Infostealers Are Draining Claude Accounts, Anthropic Warns

Anthropic logoAnthropicImportantSeptember 30, 2026Security
What happened
Anthropic is warning customers that infostealer malware is stealing Claude login sessions off their computers and spending their subscription usage.
Why it matters
In one case Anthropic investigated, a compromised session key minted unauthorized Claude Code OAuth tokens, and with only total usage tracked, TechCrunch says theft like this could go undetected for months.
What to do
Sign out of Claude everywhere, re-authenticate Claude Code on every machine, and scan every device that has held a Claude login for infostealers.

Verdict: the breach is on your machine, not at Anthropic, but Anthropic's total-only usage view is what lets it go unnoticed. Anthropic is warning customers that infostealer malware is stealing Claude login sessions and spending their usage, TechCrunch reported on September 8, 2026(opens in new tab). In one case Anthropic investigated, a compromised session key minted unauthorized Claude Code OAuth tokens. Claude Code stays Conditional in our directory, pending cost controls maturing. This story is that gap in practice: you get a total, not a receipt.

What happened

Anthropic has warned customers whose accounts showed suspicious activity, and users posted its emails. The warning, as quoted by TechCrunch:

We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.

Anthropic also said the malware did not come from using Claude itself.

DetailWhat is reported
Entry pointCommon infostealer malware on the user's own computer
What is stolenClaude login sessions
What the attacker doesAccesses the account and consumes its usage
Documented case (vector not stated)A compromised session key minting unauthorized Claude Code OAuth tokens
Anthropic's responseSigned users out, invalidated existing authorizations, issued some refunds, warned of malware
Detection guidanceNot provided. Asked how users can identify misuse, Anthropic declined to comment

One case, end to end

Grant De Swardt, an independent AI consultant in East Sussex, U.K., paid $200 per month for Claude Max 20x and noticed the unexplained usage on August 4, 2026. In what he called his clearest controlled interval, usage rose from 45% to 55% while he did no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and no local Claude Code task was running, he told TechCrunch.

Anthropic told him the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access." After investigating, it told him a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. Neither Anthropic nor TechCrunch says how that key was compromised. It suspended his paid account, invalidated all his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining subscription time. The account was reinstated after about two weeks. He cancelled his subscription in favor of Cursor, citing its ability to use multiple models, including more affordable open source options.

He was not alone. He posted his experience on Reddit, and 80 comments in, found others reporting similar problems. TechCrunch also cites a Claude user whose account burned through its max tokens every day for three days without them using it at all. That user opened GitHub issue anthropics/claude-code#82506, where, per TechCrunch, two other users posted Anthropic's warning emails.

Why it matters

  • The theft is hard to see. Account support tracks total usage but not itemized usage, even upon request. Per TechCrunch, this kind of theft "could have gone on for months undetected."
  • A session is a bearer credential. Whoever holds it spends your plan, and Claude Code turns that into machine-speed spend.
  • This is credential hygiene, not a vendor breach. The entry point is the endpoint, so a password change alone does not fix a machine that is still infected.
  • The question to ask every AI vendor you pay: can you show me what spent my money? If the answer is no, you are relying on noticing the shape of the bill.

What changes for you

StepWhy
Sign out of Claude on every device, then sign back inInvalidating sessions is the remediation Anthropic itself applied
Log Claude Code out and re-authenticate on every machineIn the documented case, a compromised session key minted Claude Code OAuth tokens
Run an infostealer scan on every machine that has held a Claude login, personal ones includedAnthropic warned affected users they may have malware, which can come from infected downloads or ads
Watch your usage meter for movement during hours you did not workTotal usage is the only signal support tracks
If you receive Anthropic's warning email, treat the whole machine as compromisedThe session was lifted from the computer, not from Anthropic

FAQ

Was Anthropic hacked? Nothing in the reporting says so. Anthropic says the malware did not come from using Claude itself. The sessions were stolen from users' own computers.

How do I know if my account was hit? Anthropic has warned customers whose accounts showed suspicious activity. Asked how users can identify misuse, it declined to comment, so unexplained jumps in your usage meter are the main signal you have.

Do affected users get refunds? Anthropic issued some refunds. In the documented case, that was a partial refund of £44.49 for the remaining subscription time, after the account was suspended.

Does this change the Claude Code verdict? No. Claude Code stays Conditional. That verdict already hinges on cost controls maturing, and a usage view with no itemization is a cost-control gap.

What to do

  1. 1 Sign out of Claude on every device, then sign back in. Invalidating sessions is the remediation Anthropic applied.
  2. 2 Log Claude Code out and re-authenticate on every machine. In the documented case, a compromised session key minted Claude Code OAuth tokens.
  3. 3 Run an infostealer scan on every machine that has held a Claude login, personal ones included. Anthropic warned affected users they may have malware, which can come from infected downloads or ads.
  4. 4 Watch your usage meter for movement during hours you did not work. Total usage is the only signal support tracks.

Affected tools & models

Never need to catch up again

The weekly delta — only verdict changes and act-now items. No digest filler.

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.