Claude Token Theft Hackers Are Draining Subscriber Accounts Anthropic Warns

TL;DR
- A Claude Pro subscriber discovered in August 2026 that his account was burning thousands of tokens while idle, exposing a wave of session hijacks targeting paying users.
- Attackers are stealing browser session tokens, API keys, and OAuth logins via infostealer malware and malicious extensions, then reselling or draining Claude access for AI spam and automation.
- Anthropic warns users to revoke sessions, rotate API keys, enable two-factor authentication, and monitor usage dashboards to stop account hijacking.
An Idle Account That Wasn't Idle
Last month, a paying Claude subscriber woke up to a mystery. He hadn't opened Claude in days, yet his usage dashboard showed heavy activity overnight — thousands of tokens consumed, long chat histories he never wrote, and API calls he never made.
When he posted screenshots of the phantom sessions, other subscribers chimed in with the same story: accounts running while idle, credits vanishing, rate-limit warnings out of nowhere. Security researchers who picked up the thread say it wasn't a billing glitch. It was theft.
Instead of breaking into Anthropic's servers, hackers were quietly riding along on legitimate paid accounts, siphoning their token quotas and reselling the access.
How The Claude Token Theft Works
The scheme is simple and brutally effective. It doesn't target Anthropic directly — it targets you.
Researchers say most victims are compromised by infostealer malware like LummaC2, RedLine, and RisePro, often bundled with cracked software, fake Claude desktop apps, or free AI tools. Once installed, the malware scrapes browser cookies, local storage, and saved session tokens for claude.ai and console.anthropic.com.
With a stolen session token, an attacker doesn't need your password or your two-factor code. They simply inject your cookie into their own browser and inherit your logged-in session, including your Pro or Team subscription and any stored API credits.
A second vector is malicious browser extensions. Fake ad-blockers, PDF helpers, and so-called Claude productivity boosters have been caught requesting permission to read data on all sites, then silently exfiltrating Anthropic session keys and API keys.
Once inside, hackers automate the drain. Victims report seeing API calls at 2 a.m. to 5 a.m., massive context-window prompts, and conversations in other languages focused on spam generation, SEO farming, phishing email drafting, coding tasks, and crypto scam chatbots. In some cases, attackers create hidden API keys under the victim's account to maintain persistent access even after the password is changed. That access is then resold on Telegram and dark web forums as cheap unlimited Claude access.
Why Paying Users Are Prime Targets
Free accounts aren't worth much to criminals. Paid Claude Pro, Max, and Team accounts are.
A hijacked Pro account gives attackers priority access to Claude Sonnet and Opus models without paying $20 to $100-plus per month. For operators running large-scale spam, scraping, or AI agent farms, stealing dozens of paid accounts is far cheaper than paying for legitimate API usage, which can run into hundreds of dollars in tokens per day.
Anthropic's usage-based API pricing makes the theft even more painful. Some developers linked to Claude via API reported unexpected five-figure token spikes and surprise charges before they realized a leaked key was being used externally.
What Anthropic Has Warned Subscribers
Anthropic has not announced a breach of its own systems, and says there is no evidence its databases were compromised. The company frames the incidents as account takeover via endpoint compromise.
In recent support advisories and emails to affected users, Anthropic has urged subscribers to treat any unrecognized activity as a hijack. The company warns that changing your password alone is not enough, because active sessions and API keys remain valid after a password reset unless manually revoked.
Anthropic is advising users to check their chat history for conversations they didn't start, review the usage and billing dashboard for overnight spikes, and audit the API keys page and connected apps for keys or integrations they didn't create. The company says it is actively revoking flagged fraudulent sessions, resetting abused API keys, and blocking known resold tokens, while encouraging users to report phantom usage immediately through its Trust and Safety channel.
How To Protect Your AI Account From Hijacking
Security experts say protecting your Claude account now requires the same hygiene as a bank account.
First, turn on two-factor authentication and use a passkey or authenticator app, not SMS. Then go to your Claude settings and log out of all devices to kill stolen session cookies. If you are a developer, go to the Anthropic Console, delete any unknown API keys, rotate the ones you use, and set strict monthly spend limits and per-key usage caps.
Never paste your Claude API key into browser extensions, public demos, GitHub repos, or shared prompts. Store it only in server-side environment variables. Remove any Chrome or Edge extensions you don't absolutely trust, especially those that can read and change data on claude.ai.
Finally, run an antivirus scan for infostealers, clear browser cookies after a suspected compromise, and switch to a dedicated browser profile just for AI and financial accounts.
What To Do If You've Already Been Drained
If your account is consuming tokens while idle, act fast. Revoke all sessions, rotate all API keys, change your password from a clean device, and enable 2FA. Export your chat history and usage logs as evidence, then contact Anthropic Support to dispute fraudulent usage and request a key revocation.
If you entered payment details on a fake Claude app or extension, freeze that card and monitor for fraud. For developers, check server logs for unfamiliar IP addresses calling your key from outside your infrastructure.
The August discovery was a wake-up call: in the age of paid AI, your token quota is currency. And hackers have learned exactly how to spend it.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!