Claude AI Token Theft: Is Your AI Chatbot Safe?

2026-09-09
Hackers are stealing Claude subscribers' token allowances through session key theft. Here's how the Claude AI hack works and how to protect your account.
On August 4, 2025, Grant De Swardt, an independent AI consultant based in East Sussex, England, noticed something odd. His Claude Max 20x account was burning through tokens and he wasn't even working. He disabled every connected service the next day. The usage kept climbing. From 45% to 55%, with no active sessions, no scheduled tasks, no cloud execution, and no local Claude Code processes running.
TechCrunch reported on September 8 that what happened to De Swardt wasn't an isolated glitch. It was part of a pattern. Attackers had figured out how to siphon token allowances from Claude subscribers, and Anthropic confirmed the mechanism: stolen session keys were used to generate unauthorized OAuth tokens for Claude Code. This form of OAuth token abuse is particularly dangerous because it bypasses every traditional security checkpoint.
Quick Verdict
| Aspect | Rating | Notes |
|---|---|---|
| Incident severity | High | Active token theft across multiple users |
| Anthropic's response | Moderate | Refunded affected users but lacks transparency |
| User detection tools | Poor | No itemized usage breakdown available |
| Account recovery | Slow | Two-week downtime for De Swardt |
| Overall risk to subscribers | Real but manageable | Take session security seriously |
What Happened to Grant De Swardt's Claude Account
De Swardt pays $200 per month for Claude Max 20x, the top-tier subscription that gives heavy users access to Claude's most capable models. As an AI consultant who helps small businesses deploy AI agents, his entire workflow depends on Claude. When he noticed the unexplained usage spike, he contacted Anthropic support and asked for a per-line usage breakdown.
Anthropic didn't provide the itemized data. But they did confirm the anomaly, paused his paid account, revoked all sessions and server-side Claude Code tokens, and refunded £44.49 for the remaining subscription period.
The company's investigation found that a leaked session key had been used to mint unauthorized Claude Code OAuth tokens. In plain terms: someone grabbed the digital credential that proves you're logged in, then used it to generate their own access tokens for Claude Code. They could run AI tasks on De Swardt's dime without ever touching his password or triggering two-factor authentication.
Anthropic couldn't determine exactly how the session key leaked. Their statement suggested two possibilities: credentials stolen without the user's knowledge (through malware on his machine), or the account had been connected to an external service that leaked the key. They couldn't rule either out.
How the Claude AI Hack Actually Works
This isn't someone guessing your password. The attack targets what happens after you log in.
When you sign into Claude through your browser, the server hands your browser a session key. That key persists so you don't have to re-enter your password every time you open a new tab. It's the digital equivalent of a hotel room keycard. As long as you have it, you can come and go.
Info-stealing malware scans browsers for saved cookies, passwords, autofill data, and session tokens. Claude's session key is just another item in that loot bag. Once an attacker has the session key, they can use it to generate OAuth tokens for Claude Code without going through the login flow again. No password. No 2FA prompt. No new device alert.
The theft is particularly hard to catch because Anthropic's usage dashboard only shows aggregate consumption. There's no per-session or per-token breakdown. If someone is quietly running Claude Code tasks on your account, the only sign is that your usage percentage creeps up faster than expected. If you're not checking, it could go on for weeks.
Reddit Community Response and Similar Incidents
De Swardt posted his experience on Reddit. Within days, the thread had over 80 comments from users describing nearly identical problems.
One user reported that their Claude Pro account's five-hour usage limit reset and immediately dropped back to zero without them sending a single message. Another said they'd used Claude for a few conversations and one web search, then saw usage hit 49% within twelve minutes. A third had their tokens fully consumed for three consecutive days without touching the account.
Some users posted screenshots of emails from Anthropic. The company told them it had identified signs of token theft, specifically attributing the attacks to info-stealing malware. The likely vectors: downloading cracked software, clicking malicious ads, or visiting compromised websites.
Anthropic's response to affected users included force-logging-out all sessions, removing saved payment methods (Visa and Mastercard on file), and keeping the accounts paused until the situation was under control. User chat history and projects were preserved.
Anthropic's Response and What They're Not Telling You
Anthropic took the incident seriously at the individual level. They refunded De Swardt, revoked compromised credentials, and sent warnings to users they identified as affected. His account was restored after roughly two weeks.
But when TechCrunch asked Anthropic how users can identify unauthorized token usage on their own, the company declined to comment. That's a significant gap. The usage dashboard shows a single percentage. If your usage goes from 0% to 100% in an hour and you know you weren't doing anything, that's a signal. But if an attacker is more careful and runs small tasks over time, the gradual increase looks like normal usage. You'd never know.
De Swardt's case had a clear signal: zero activity paired with rising usage. Not every victim will be so lucky. He eventually canceled his subscription and switched to Cursor, which supports multiple AI models at a lower cost. His reasoning was straightforward: Anthropic doesn't give users the tools to see what's consuming their tokens, so regular users have no practical way to protect themselves.
AI Chatbot Security: Why Session Keys Are the New Target
The shift from password-based attacks to session-based attacks isn't unique to Claude. Any web application that maintains persistent login sessions faces this problem. But AI chatbot accounts are a particularly attractive target because they come with something worth stealing: compute credits.
A stolen Netflix session gets you free streaming. A stolen Claude Max session gets you access to some of the most powerful AI models in the world. Attackers can use that access to run coding tasks, generate content, or power automated workflows, all on someone else's $200/month subscription.
Session keys don't expire quickly. They're designed for convenience so you don't have to log in constantly. But that long lifespan is exactly what makes them valuable to attackers. A single stolen session key can provide access for days or weeks unless the user manually logs out or the company detects suspicious activity.
Two-factor authentication doesn't help here. 2FA protects the login step. Once you're logged in and the session key exists, the attacker bypasses 2FA entirely. They're not logging in. They're using a key that was already issued to a legitimate, authenticated user. This session key attack pattern is why traditional security advice like "use a strong password" falls short against modern AI chatbot threats.
What You Can Do to Protect Your AI Chatbot Account
If you use Claude or any AI chatbot with a paid subscription, here are practical steps to reduce your risk.
Log out of active sessions you don't need. Most AI services have a "sign out everywhere" or "revoke all sessions" option in account settings. Use it periodically, especially if you've logged in on shared or unfamiliar devices.
Watch your usage patterns. If your usage percentage rises when you haven't been using the service, treat it as a red flag. Contact support immediately and ask them to revoke all active sessions.
Run malware scans on your devices. Info-stealing malware is the primary vector for session key theft. These programs often arrive through pirated software, malicious browser extensions, or compromised download links. A reputable antivirus or anti-malware tool can catch the most common families.
Be cautious about connecting external services to your AI account. Every third-party integration that uses your Claude credentials is another potential leak point. If a service gets compromised, your session key could be exposed.
Use a dedicated browser profile for AI work. Keeping your Claude sessions isolated from general browsing reduces the attack surface. If you accidentally visit a compromised site while in your general browser profile, your Claude session in a separate profile won't be affected.
The Bigger Picture for AI Chatbot Safety
The Claude token theft incidents reveal a gap in how AI platforms handle security transparency. Users are paying premium prices for access to powerful models, but they can't see the details of their own usage. That opacity gap makes theft detection nearly impossible for the average user.
Companies building AI chatbot platforms need to treat session security as a first-class concern. Itemized usage logs, alerts for anomalous usage patterns, and granular session controls aren't optional features anymore. They're baseline expectations for any service that charges real money for compute access.
For now, Claude subscribers are in a tricky spot. The product works well when it works. But if someone silently steals your tokens, the platform gives you almost no visibility into what's happening. You're left watching a percentage climb and hoping it's you.
If you rely on AI chatbot apps for daily work, keep your security tight and your sessions short. The convenience of persistent login isn't worth the risk of funding someone else's AI habit. The Claude Max subscription at $200 per month is a significant investment, and without proper visibility tools, Claude token stolen incidents will continue to catch paying users off guard.
Check more AI tool: