Repeated cases of Claude users consuming credits without their knowledge have raised concerns about account security, after it emerged that malware may be behind login sessions and exploiting them to consume users’ quota from artificial intelligence models.

The story began with Grant de Swart, an independent consultant in the field of artificial intelligence in Britain, when he noticed in August an increase in the consumption of tokens in his paid account on Claude Max 20x, even though he was not using the service.

De Swart attempted to determine the source of the consumption, disabled the tools and services associated with his account and stopped using Claude, but the balance continued to decrease. At one point, usage rose from 45% to 55% despite no active tasks or cloud implementations.

This prompted the user to contact Anthropic, the company behind Claude, requesting details about the activity on his account. Although he did not receive a detailed log of usage, the company acknowledged the abnormal activity, temporarily suspended his account, canceled his sessions and associated Claude Codes, and refunded a portion of his $200 monthly subscription.

Hack session beyond consumption

After investigation, Anthropic notified De Soarte that a session key for his account had been compromised and used to generate unauthorized OAuth tokens for Cloud Code.

According to the company, it appeared that an unauthorized third party used the account to carry out activities for the benefit of other people, but it was unable to determine how the attackers obtained the access data.

This incident raises an additional problem, which is the lack of a detailed record showing the user how his balance was consumed, which may allow unauthorized activity to continue for a long period without detection.

Similar cases among users

After de Swaart posted his experience on Reddit, dozens of comments appeared from users who said they experienced a sudden spike in their account consumption without actually using the service.

One of them reported that his account was upgraded automatically and without his consent, before usage rose from zero to 100%. Another user said that his consumption jumped from zero to 49% within 12 minutes, although his use was limited to a small number of requests and searches.

In another case, a user said that his account had exhausted the maximum number of tokens for three consecutive days despite not using it, prompting him to report the issue via GitHub.

Anthropic warns of information theft software

Anthropic has revealed to some affected users that the cause may be malware of some sort Infostealerwhich are programs designed to steal passwords, session data, and login information from users’ devices.

The company said that a malicious party used this type of software to steal Claude login sessions, then exploit them to access accounts and consume user balances.

When suspicious activity was detected, Anthropic took measures that included logging users out and revoking existing access permissions, as well as offering some refunds and warning them of the potential presence of malware on their devices.

The company confirmed that the malware does not come from using Claude himself, but rather it can reach users’ devices from various sources, such as infected programs or malicious advertisements.

A crisis of confidence and demands for more transparency

De Swaart got his account back about two weeks later, but eventually decided to cancel his subscription and move to Cursor, which allows the use of multiple AI models, including less expensive open source options.

He believes that the performance of other alternatives is close to Claude, while he considers that the absence of tools that allow the user to know the details of token consumption is a fundamental problem.

These incidents highlight a growing challenge for paid AI services: How can a user detect that his account has been exploited before his balance is depleted?

While Anthropic acknowledged that instances of login sessions being stolen, it did not provide general details about the tools users can rely on to detect unauthorized use, and declined to comment when asked how users were able to identify misuse of their accounts.