Anthropic has confirmed that hackers are stealing Claude tokens from subscribers by using infostealer malware to compromise active login sessions. This security breach allows unauthorized parties to access paid accounts and deplete token allowances without the owner's knowledge. While the company has begun invalidating affected sessions and issuing refunds, users report significant difficulty in tracking unauthorized activity due to a lack of itemized usage logs.
How are hackers stealing Claude tokens?
Bad actors are deploying common infostealer malware on personal computers to harvest session data and login credentials. Once this information is captured, attackers use the stolen session keys to gain unauthorized access to Claude accounts. This allows them to consume the victim's paid token allowance, leading to rapid, unexplained usage spikes that often go undetected by subscribers until their limits are exhausted.
The company maintains that the malware does not originate from its own platform but is instead picked up through external vectors, such as downloading infected software or clicking on malicious advertisements. When suspicious activity is identified, Anthropic has been signing users out, invalidating existing authorizations, and providing partial refunds to those impacted by the unauthorized access.
What can users do to track unauthorized activity?
Currently, users have limited options for monitoring account misuse because Anthropic does not provide itemized usage logs. Subscribers who notice suspicious activity are encouraged to contact support, which may result in session invalidation and account reviews. However, the lack of granular tracking tools makes it difficult for individuals to independently verify how their tokens are being consumed or to identify the specific source of a breach.