Anthropic Confirms Account Breaches Led to Unauthorized Use of Claude

iconMetaEra
Share
AI summary iconSummary
Anthropic confirmed that account breaches led to unauthorized use of Claude, reported via on-chain news. Users reported that stolen login sessions, compromised by malware, consumed API quotas. AI and crypto news outlets highlighted the breach, initially flagged by Grant Desvour on August 4. Affected accounts were suspended, active sessions revoked, and partial refunds issued. Attackers exploited leaked session keys to generate OAuth tokens. Similar incidents emerged on Reddit and GitHub, including unauthorized upgrades and charges. Anthropic advised users to scan for malware but did not release detailed logs. Some subscribers canceled their services due to dissatisfaction.
Recently, multiple Claude users reported on social media that their account credits were being rapidly depleted despite no usage of the service. In response, Anthropic confirmed after investigation that hackers had illegally accessed user accounts using stolen Claude login sessions obtained via malware, silently consuming their valuable API credits.

Author and source: AIBase

The incident was first detected on August 4 by Grant Deswart, an independent AI consultant based in East Sussex, England. On that day, although he was not working, the usage of his Claude Max 20x account continued to rise steadily. The next day, he promptly disabled all tools connected to Claude, paused scheduled tasks and cloud execution functions, yet even without any Claude Code tasks running locally, usage still surged from 45% to 55%.

After communicating with Anthropic's customer service, the company acknowledged anomalies with the account, subsequently suspending the paid account, terminating all active sessions, revoking all server-side Claude Code tokens, and refunding £44.49 for the remaining subscription period. It is reported that the Claude Max 20x subscription costs as much as $200 per month. The sudden suspension of the account directly impacted Deswart, an independent entrepreneur who relies heavily on AI to help small and medium-sized businesses deploy agents for automatically extracting purchase orders and entering them into financial systems, as well as for his daily administrative, web design, and programming tasks.

After a thorough investigation, Anthropic informed Deswart that the attacker exploited a leaked Claude session key to generate unauthorized Claude Code OAuth tokens. The company found that its account appeared to have been used by a suspicious third-party service to process tasks for others, but it has yet to determine how the attacker gained access. TechCrunch noted that because Anthropic’s current customer support system can only view total usage and cannot provide users with detailed itemized usage records, such misuse could go undetected for months.

As the incident gained traction on communities such as Reddit and GitHub, an increasing number of victims came forward. Users reported that their accounts were automatically upgraded without consent and charged to their credit cards, with usage instantly spiking from zero to 100%; others noted that after sending just a few prompts and performing a single web search, nearly half of their quota was consumed within 12 minutes; some even had their daily limits fully depleted over three consecutive days despite complete inactivity.

Some users have shared Anthropic’s security alert email, which states that the company recently discovered attackers using common information-stealing malware to steal passwords, session data, and login credentials stored on users’ computers. Anthropic said that upon detecting suspicious activity, it will forcibly log users out, revoke authorizations, and issue refunds where appropriate, while advising users to check their devices for malware distributed through unofficial downloads or malicious ads. However, Deswart himself has not received this security alert and has found no evidence of compromise on his computer to date.

Approximately two weeks after the account was restored, Deswart ultimately canceled the subscription due to dissatisfaction with the slow pace of the official response and the inability to obtain detailed usage breakdowns, opting instead to switch to Cursor, which supports multi-model invocation. Industry insiders believe that Anthropic still lacks the necessary management tools to help users accurately identify the sources of their quota consumption. In response to further media inquiries, Anthropic has chosen not to comment.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.