BREAKING NEWS
Hackers Stealing Claude Tokens via Session Hijacking
According to TechCrunch, AI developer Anthropic has warned subscribers that hackers are stealing Claude login sessions to siphon off their token allowances.
QuickTool Team
✓
Sep 8, 2026•3 min read•Source: TechCrunchAI-assisted summary · Automatically reviewed by the QuickTool Quality Pipeline
Share:

⚡ In Short
- TechCrunch reported that hackers are utilizing infostealer malware to capture active login sessions from user computers.
- Affected subscribers experienced sudden, unexplained spikes in token consumption while their platforms were completely inactive.
- In response to the security incidents, Anthropic signed users out, invalidated existing authorizations, issued some refunds, and issued warnings.
What Happened?
As reported by TechCrunch, independent AI consultant Grant De Swardt noticed his Claude Max 20x account consuming tokens while inactive. Anthropic later suspended the paid account, invalidated sessions, and issued a partial refund. Investigation results revealed a compromised session key minted unauthorized OAuth tokens. Anthropic subsequently warned other users that bad actors are utilizing infostealer malware—software that steals saved passwords, login credentials, and session data from local computers—to access accounts and deplete usage limits without authorization.
Key Highlights
1
TechCrunch reported that hackers are utilizing infostealer malware to capture active login sessions from user computers.
2
Affected subscribers experienced sudden, unexplained spikes in token consumption while their platforms were completely inactive.
3
In response to the security incidents, Anthropic signed users out, invalidated existing authorizations, issued some refunds, and issued warnings.
Why It Matters
This security issue highlights vulnerability vectors in modern subscription-based artificial intelligence services, where compromised login credentials can lead to unauthorized resource consumption. For sole proprietors and businesses relying heavily on automated workflows and AI agents, such interruptions can disrupt daily business operations and administrative tasks.
💡 Related AI Tools
The incident demonstrates the growing need for robust endpoint security and multi-factor authentication when handling cloud-based artificial intelligence credentials. Professionals managing multiple subscriptions may explore alternatives like Cursor, which allows integration with various open-source models, or implement stricter monitoring for unauthorized API and token activity.
Conclusion
As malicious actors increasingly target artificial intelligence accounts, platform providers face growing pressure to implement transparent usage tracking and detailed itemized logs, enabling subscribers to quickly detect and mitigate unauthorized access before their allowances are fully depleted.
Found this news helpful? Share it with your network!
Discover More on QuickTool
Latest Blogs
In-Depth Articles
Tools for the next step
These links are selected from this page's topic, not from a generic popularity list.
Developer ToolsAI Git Command GeneratorGenerates exact git commands based on plain English descriptions.Developer ToolsAI SQL Query GeneratorTranslate plain English text into complex SQL queries.Developer ToolsCSS Box Shadow GeneratorDesign beautiful, customized CSS box shadows instantly with visual preview.MarketingAI Abandoned Cart Email SeriesCreate a structured Abandoned Cart Email Series result from your requirements with guided AI assistance.