Infostealers Are Draining Claude Accounts, Anthropic Warns
- What happened
- Anthropic is warning customers that infostealer malware is stealing Claude login sessions off their computers and spending their subscription usage.
- Why it matters
- In one case Anthropic investigated, a compromised session key minted unauthorized Claude Code OAuth tokens, and with only total usage tracked, TechCrunch says theft like this could go undetected for months.
- What to do
- Sign out of Claude everywhere, re-authenticate Claude Code on every machine, and scan every device that has held a Claude login for infostealers.
Verdict: the breach is on your machine, not at Anthropic, but Anthropic's total-only usage view is what lets it go unnoticed. Anthropic is warning customers that infostealer malware is stealing Claude login sessions and spending their usage, TechCrunch reported on September 8, 2026(opens in new tab). In one case Anthropic investigated, a compromised session key minted unauthorized Claude Code OAuth tokens. Claude Code stays Conditional in our directory, pending cost controls maturing. This story is that gap in practice: you get a total, not a receipt.
What happened
Anthropic has warned customers whose accounts showed suspicious activity, and users posted its emails. The warning, as quoted by TechCrunch:
We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage.
Anthropic also said the malware did not come from using Claude itself.
| Detail | What is reported |
|---|---|
| Entry point | Common infostealer malware on the user's own computer |
| What is stolen | Claude login sessions |
| What the attacker does | Accesses the account and consumes its usage |
| Documented case (vector not stated) | A compromised session key minting unauthorized Claude Code OAuth tokens |
| Anthropic's response | Signed users out, invalidated existing authorizations, issued some refunds, warned of malware |
| Detection guidance | Not provided. Asked how users can identify misuse, Anthropic declined to comment |
One case, end to end
Grant De Swardt, an independent AI consultant in East Sussex, U.K., paid $200 per month for Claude Max 20x and noticed the unexplained usage on August 4, 2026. In what he called his clearest controlled interval, usage rose from 45% to 55% while he did no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and no local Claude Code task was running, he told TechCrunch.
Anthropic told him the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access." After investigating, it told him a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. Neither Anthropic nor TechCrunch says how that key was compromised. It suspended his paid account, invalidated all his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining subscription time. The account was reinstated after about two weeks. He cancelled his subscription in favor of Cursor, citing its ability to use multiple models, including more affordable open source options.
He was not alone. He posted his experience on Reddit, and 80 comments in, found others reporting similar problems. TechCrunch also cites a Claude user whose account burned through its max tokens every day for three days without them using it at all. That user opened GitHub issue anthropics/claude-code#82506, where, per TechCrunch, two other users posted Anthropic's warning emails.
Why it matters
- The theft is hard to see. Account support tracks total usage but not itemized usage, even upon request. Per TechCrunch, this kind of theft "could have gone on for months undetected."
- A session is a bearer credential. Whoever holds it spends your plan, and Claude Code turns that into machine-speed spend.
- This is credential hygiene, not a vendor breach. The entry point is the endpoint, so a password change alone does not fix a machine that is still infected.
- The question to ask every AI vendor you pay: can you show me what spent my money? If the answer is no, you are relying on noticing the shape of the bill.
What changes for you
| Step | Why |
|---|---|
| Sign out of Claude on every device, then sign back in | Invalidating sessions is the remediation Anthropic itself applied |
| Log Claude Code out and re-authenticate on every machine | In the documented case, a compromised session key minted Claude Code OAuth tokens |
| Run an infostealer scan on every machine that has held a Claude login, personal ones included | Anthropic warned affected users they may have malware, which can come from infected downloads or ads |
| Watch your usage meter for movement during hours you did not work | Total usage is the only signal support tracks |
| If you receive Anthropic's warning email, treat the whole machine as compromised | The session was lifted from the computer, not from Anthropic |
FAQ
Was Anthropic hacked? Nothing in the reporting says so. Anthropic says the malware did not come from using Claude itself. The sessions were stolen from users' own computers.
How do I know if my account was hit? Anthropic has warned customers whose accounts showed suspicious activity. Asked how users can identify misuse, it declined to comment, so unexplained jumps in your usage meter are the main signal you have.
Do affected users get refunds? Anthropic issued some refunds. In the documented case, that was a partial refund of £44.49 for the remaining subscription time, after the account was suspended.
Does this change the Claude Code verdict? No. Claude Code stays Conditional. That verdict already hinges on cost controls maturing, and a usage view with no itemization is a cost-control gap.
What to do
- 1 Sign out of Claude on every device, then sign back in. Invalidating sessions is the remediation Anthropic applied.
- 2 Log Claude Code out and re-authenticate on every machine. In the documented case, a compromised session key minted Claude Code OAuth tokens.
- 3 Run an infostealer scan on every machine that has held a Claude login, personal ones included. Anthropic warned affected users they may have malware, which can come from infected downloads or ads.
- 4 Watch your usage meter for movement during hours you did not work. Total usage is the only signal support tracks.
Affected tools & models
Never need to catch up again
The weekly delta — only verdict changes and act-now items. No digest filler.