Hackers are using malicious software to steal Claude users' login sessions, allowing them to illicitly hijack account token quotas.
Imagine this: You finish your work as usual and check the usage of the artificial intelligence (AI) service ‘Claude,’ only to be surprised by the numbers you see. You know for a fact that you haven’t asked the AI a single question today, yet your token quota (the amount of information the AI can process) has dwindled as if someone had been working it hard all night. Source 4 This is, in fact, an absurd scenario that many paid Claude subscribers have recently been experiencing.
Moving beyond simple attempts to use AI for free, hackers have now started targeting our precious paid AI subscription accounts. How on earth are hackers stealing our accounts and using our tokens as they please?
Why does this matter?
AI technology has become an essential companion in our daily lives. However, having your account hacked means more than just “losing tokens.” When hackers hijack your account, they use your quota to perform their own tasks. Source 14 Not only is the money you paid being used for someone else’s work, but it also carries the risk that all AI utilization results generated from your account could be exposed to others or misused for criminal purposes. An even bigger problem is that Anthropic, the operating company, does not yet provide detailed analysis tools that allow users to see exactly where their tokens were consumed. Source 5
Easy explanation
Let’s compare the method hackers use to hijack our accounts to a “key.”
The passwords or multi-factor authentication (MFA, an additional security verification step) that we use daily are like the “key” or “door lock password” used to enter a house (your account). You check the lock every time you enter. However, the ‘Infostealer (malicious software for information theft)’ used by hackers bypasses this process entirely.
Simply put, hackers are stealing the ‘duplicate access card (browser cookies and active session data)’ that we carelessly left stuck in the front door when we left the house. Source 7, Source 12 If they have this card, hackers can enter our house without any hindrance while remaining in a logged-in state, even without knowing what the password is. Source 9 Because the system recognizes it as the “owner” who has already been authenticated reconnecting, no additional security screening takes place.
Current situation
Currently, many users are reporting damage from unexplained token depletion. Source 10 In one user’s case, token usage increased drastically from 45% to 55% even though they hadn’t done any specific work. Source 1
Anthropic is aware of this situation and is sending warning emails to some victims, but criticism is emerging that the notifications have not reached all users. Source 11 Currently, the company is responding by forcing logouts for accounts suspected of damage, deleting registered payment methods, and issuing refunds to some users. Source 12 However, fundamentally, structural tools that can perfectly defend against this type of ‘Session Hijacking’ attack have not yet been fully realized. Source 2
What happens next?
Experts warn that these hacking campaigns will become even more sophisticated. Because malware infiltrates computers without the user’s knowledge, browser security management will become the frontline of personal information protection moving forward.
Users should regularly check their account usage and develop a habit of immediately logging out and logging back in if suspicious behavior is detected. It is also important to frequently scan your system for malware using security software. Furthermore, AI service companies must urgently prepare security tools that allow users to transparently verify their token consumption history and quickly report signs of anomalies.
References
-
[Hackers are stealing Claude tokens from subscribers TechCrunch](https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers/) - Hackers Are Stealing Claude Subscribers’ AI Tokens
- Anthropic Claude Security Breach: Stolen Tokens Hit Users
-
[Hackers are stealing Claude tokens from subscribers Hacker News](https://news.ycombinator.com/item?id=49662941) - Claude Token Theft Hits Subscribers as Hackers Target Accounts…
- Hackers are stealing Claude tokens from subscribers - Diaspora…
- Hackers Are Stealing Claude Subscribers’ AI Tokens
- Hackers Are Stealing Claude Tokens From Subscribers
- Hackers are stealing Claude tokens - relvehq.com
- Hackers are stealing Claude tokens from paying subscribers …
- Hackers are stealing Claude tokens from subscribers
- Hackers draining Claude tokens from subscriber accounts
- Malware Is Now Stealing Claude Sessions To Drain Paid… - TechRound
- Newsroom \ Anthropic
- Brute-forcing strong passwords
- Using infostealer malware
- Directing users to email phishing sites
- AI models neutralize the authentication
- They steal the entire already-logged-in session information
- They decrypt the encryption technology
- Temporary suspension of service
- Forced logouts and deletion of payment information
- Deletion of user accounts