[DigitalToday reporter Jinju Hong] Cases have been confirmed in which hackers hijacked login sessions from user accounts of Anthropic's generative AI service Claude and used Claude Code tokens without authorisation. Anthropic said it identified abnormal activity on some accounts and forced sessions to end. It also invalidated server-side authentication tokens and issued refunds to some users.
TechCrunch reported on Sept. 8 that the case became known after a report by independent AI consultant Grant De Swart (그랜트 드 스워트) in East Sussex, England.
De Swart said he discovered on Aug. 4 that token usage kept rising on his Claude Max 20X account, which costs $200 a month, even though he was not working. He said he turned off all functions connected to Claude the next day and did not carry out separate work, but usage increased again.
He said scheduled Claude CoWork tasks were suspended or ended at the time, the cloud execution function was turned off and there were no Claude Code tasks running locally. He said usage rose from 45 percent to 55 percent even when conditions were most controlled.
De Swart said he asked Anthropic for detailed token usage, but did not receive itemised records. Anthropic confirmed that abnormal activity occurred and temporarily suspended the paid account. It later ended all login sessions and invalidated server-side Claude Code tokens. It partially refunded 44.49 pounds for the remaining subscription period.
Anthropic told De Swart the cause, based on its investigation, was a stolen Claude session key. It said the session key was used to obtain unauthorised Claude Code OAuth tokens. De Swart said his paid account appeared to have been used by an unauthorised third-party service that handled other users' activity. He said he could not confirm exactly how access to his account was transferred outside.
Anthropic said this matched evidence that credentials or session data may have been stolen without the user realising, or that the account may have been linked to an external service.
The problem is that users find it difficult to detect such unauthorised use immediately. De Swart said the account support system tracks only total token usage and does not allow users to check detailed usage, meaning account hijacking could go undetected for months.
He said his work, which supports small and medium-sized businesses in building automation agents, relies heavily on AI from administrative tasks to website design and coding. He said if the account does not work normally it could significantly affect the work itself.
Other users also claimed similar damage. After De Swart shared his experience on Reddit, some users reported similar cases. One user claimed their account was upgraded to a higher-priced plan without consent, their credit card was charged and token usage surged from 0 percent to 100 percent despite not using it. Another user said usage rose from 0 percent to 49 percent in about 12 minutes after using only a simple prompt and web search. Similar cases continued, including reports on GitHub that an account had exhausted the maximum tokens for three consecutive days.
Anthropic also sent warning emails directly to some users. The company said it had confirmed cases in which commonly found infostealer malware stole Claude login sessions from users' computers and then used them to access accounts and drain token usage.
An infostealer is malware that steals passwords, session data and login information stored on a user's computer. Anthropic said it forces users to log out and invalidates existing authentication when it detects suspicious activity. It said it also provided refunds to some affected users and advised them about the possibility of malware infection.
Anthropic said the malware did not arise from using Claude itself. It said it could enter user devices through various online routes, such as downloading infected software or clicking malicious ads.
De Swart said he did not receive such a warning email and did not find evidence that his computer was infected with malware. He said he still could not confirm how the hacker accessed his account.
He said his account was restored about two weeks later, but he was unhappy that it was hard to receive prompt support when the problem occurred and that there were not enough tools to 확인 where tokens were used in detail. He ultimately cancelled his Claude subscription and moved to Cursor, which allows users to use multiple AI models together.
He said other AI models could be used for his work at a similar level to Claude, and that he could also choose cheaper open-source models. He said he had no plan to return to Claude unless Anthropic resolves the problem.
The case shows that as AI services evolve beyond simple chat tools to performing real work such as coding and business automation, the importance of account authentication and usage management is also growing. It said that if there is a lack of features to track token usage in detail, users may find it hard to immediately recognise account hijacking or unauthorised use. It said a key task going forward will be how Anthropic detects unauthorised use and provides users with more detailed usage information and response tools.