Hackers are hijacking Claude tokens from subscriber accounts.
Image Credits:Samuel Boivin/NurPhoto / Getty Images
Mysterious Token Drain: A Consultant’s Alarming Experience with Claude Max 20x
On August 4, Grant de Swardt, an independent AI consultant based in East Sussex, UK, experienced an unexpected issue with his Claude Max 20x account. Although he hadn’t utilized the service that day, he observed a mysterious surge in his token usage. The next day, he took additional precautions by disabling everything linked to Claude, yet the inexplicable token consumption persisted. In a controlled interval, despite not performing any work, he noted an increase in consumption from 45% to 55%. “Scheduled tasks were paused or completed, Dispatch/cloud execution was disabled, and no active local Claude Code tasks were in progress,” he reported to TechCrunch.
The Quest for Answers
Uncertain about the source of the unauthorized token consumption, de Swardt reached out to Anthropic, the company behind Claude, to request an itemized usage report. While Anthropic acknowledged that something was amiss, they did not provide the detailed breakdown he sought. Instead, they suspended his paid account, invalidated all his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining duration of his $200-per-month subscription.
This abrupt suspension had serious implications for de Swardt’s business. As a consultant, he specializes in helping small and medium-sized enterprises set up automation agents—akin to forward-deployed engineers—for tasks like transferring purchase-order data from emails into accounting systems. Being a sole proprietor, he relies heavily on AI-driven agents for a multitude of operations, including daily administration, website design, and coding. “Everything runs through AI these days,” he remarked.
The Culprit Revealed
Following further investigation, Anthropic identified the issue: a compromised Claude session key had been exploited to create unauthorized OAuth tokens. According to the company, it appeared that an unauthorized third-party service had utilized de Swardt’s account for activities not sanctioned by him. While Anthropic could not ascertain how the breach occurred, they indicated that the evidence suggested either his credentials or session data had been accessed without his knowledge, or that his account was linked to an external service.
In essence, a hacker had gained access to de Swardt’s account and was siphoning off his tokens. Due to the lack of itemized tracking in account support, this theft could have continued for months without detection.
A Shared Experience
In an effort to find others who may have encountered similar issues, de Swardt took to Reddit. To his astonishment, he discovered that he was far from alone. One commenter reported that their account had been automatically upgraded without consent, resulting in unexpected charges and a jump in usage from 0% to 100%. Another user noted that their token usage spiked from 0 to 49% in just 12 minutes with minimal engagement.
One particularly alarming account came from a user whose Claude tokens were consumed at a rapid rate, drawing down their maximum allocation every day for three consecutive days despite no activity. This user subsequently created a GitHub report documenting their experience. The pattern continued with additional users who reported alarming similarities, creating a chorus of concerns about token theft.
Two users had even received warning emails from Anthropic, which advised them that their tokens were being stolen. The email stated, “We have recently become aware of a bad actor using common infostealer malware to steal Claude login sessions.” Infostealers are a type of malware that surreptitiously gathers saved passwords, session data, and other login credentials.
Upon detecting suspicious activity, Anthropic signed out the affected users, invalidated their existing authorizations, and issued some refunds while warning them about malware risks. They clarified that the malware was not introduced via Claude itself, but could be acquired through various online sources, such as downloading infected software or clicking on malicious ads.
Lack of Clear Communication
Despite the proactive measures taken with others, de Swardt did not receive one of those cautionary emails. He believes his computer remains uncompromised and questions how hackers managed to exploit his account. After about two weeks, his Claude account was reinstated, but his trust in the platform had been severely damaged.
The cumbersome process of rectifying the situation and the absence of itemized usage tracking led de Swardt to cancel his subscription. He pivoted to Cursor, which offers multiple models, including more budget-friendly, open-source options. He noted that in his experience, these alternative models perform as well as Claude, saying, “It’s not much different or better.” He expressed reluctance to return to Claude until the issues he encountered were fully resolved.
The Importance of Token Tracking
De Swardt’s experience highlights a crucial gap in security and user assistance. He pointed out that Anthropic lacks tools that allow users to see what is consuming their tokens, stating, “I don’t think there’s any way that these people can protect themselves.”
When pressed for information on how users can identify misuse, Anthropic declined to comment. This lack of clear guidance raises a red flag for users who rely on the platform, emphasizing the need for more robust security measures and transparent communication from AI service providers.
In a space where trust is paramount, lessons learned from this incident should lead to improvements in user protections and clearer reporting mechanisms. As the reliance on AI increases across various sectors, ensuring secure and transparent operations will be critical for users like de Swardt and others who depend on these technologies for their livelihoods.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Thanks for reading. Please let us know your thoughts and ideas in the comment section down below.
Source link
#Hackers #stealing #Claude #tokens #subscribers
