Skip to content

Claude Token Theft: How Hackers Steal Your Credits and How to Protect Yourself

Users of Claude, Anthropic's AI assistant, are facing a growing threat: the theft of their usage tokens. Several cases documented by TechCrunch show hackers using victims' accounts without consent, leading to high bills and frustration. This article explains the phenomenon and offers concrete steps to protect your account.

Real Cases of Token Theft

A freelance consultant, subscribed to Claude Max at $200 per month, noticed an abnormal increase in his token usage, jumping from 45% to 55% in a short interval while he wasn't working. After contacting support, his account was suspended, sessions and tokens invalidated, and he received a partial refund. The investigation revealed that a compromised session key had been used to create unauthorized OAuth tokens for Claude Code, a development tool.

Other users have reported unexplained usage spikes, such as a rise from 0% to 49% in 12 minutes without any action. These incidents suggest the problem is not isolated.

How Hackers Operate

According to emails sent by Anthropic to some users, attackers use infostealers, malware designed to steal passwords and session data. These malicious programs often spread through infected software or malicious ads. Once they gain access to your login session, they can generate access tokens to use Claude without your knowledge.

Anthropic clarified that the malware did not originate from using Claude itself, but rather from external compromise of the user's device or browser.

Detection Limitations

The victim consultant highlighted a lack of tools to monitor usage in detail. Anthropic's support does not provide usage breakdowns, even upon request, which could hide theft for months. He has since canceled his Claude subscription and switched to Cursor, finding other models equivalent and more affordable.

Anthropic has not commented on detection methods available to users, and the full scope of the problem remains unknown.

Protective Measures to Adopt

Given this threat, here are some practical recommendations to secure your Claude account:

  • Monitor your usage regularly: check your usage reports to spot any anomalies, such as sudden token spikes.
  • Enable two-factor authentication (2FA): this adds an extra security layer, even if your credentials are stolen.
  • Use strong, unique passwords: avoid reusing passwords across multiple sites.
  • Be wary of suspicious software and ads: infostealers often spread through infected downloads. Install only software from trusted sources.
  • Revoke unused sessions: if you suspect compromise, log out of all devices and change your passwords.
  • Contact support immediately if you notice anomalies: report any suspicious activity for quick assistance.

What to Do If You're a Victim

If you notice fraudulent activity, act quickly:

  1. Change your password immediately and revoke all active sessions.
  2. Contact Anthropic support to report the issue and request an investigation.
  3. Check if a refund is possible for fraudulently consumed tokens.
  4. Scan your device with antivirus software to detect any malware.

In the meantime, caution is key. The security of your online accounts largely depends on your digital habits. By adopting these measures, you can significantly reduce the risk of losing your valuable tokens.

Source

Hackers are stealing Claude tokens from subscribers | TechCrunch

Related reading