Back to news
AI & Machine Learning
Sep 8, 2026

Unauthorized access leads to token theft from Claude users

Sep 8, 2026
AI Summary

Users of the Claude AI platform have reported unauthorized token consumption linked to compromised session keys. Anthropic, the company behind Claude, has acknowledged the issue and taken steps to suspend affected accounts, but users express frustration over the lack of detailed usage tracking and support.

  • Grant de Swardt, an AI consultant, noticed unusual token usage on his Claude Max account despite not using it.
  • After contacting Anthropic, his account was suspended, and he received a partial refund due to unauthorized token consumption.
  • Anthropic discovered that a compromised session key was used to mint unauthorized tokens, indicating a hacker accessed de Swardt's account.
  • Other users reported similar issues, with unexpected token usage and unauthorized account upgrades.
  • Anthropic informed some users that infostealer malware was responsible for stealing login sessions, but the malware did not originate from using Claude.
  • De Swardt's account was reinstated after two weeks, but he canceled his subscription due to inadequate support and tracking tools.
  • Anthropic has not provided information on how users can identify misuse of their accounts.
hackerssecuritytokensanthropicclaude