{"slug": "hackers-are-draining-claude-subscribers-usage-without-stealing-a-password", "title": "Hackers Are Draining Claude Subscribers Usage Without Stealing a Password", "summary": "Anthropic confirmed that hackers using infostealer malware have been hijacking Claude subscribers' login sessions and draining their paid usage without stealing passwords, affecting users like independent AI consultant Grant De Swardt, whose usage rose from 45% to 55% while he performed no work. Anthropic suspended affected accounts, invalidated sessions, and refunded charges, but has not provided itemized usage logs or detailed detection tools, leaving users without proof of what was stolen.", "body_md": "*Anthropic confirmed that hackers using common infostealer malware have been hijacking Claude subscribers' login sessions and quietly burning through their paid usage, and the company still can't give affected users an itemized log to prove how much was stolen.*\n\nGrant De Swardt, an independent AI consultant based in East Sussex, noticed something wrong with his Claude Max 20x account on August 4. He hadn't touched it that day, yet his token usage kept climbing. The next day he switched everything off, paused every scheduled task, and stopped working entirely. His usage rose anyway, from 45% to 55%, while he did nothing. \"In the clearest controlled interval, it increased from 45% to 55% while I performed no work,\" he said, according to TechCrunch.\n\nDe Swardt pushed Anthropic for an itemized breakdown of what had consumed his tokens. The company agreed something was off. It suspended his account, invalidated his sessions and server-side Claude Code OAuth tokens, and refunded him £44.49 for the unused portion of his $200-a-month plan. Anthropic told him the account appeared to have been used by an unauthorized third-party service on behalf of other people. It never explained how the attacker got in.\n\nIt turns out De Swardt wasn't an isolated case. On August 30, Anthropic began emailing a wider group of Claude users, warning that a bad actor was using infostealer malware. The list was long: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs. The goal was to lift active login session cookies straight off infected machines. According to BleepingComputer's review of the warning, Anthropic told users the tell is usage that \"looked like they refilled and then drained while you weren't using Claude.\"\n\nThis isn't a password breach. Infostealers scrape the browser's already-authenticated session, the cookie that proves you logged in and passed your two-factor check minutes or hours earlier. Hand that cookie to an attacker and they walk in as you, no password, no MFA prompt, nothing to trip an alarm. No alarm bells at all. Anthropic's response, signing users out to kill the stolen session, only stops the immediate access. That's a stopgap, not a fix. It doesn't touch the malware sitting on the victim's laptop, so a fresh login can hand the attacker a brand new cookie the moment the infection is still active.\n\n[Anthropic Admits Its Own Bugs Broke Claude Code After Weeks of Denial](https://startupfortune.com/anthropic-admits-its-own-bugs-broke-claude-code-after-weeks-of-denial/)\n\nAnthropic admitted that three of its own engineering bugs, not user error, caused Claude Code's monthlong performance decline, after weeks of telling subscribers nothing was wrong. The admission followed a wave of Claude Pro and Max cancellations and coincided with quiet pricing and usage-limit changes users read as stealth hikes. - [claude code regression bug issues](https://startupfortune.com/anthropic-admits-its-own-bugs-broke-claude-code-after-weeks-of-denial/) - [anthropic admits tool broke users](https://startupfortune.com/anthropic-admits-its-own-bugs-broke-claude-code-after-weeks-of-denial/)\n\nAnthropic pulled saved payment methods from compromised accounts and refunded charges it could identify. That's a real fix for the billing side. It does nothing for the trust problem underneath it: Anthropic still won't hand subscribers a usage log broken down by session, device, or timestamp. Users are told their number went up. They are not told which requests ran, from where, or for how long. TechCrunch reported that Anthropic declined to comment on whether it plans to build better detection tools for account holders.\n\nReddit threads and GitHub issues had been flagging the pattern for weeks before Anthropic's August 30 notice, users describing quota that drained overnight, auto-upgrades to higher tiers they never authorized, and support tickets that went nowhere until enough people complained. Security researchers at Malwarebytes and SecurityWeek both flagged the same root cause independently: run-of-the-mill infostealers, the same families that have hoovered up banking and gaming credentials for years, have simply found a new payload worth stealing. The tools weren't new. The target was. A Claude Max subscription that costs $200 a month is a more liquid target than a bank login that still needs laundering.\n\n## What this means for anyone running Claude Code at scale\n\nStartup Fortune's audience skews toward founders and engineers who live inside Claude Code on Max or Team plans, often with API keys and OAuth tokens wired into CI pipelines, cron jobs, and internal tools. That's exactly the setup an infostealer wants: a long-lived, authenticated session tied to a payment method, running unattended jobs that make anomalous activity easy to mistake for a scheduled task. That's the danger zone. If your usage graph doesn't match your work, don't assume it's a billing glitch. Check for infostealer infection on any machine that's logged into Claude, rotate your session and API keys, and remove saved cards from the account until you're sure the device is clean.\n\nAnthropic is not alone in facing this. OpenAI and other subscription AI platforms sit on the same exposure: a paid seat, a browser cookie, and no itemized ledger a user can audit on their own. The infostealer economy has already proven it will chase wherever the payout is easiest to cash out. Right now, that's a Claude session nobody's watching closely enough.\n\n**Also read:** [FBI, NSA and CISA Accuse Six Chinese AI Firms of Stealing US Models](https://startupfortune.com/fbi-nsa-and-cisa-accuse-six-chinese-ai-firms-of-stealing-us-models/) • [How Does Prompt Caching Work for LLMs, and Why It Cuts Bills in Half](https://startupfortune.com/how-does-prompt-caching-work-for-llms-and-why-it-cuts-bills-in-half/) • [Pony.ai's CEO Says Robotaxi Tech Is Solved, Only Regulators Stand in the Way](https://startupfortune.com/ponyais-ceo-says-robotaxi-tech-is-solved-only-regulators-stand-in-the-way/)\n\n*This article is filed under [AI News](https://startupfortune.com/category/ai/). Check it for more stories.*\n\n## Join the discussion\n\n[Open in the community →](/community/)\n\nAlmost there. Sign in and your reply posts straight away.\n\n[Anthropic's breakout ran through Microsoft's VS Code, and Satya Nadella deserves more credit than he gets](https://startupfortune.com/how-claude-code-and-vs-code-turned-anthropic-from-a-safety-lab-into-a-developer-phenomenon/)\n\nClaude Code turned Anthropic from an admired safety lab into a company with a $47 billion run-rate, and it did it inside VS Code, the free editor Microsoft gives away and most developers already use. The breakout was a distribution story, and the platform underneath it belonged to Satya Nadella. - [claude code vs code integration strategy](https://startupfortune.com/how-claude-code-and-vs-code-turned-anthropic-from-a-safety-lab-into-a-developer-phenomenon/) - [how microsoft enabled anthropic's growth](https://startupfortune.com/how-claude-code-and-vs-code-turned-anthropic-from-a-safety-lab-into-a-developer-phenomenon/)", "url": "https://wpnews.pro/news/hackers-are-draining-claude-subscribers-usage-without-stealing-a-password", "canonical_source": "https://startupfortune.com/hackers-are-draining-claude-subscribers-usage-without-stealing-a-password/", "published_at": "2026-09-09 00:53:29+00:00", "updated_at": "2026-09-09 01:15:29.738914+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-products"], "entities": ["Anthropic", "Claude", "Grant De Swardt", "Vidar", "LummaC2", "StealC", "RedLine", "Acreed"], "alternates": {"html": "https://wpnews.pro/news/hackers-are-draining-claude-subscribers-usage-without-stealing-a-password", "markdown": "https://wpnews.pro/news/hackers-are-draining-claude-subscribers-usage-without-stealing-a-password.md", "text": "https://wpnews.pro/news/hackers-are-draining-claude-subscribers-usage-without-stealing-a-password.txt", "jsonld": "https://wpnews.pro/news/hackers-are-draining-claude-subscribers-usage-without-stealing-a-password.jsonld"}}