Recently, multiple Claude users reported on social media that their account credits were being rapidly depleted despite no usage of the service. In response, Anthropic confirmed after investigation that hackers had illegally accessed user accounts using stolen Claude login sessions obtained via malware, silently consuming their valuable API credits.Author and source: AIBase
The incident was first detected on August 4 by Grant Deswart, an independent AI consultant based in East Sussex, England. On that day, although he was not working, the usage of his Claude Max 20x account continued to rise steadily. The next day, he promptly disabled all tools connected to Claude, paused scheduled tasks and cloud execution functions, yet even without any Claude Code tasks running locally, usage still surged from 45% to 55%.
After communicating with Anthropic's customer service, the company acknowledged anomalies with the account, subsequently suspending the paid account, terminating all active sessions, revoking all server-side Claude Code tokens, and refunding £44.49 for the remaining subscription period. It is reported that the Claude Max 20x subscription costs as much as $200 per month. The sudden suspension of the account directly impacted Deswart, an independent entrepreneur who relies heavily on AI to help small and medium-sized businesses deploy agents for automatically extracting purchase orders and entering them into financial systems, as well as for his daily administrative, web design, and programming tasks.
After a thorough investigation, Anthropic informed Deswart that the attacker exploited a leaked Claude session key to generate unauthorized Claude Code OAuth tokens. The company found that its account appeared to have been used by a suspicious third-party service to process tasks for others, but it has yet to determine how the attacker gained access. TechCrunch noted that because Anthropic’s current customer support system can only view total usage and cannot provide users with detailed itemized usage records, such misuse could go undetected for months.
As the incident gained traction on communities such as Reddit and GitHub, an increasing number of victims came forward. Users reported that their accounts were automatically upgraded without consent and charged to their credit cards, with usage instantly spiking from zero to 100%; others noted that after sending just a few prompts and performing a single web search, nearly half of their quota was consumed within 12 minutes; some even had their daily limits fully depleted over three consecutive days despite complete inactivity.
Some users have shared Anthropic’s security alert email, which states that the company recently discovered attackers using common information-stealing malware to steal passwords, session data, and login credentials stored on users’ computers. Anthropic said that upon detecting suspicious activity, it will forcibly log users out, revoke authorizations, and issue refunds where appropriate, while advising users to check their devices for malware distributed through unofficial downloads or malicious ads. However, Deswart himself has not received this security alert and has found no evidence of compromise on his computer to date.
Approximately two weeks after the account was restored, Deswart ultimately canceled the subscription due to dissatisfaction with the slow pace of the official response and the inability to obtain detailed usage breakdowns, opting instead to switch to Cursor, which supports multi-model invocation. Industry insiders believe that Anthropic still lacks the necessary management tools to help users accurately identify the sources of their quota consumption. In response to further media inquiries, Anthropic has chosen not to comment.
