Hackers are stealing Claude session tokens to drain paid subscriptions
If your Claude account is burning through tokens while you sleep, hackers might be riding shotgun on your subscription.
Hackers are using infostealer malware to snatch active login sessions from Anthropic subscribers, TechCrunch reports. Anthropic confirmed in emails to users that bad actors are using stolen session keys to mint unauthorized OAuth tokens and drain paid account usage. Multiple subscribers on Reddit and GitHub reported their token meters jumping to 100% capacity without them touching the service.
Why it matters: Anthropic currently lacks tools for users to view itemized token usage logs, meaning stolen sessions can quietly drain your quota for weeks. While Anthropic has invalidated compromised sessions and issued partial refunds to some users, subscribers have no direct way to audit what is consuming their monthly limits.
If your usage spikes unexpectedly, log out of all active sessions, scan your device for malware, and contact support.
Until Anthropic adds granular usage tracking, keep a close eye on your token meter.

