Anthropic has warned customers that a criminal campaign is stealing Claude usage through infostealer malware, after multiple subscribers reported token balances draining while they were not working.
Independent AI consultant Grant De Swardt first noticed the problem on August 4, when his Claude Max 20x account burned through tokens on a day he did no work. Even with background tasks paused and cloud execution disabled, consumption climbed from 45 percent to 55 percent of his allowance. Anthropic suspended the account, revoked all sessions and server-side tokens, and refunded part of his $200 monthly fee, telling him a compromised session key had been used to mint unauthorized Claude Code OAuth tokens.
Others surfaced similar stories on Reddit and GitHub: accounts upgraded without consent, credit cards charged, usage jumping from zero to full within minutes of light prompting. Some users shared emails in which Anthropic identified the cause, saying a bad actor is using common infostealer malware to lift Claude login sessions from computers and then spend the victims’ usage. The company signed those users out, invalidated authorizations and issued refunds, adding that the malware did not come from Claude itself.
De Swardt’s account was restored after about two weeks, but he cancelled anyway, frustrated by the lack of itemized usage data that would let customers see what is consuming their allowance. Anthropic said it could not determine how his session was obtained and declined to say how users can spot misuse. Without per-activity logs, the consultant argued, customers have no real way to defend themselves.