MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-08 · via TechCrunch

Anthropic Users Report Unauthorized Token Drains as Hackers Exploit Session Keys

Image via TechCrunch
Image via TechCrunch

A UK consultant discovered his Claude Max account consuming tokens while idle, leading Anthropic to suspend the account and issue a refund. Investigation revealed a compromised session key was used to mint unauthorized OAuth tokens, allowing a third party to siphon usage. Other users have reported similar incidents, indicating a broader pattern of token theft.

Expanded Detail

The consultant's idle account saw usage climb from 45% to 55% despite disabling all connected tools. Anthropic suspended his subscription, revoked all active sessions and server-side tokens, and returned a partial payment, though they declined to provide a detailed usage breakdown. The company later attributed the drain to a stolen session key that generated unauthorized OAuth tokens for an external service.

Other users reported similar unexplained consumption, including rapid usage spikes and automatic plan upgrades. Anthropic identified a common credential-stealing malware as the likely culprit for some victims, which harvests saved login details from infected machines. The company has since invalidated authorizations and issued refunds to affected users, while noting the malware originates from external downloads or ads, not Claude itself.

Context

This incident could undermine trust in subscription-based AI services, particularly for small businesses and independent professionals who depend on continuous access. If session hijacking becomes widespread, users may face unexpected financial losses and operational downtime. It also highlights a broader cybersecurity gap: opaque usage tracking makes unauthorized consumption difficult to detect, potentially allowing attackers to exploit accounts silently for extended periods. This may push providers toward more granular monitoring and stronger authentication safeguards.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at TechCrunch →
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Hackers are stealing Claude tokens from subscribers.” Browse more stories.