Hackers stole Claude tokens by using a compromised Claude session key to mint unauthorized Claude Code OAuth tokens, Anthropic confirmed in a response to a subscriber’s report.
Unexpected token consumption
On 4 August 2026, independent AI consultant Grant De Swardt noticed that his Claude Max 20x account was consuming tokens despite no work being performed. The token‑usage metric rose from 45 % to 55 % – a jump of 10 percentage points – over a controlled interval in which all Claude‑linked integrations were disabled.
De Swardt logged the anomaly on 5 August and again on 6 August when he requested an itemised usage report from Anthropic. The rise continued, prompting him to contact Anthropic on 6 August.
Anthropic’s investigation and remediation
Anthropic suspended the paid account on 7 August, invalidated every active session and every server‑side Claude Code token, and issued a partial refund of £44.49 for the remaining time on a $200‑per‑month subscription. The refund amount is a one‑time figure reported by TechCrunch.
In its statement, Anthropic said the evidence points to a compromised Claude session key that was used to mint unauthorized OAuth tokens. The company’s support tools could not itemise the illicit activity, meaning the theft could have persisted undetected for months.
Technical context and malware claim
An email circulating among security researchers warned that a “bad actor … is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” The email is quoted verbatim in the source material.
Anthropic clarified that the malware did not originate from Claude itself and that such malware can be acquired from many online sources, including infected software downloads or malicious ads. The company also noted that it did not send the quoted email to De Swardt.
Impact and unanswered questions
The incident affected at least one paying subscriber and highlights a gap in Anthropic’s ability to detect token‑theft in real time. Anthropic’s statement did not specify how many other accounts might have been compromised, nor the exact duration of the unauthorized activity.
Subscribers should monitor their token usage and be prepared for possible session invalidations. Anthropic has not announced any broader changes to its authentication flow, leaving the timeline for any security upgrades uncertain.
| Metric | Value | Period / Basis | Source |
|---|---|---|---|
| Refund amount | £44.49 | One‑time | TechCrunch |
| Subscription cost | $200 | Per month | TechCrunch |
| Token usage increase | 10 | Percentage points (45 % → 55 %) | TechCrunch |
Anthropic’s chief executive Dario Amodei leads the San Francisco‑based AI firm, which employs roughly 2,500 people and was founded on 26 January 2021. The company has not disclosed whether additional accounts were affected.
Until further details emerge, the episode serves as a reminder that session‑key security remains a critical vector for AI‑service providers.