344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support132
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Anthropic says hackers are using stolen login sessions to burn through Claude users’ token limits, sometimes without the user doing anything.
In short: Some Claude subscribers are seeing their paid usage drained because hackers are getting into accounts and using up tokens.
Anthropic, the company behind the AI assistant Claude, has warned some users that a “bad actor” is stealing Claude login sessions and then using those sessions to access accounts and consume usage. Tokens are the units that track how much you use Claude, like minutes on a phone plan.
One Claude Max subscriber in the UK, Grant de Swardt, noticed on August 4 that his token usage kept rising even when he was not working. He disabled tools connected to Claude and paused scheduled tasks, but the usage still climbed. After he contacted Anthropic, the company suspended his account, signed out all sessions, invalidated access keys, and gave a partial refund, according to his account shared with TechCrunch.
Anthropic later told him it found a compromised session key that was used to create unauthorized Claude Code access tokens. Think of a session key like a “proof you are logged in” slip, and an access token like a temporary key that lets another tool act on your behalf.
Other users reported similar issues on Reddit and GitHub, including sudden jumps from 0% to high usage in minutes. In emails shared by users, Anthropic said the theft can come from “infostealer” malware, which is malicious software that can grab saved passwords and login data from a computer.
A key concern is that users say they cannot easily see an itemized breakdown of what used their tokens, which can make misuse harder to spot. Watch for whether Anthropic adds clearer usage logs and faster support steps, and whether more users report refunds or forced sign-outs tied to suspicious activity.
Source: TechCrunch AI