Anthropic says infostealer malware is stealing Claude login sessions and running up subscribers' paid usage

Image: TechCrunch / Getty Images
Why it mattersA Claude Max meter that climbs while you are not working can mean a stolen session, so invalidate all sessions from Anthropic's settings, re-authenticate from a clean machine, and scan the old one for infostealer malware.
TechCrunch reports that Anthropic has warned Claude subscribers a bad actor is using common infostealer malware to steal their login sessions and then rack up usage on their paid accounts. The story, published Tuesday, is built on the account of one independent AI consultant in the UK, a Reddit thread with dozens of similar reports, and an email Anthropic sent to affected users that TechCrunch quotes directly.
What Anthropic told users
The email TechCrunch quotes reads: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Infostealers are malware that installs on a user's machine and steals saved passwords, session data, and login credentials, and Anthropic said in the same email that the malware did not come from using Claude itself.
When Anthropic spotted suspicious activity on an account, it signed the user out, invalidated existing authorisations, issued some refunds, and told the user to expect that their computer may be compromised.
What a compromised account looked like
The named source in the piece is Grant De Swardt, an independent AI consultant in East Sussex whose Claude Max 20x account, the $200-a-month tier, started climbing on 4 August while he was not working. He told TechCrunch he ran a controlled interval the next day with everything disabled, and the meter still moved from 45% to 55% while nothing was running locally.
Anthropic told De Swardt the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access", and traced the theft to a compromised Claude session key that was used to mint unauthorised Claude Code OAuth tokens.
The Reddit thread De Swardt posted afterwards drew similar accounts from other subscribers, one of whom said usage went from 0 to 49% in twelve minutes on an account that had only run a couple of prompts and a web search. A separate GitHub report gathered more.
The gap that lets it hide
The wider problem in the piece is what happens after a session key leaks. Anthropic tracks total usage on a subscription but does not itemise it, and did not provide an itemised list to De Swardt when he asked for one. In an account whose owner does not sit and watch the counter, quiet siphoning of a few percent per hour is invisible until the weekly cap arrives.
The practical action for a Claude Code or Claude Max user reading this today: if usage on your account climbs while you are not using it, treat the machine as compromised until you have looked, invalidate all sessions from Anthropic's account settings, and re-authenticate from a machine you have scanned. What makes stolen credentials pay for themselves is the session-key model that lets an OAuth token minted on your box keep working from any address a thief chooses to run it from.
Source
- TechCrunch, Hackers are stealing Claude tokens from subscribers, by Julie Bort, 8 September 2026.
Reported by: TechCrunch
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually shipping with them. Short, and only when there is something worth reading.

