system, losing access wreaked havoc on his business operations, according to TechCrunch. Other impacted users experienced various symptoms of account compromise, including accounts auto-upgrading without consent, credit cards getting charged, and token metrics surging from zero to full capacity in minutes.
