How Infostealer Malware Bypasses MFA to Drain Claude AI Tokens
Anthropic said infostealer malware stole Claude login sessions and consumed users’ usage, while some subscribers reported sudden token spikes and unexpected charges.
- Anthropic recently warned users that infostealers are stealing Claude login sessions from computers to consume account usage, identifying bad actors using common malware to access accounts and alert affected customers.
- Grant Swardt, an independent AI consultant in East Sussex, noticed his Claude Max token usage climbing on August 4 while he performed no work, increasing from 45% to 55% during a controlled interval.
- One Reddit user claimed usage shot from 0% to 100% automatically without consent, while another reported usage spiking to 49 percent in 12 mins, and a third said accounts burned through max tokens daily for three days.
- Following investigation, Anthropic told Swardt a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens, leading the company to suspend his account and issue a partial refund of his $200-per-month subscription.
- But the difficulty of getting speedy help and lack of itemized usage soured Swardt on Claude, prompting him to cancel his subscription in favor of Cursor, which he said works as well as Claude.
11 Articles
11 Articles
Hackers gain access to Claude's records using harmful software and waste user currents.
In the ever-expanding world of artificial intelligence, users are facing new threats to the security of their accounts. In this article, we review Grant de Swordt's experience with Cloud token theft and how users can protect themselves. Hackers steal Cloud tokens from subscribers. On August 4th, Grant de Swordt, an independent AI consultant in East Sussex, UK, noticed something strange happening with… The article “Hackers steal Cloud tokens fro…
Infostealers Target Claude, Cursor, Codex and Other AI Agents to Steal Credentials and Sensitive Data
Information-stealing malware is expanding its collection logic to target locally stored data from AI coding agents, including Claude, Cursor, Codex, Cline, Continue, and OpenCode. The shift puts developer credentials, Model Context Protocol configurations, prompt histories, project metadata, and potentially proprietary source code into the same theft pipeline long used for browser cookies, cryptocurrency wallets, and
A wave of hacked Claude accounts has hit Anthropic users, with several subscribers seeing their token usage skyrocket without them even touching the tool.
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











