Claude Subscribers' Tokens Being Stolen Due to Security Vulnerability
Artificial intelligence assistant Claude users noticed that tokens in their accounts were being spent by unauthorized parties due to compromised session keys and malware.
Grant de Swardt, an independent AI consultant living in the UK, and several other subscribers discovered unexpected token consumption on their Claude accounts even when they were not working.
Unexpected Token Usage Discovered
Grant de Swardt, working as an independent AI consultant in East Sussex, UK, noticed unusual token consumption on his Claude Max 20x account outside of working hours.
Measures Taken by Anthropic
Upon reporting the situation, Anthropic temporarily suspended the paid account, invalidated existing sessions and server-side Claude Code tokens, and provided a partial refund to the user.
Similar Reports from Other Users
After sharing his experience on Reddit and GitHub platforms, many users reported that similar unintended token consumptions had occurred in their own accounts.
Malware and Security Warning
Anthropic sent warning emails stating that malicious actors had taken over users' sessions by using widespread info-stealing malware.