AIToday
AI Safety & AlignmentAI Business & IndustryTechCrunch AIPublished: Sep 9, 2026, 10:00 JST2 min read

Hackers steal Claude tokens from subscribers via infostealer malware

Hackers steal Claude tokens from subscribers via infostealer malware

3 Key Points

  1. What happened

    Hackers used infostealer malware to steal Claude login sessions and consume users' token allowances. Grant De Swardt's account was compromised, leading Anthropic to suspend it and issue a partial refund.

  2. Why it matters

    Previously, users could not detect this theft because Anthropic only tracks total usage, not itemized usage. This lack of visibility means such siphoning could go unnoticed for months, as seen in De Swardt's case where usage climbed from 45% to 55% without his action.

  3. What to watch

    Whether Anthropic will add itemized usage tools, as De Swardt notes users currently have no way to protect themselves. The company declined to comment on how users can identify misuse.

WHO IT HITSIndividual subscribers and small businesses relying on Claude for daily operations are most affected. They face potential financial loss from stolen tokens and operational disruption, as seen with De Swardt, who had to suspend his work and eventually switched to Cursor.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

This incident highlights a significant vulnerability in AI service accounts, where token usage is not itemized, leaving users blind to unauthorized consumption. De Swardt's experience shows that even a careful user can be victimized, and the lack of detailed usage data hampers both detection and resolution.

Anthropic's response—suspending accounts, invalidating tokens, issuing refunds—indicates acknowledgment of the issue, but the company has not yet implemented tools for users to see what is consuming their tokens. This leaves users with no proactive way to protect themselves, as De Swardt pointed out.

The stakes are high for small businesses and independent consultants who rely heavily on AI agents for core operations. For them, such an attack can disrupt their entire workflow, as it did for De Swardt, who had to pause his work and eventually leave the platform. The lack of transparency and support may drive other affected users to competitors like Cursor, which offers multiple model options. Whether Anthropic addresses this gap will likely influence user trust and retention.

FAQ
What should I do if I suspect my Claude account is being used without my permission?
Contact Anthropic support immediately. They may suspend your account, invalidate sessions, and issue a refund if they confirm suspicious activity. Also, check your computer for infostealer malware, as it is the common vector.
How can I prevent this type of token theft?
Ensure your computer is free of infostealer malware, which can be picked up from infected software or ads. Avoid saving login credentials and session data in browsers, and regularly monitor your token usage for unexplained spikes.
Does Anthropic provide itemized token usage reports?
No, Anthropic currently only tracks total usage. Even upon request, they did not provide an itemized list to De Swardt, making it hard for users to detect unauthorized consumption.

Get the latest AI Safety & Alignment news every morning

For example, today's edition would include:

  • Anthropic researcher Jacob Kochson quits, warns AI may be uncontrollable by next yearITmedia AI+ · 1h ago
  • OpenAI agents used German wiki to swap 18,000 messages, report saysLatent Space · 1h ago
  • Meta launches Muse AI agent, stresses securitySiliconANGLE AI · 4h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleGPT-6 Astra now generally available on Amazon Bedrock