Hackers Hijack Claude Subscriber Session Tokens to Generate Unauthorized OAuth Access

De Swardt said his token usage rose from 45% to 55% during a controlled period on Aug. 5, even though scheduled Cowork tasks were paused or completed, cloud execution was disabled and no local Claude Code task was running.
Anthropic did not provide the itemized token-usage records De Swardt requested, despite acknowledging that the account activity was abnormal.
The $44.49 partial refund covered the remaining period of De Swardt’s $200-per-month Claude Max 20x subscription.
The suspension affected De Swardt’s client work, which includes building automation agents for small and midsize businesses, such as transferring purchase-order data from email into accounting software.
Describing his dependence on the service, De Swardt said, “Like everything is just running through AI these days,” noting that he also uses agents for administration, website design and coding.
Hackers hijacked Claude AI subscriber tokens using stolen login credentials, Anthropic confirmed. Grant de Swardt, a British AI consultant, discovered his Claude Max 20x account burning through $200-per-month tokens without his authorization Extremetech. His token usage jumped from 45% to 55% in a single controlled period on August 5, even though he had disabled all connected services and wasn't running any tasks Extremetech.
Anthropic suspended de Swardt's account, ended all active sessions, and invalidated server-side tokens after determining the breach was consistent with a stolen session key or compromised credentials Yahoo Tech. The company issued a partial refund of $44.49 for the remaining subscription period. The incident disrupted de Swardt's business, which relies on Claude-powered automation to serve small and midsize business clients AsaaserRadio.
De Swardt first noticed the anomaly on August 5 when his token consumption spiked unexpectedly. He had deliberately paused scheduled Cowork tasks, disabled cloud execution, and was running no Claude Code work locally Extremetech. Yet his token usage climbed from 45% to 55% of his monthly allowance in a short window. "Like everything is just running through AI these days," de Swardt said, describing his deep reliance on the service Extremetech.
Anthropic's investigation concluded the breach involved either a stolen session key or compromised credentials, but the company could not pinpoint exactly how the account was accessed Yahoo Tech. Security researchers believe infostealer malware — including Vidar, LummaC2, StealC, and RedLine on Windows, plus Atomic Stealer on Macs — may be harvesting browser sessions from paid subscribers WebProNews. Anthropic did not provide itemized token-usage records de Swardt requested, limiting his ability to identify what tasks burned his credits.
De Swardt uses Claude to build automation agents for small and midsize clients, including tools that transfer purchase-order data from email into accounting software GadgetReview. He also relies on Claude agents for website design, coding, and administrative work. The account suspension forced him offline and disrupted active client projects. Anthropic's $44.49 refund covered only the remaining portion of his $200-per-month Claude Max 20x subscription.
Anthropic could not determine whether the same compromised session was used against other subscribers, raising concerns about the scope of the breach AsaaserRadio. The incident highlights a critical vulnerability: stolen browser sessions or login tokens grant attackers immediate access to premium accounts and their monthly token allowances. Defenders recommend enabling two-factor authentication, monitoring account activity regularly, and avoiding logins on untrusted machines. De Swardt's case is a stark reminder that even cautious users can fall victim to session hijacking.
Publishers
32
Articles
42
Reach
74