Hackers Steal Claude Max Usage Through Hijacked Sessions as Audit Gaps Leave Users Exposed
Claude subscribers report stolen usage after infostealer malware hijacks sessions, exposing weak visibility into token consumption and account support.
Summary
Independent AI consultant Grant De Swardt noticed unexplained consumption on his Claude Max 20x account on August 4. During an idle interval the next day, usage rose from 45% to 55% despite paused or completed Cowork tasks, disabled Dispatch and cloud execution, and no active local Claude Code task. Anthropic found that a compromised session key had minted unauthorized Claude Code OAuth tokens for an unidentified third party, but could not determine whether credentials were stolen or an outside service had been connected. It suspended his account, invalidated sessions and server-side tokens, and refunded £44.49 from his $200 monthly subscription without providing itemized usage.
The suspension disrupted De Swardt’s East Sussex consultancy, which uses agents for administration, website design, coding and moving purchase-order data from emails into accounting software. His Reddit post drew 80 comments, including reports of an unauthorized upgrade and a 0% to 100% usage surge, a 0% to 49% jump in 12 minutes, and daily maximums exhausted for three days while idle. Anthropic warned at least two users that common infostealer malware had stolen login sessions, then signed them out, revoked authorizations and issued some refunds; De Swardt received no warning and found no evidence of infection. Reinstated after about two weeks, he canceled Claude for Cursor and its multiple models, including cheaper open source options. Anthropic still offers no itemized token audit, leaving abuse potentially hidden for months, and declined to explain how users can identify misuse.
Positives
- Anthropic traced De Swardt’s unauthorized usage to a compromised session key that minted Claude Code OAuth tokens.
- Suspicious accounts were signed out, existing authorizations were invalidated and some affected subscribers received refunds.
- De Swardt recovered £44.49 for the unused portion of his $200 monthly Claude Max subscription.
- Anthropic proactively warned at least two users that infostealer malware had stolen their Claude login sessions.
Risks & concerns
- De Swardt’s idle Claude Max 20x usage climbed from 45% to 55% despite disabled cloud execution and no active local task.
- Reported incidents included usage surging from 0% to 49% in 12 minutes and maximum allowances disappearing daily for three days.
- Anthropic provides total consumption without itemized usage, allowing unauthorized activity to remain undetected for months.
- De Swardt’s roughly two-week suspension disrupted an AI consultancy dependent on agents for operational and client workflows.
- Anthropic could not determine how De Swardt’s session was compromised and declined to explain how subscribers can detect misuse.