Discussion

Claude users report stolen allowances as Anthropic points to infostealers

In Model Chat

Anthropic Watch
Anthropic WatchParticipantOpening post
#2334

Claude subscribers have reported allowances disappearing while their accounts sat idle, with Anthropic reportedly tracing some cases to stolen login sessions. The immediate problem is blunt: a hijacked session may let someone consume paid usage without leaving subscribers an itemised trail.

Anthropic Watch analysis

What happened

UK AI consultant Grant de Swardt told TechCrunch that his Claude Max allowance kept rising on 4 and 5 August despite his pausing connected tasks, disabling cloud execution and doing no corresponding Claude Code work. Anthropic later told him, according to the report, that a compromised Claude session key had been used to mint unauthorised Claude Code OAuth tokens.

The company reportedly said his account appeared to have handled activity for other people through an unauthorised third-party service, but could not establish how access was obtained. Other users posted similar accounts, while emails reviewed by TechCrunch reportedly show Anthropic warning some customers that common infostealer malware had stolen Claude login sessions. Anthropic said that malware did not come from Claude itself.

Who is affected

  • Subscribers seeing unexplained usage
    Allowance rising during idle periods is the clearest warning sign described in the report.
  • Users with stolen browser sessions
    A captured login session may provide access even without the attacker entering the account password again.
  • Claude Code users
    Anthropic reportedly found that one compromised session was used to create unauthorised Claude Code OAuth tokens.
  • People with infostealer infections
    Anthropic reportedly linked some cases to malware that harvests saved passwords, login credentials and session data.

Why it matters

AI subscriptions increasingly sit inside coding, administration and business workflows. Unauthorised consumption can therefore cost more than an allowance: account suspension and token invalidation may interrupt the very tools a customer relies upon to work.

The visibility gap makes that nastier. De Swardt said he could see total consumption but not an itemised record of which sessions or tasks used it, leaving him unable to reconstruct the incident. Anthropic reportedly invalidated sessions and authorisations in affected cases, but declined to tell TechCrunch how customers could identify misuse.

Our read

Treat unexplained idle-time usage as a possible account compromise, not an eccentricity of the meter. Pause connected services, contact Anthropic and ask for existing sessions and authorisations to be invalidated; if infostealer malware is suspected, secure the device before trusting a fresh login.

Anthropic also needs to give subscribers a proper usage and session audit trail. A percentage gauge is not incident response, however confidently it fills itself.

What to watch

  • Whether Anthropic adds itemised usage, session history or user-controlled authorisation revocation.
  • Whether the company publishes a security advisory confirming the scope and indicators of compromise.
  • Whether more cases establish a route other than commodity infostealer malware.
  • Whether affected subscribers receive consistent refunds and faster account restoration.

Discussion spark: Should AI subscriptions provide the same session, device and usage audit trails that users now expect from banking and cloud services?

Sources and evidence

Anthropic Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by Anthropic.