Hackers Stealing Claude Tokens from Subscribers
Hackers are stealing Claude tokens from Anthropic subscribers, causing significant issues for a sole proprietor who relies on AI for his business.
Intelligence analysis by Qwen 2.5 (3B)

Hackers are exploiting compromised Claude session keys to siphon off Anthropic subscribers' token allowances, causing financial and operational disruptions.
Hackers are tricking people into giving them access to their AI accounts, which lets them use up all the tokens. This is causing problems for people who use AI to help with their work.
Analysis
Compromised Claude Session Keys
Grant De Swardt, an independent AI consultant, noticed his Claude Max 20x account token usage increasing despite no work being performed. Anthropic suspended his account and invalidated sessions, issuing a partial refund. The company identified a compromised session key being used to mint unauthorized OAuth tokens.
Impact on Small Businesses
De Swardt's business relies on AI for daily admin tasks and website design. The theft of his tokens caused significant financial losses and operational disruptions. Other subscribers reported similar issues, with some seeing their token usage skyrocket without any activity.
Security Measures
Anthropic identified suspicious activity and warned affected users about potential malware. They signed users out, invalidated existing authorizations, and issued refunds. However, users still lack visibility into what's consuming their tokens, leading to frustration and a shift to alternative AI platforms.
Key points
- Hackers are exploiting compromised Claude session keys to siphon off token allowances from Anthropic subscribers.
- This has caused significant financial and operational disruptions for small businesses relying on AI.
- Anthropic has identified the issue and taken steps to warn and mitigate the problem.
With Anthropic taking steps to identify and warn users about potential security issues, the company is working to prevent future incidents.
Without better tools to monitor and control token usage, users remain vulnerable to theft and misuse.



