On August 4, Grant De Swardt, an independent AI consultant in East Sussex, England, noticed something small: he wasn’t doing any work, but his Claude usage meter climbed from 45% to 55% (TechCrunch). He pays for the $200-a-month Max plan. Soon after, Anthropic suspended his account, invalidated all of its sessions, refunded £44.49, and told him the account had been used by a suspected unauthorized external service to process someone else’s activity. How that service got access, Anthropic could not determine.

He is not an isolated case. Reddit threads collected users with the same story: one watched usage jump from 0 to 49% in 12 minutes; another had the full quota burned three days in a row; a third found the account upgraded to a more expensive tier, and charged for it, without their knowledge. Anthropic later confirmed the cause in an email to affected users: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” (BleepingComputer)

Account takeover is an old story, and it isn’t the part worth dwelling on. The new part is what the thief was after: the thing stolen was a login session, and the thing spent was a prepaid pool of compute. That spending creates no new bank transaction. In-plan usage comes with no per-session breakdown. No fraud team at any bank is watching it for you. Someone can siphon your quota, and odds are you will never know.

Nobody stole your password. They stole your logged-in session.

Here is the mechanism, assuming no security background at all.

When you log in to Claude, you type a password and maybe pass two-factor authentication (2FA), say a code sent to your phone. That is the ID check at the front door. After the check, the site doesn’t re-verify you on every action. Instead it stores a small piece of data in your browser called a session cookie, the wristband you get once your ID has been checked: present the wristband with each request, and the site treats you as the same person who just logged in (OWASP).

An infostealer (information-stealing malware) sneaks onto your computer and copies the wristbands out of your browser wholesale. With the wristband, the attacker needs neither your password nor your 2FA code, because as far as the site can tell, they are the already-logged-in you. The security industry calls this session hijacking: hold a valid session cookie and you can impersonate that user completely (OWASP). This is why the attack walks past 2FA: 2FA guards the front door, while the attacker lifted the wristband straight out of your pocket. According to the email Anthropic sent users, the malware involved is a set of familiar names: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer for a small number of Mac users (Search Engine Journal). The infection routes are familiar too: one victim on Reddit admitted downloading a pirated game before the compromise (Search Engine Journal).

The attack chain has one more step that matters. Per TechCrunch, stolen Claude session keys were used to “mint unauthorized Claude Code OAuth tokens.” In plain terms: holding the browser session, the attacker issued programmatic credentials for Claude Code, Anthropic’s coding agent (Claude Code docs), a key that can be dropped into a script, so the draining doesn’t require anyone sitting at a browser window. None of the reports says how long either credential type stays valid or what it is scoped to. As for burning 49% of a Max quota in 12 minutes, my inference is that manual chatting can’t move the meter that fast, and the pace looks like scripted agent workloads; the coverage I’ve read has no forensic detail on what the attackers actually ran, so this is inference, not established fact.

Why victims almost never find out on their own

Put this next to classic credit card fraud and the difference is immediate.

When a card is stolen, you have layers of protection built for you. The monthly statement lists every charge with a merchant name and an amount, and regulators tell consumers to watch it precisely because fraud surfaces there (CFPB). If you spot an unauthorized charge you can dispute it, and once the dispute is verified the charge must come off your bill (CFPB). And card issuers run their own fraud screening on top, the kind that freezes a card after an odd-looking purchase. Decades of fraud losses built that system.

For stolen subscription quota, each of those layers mostly fails. First, the attacker usually generates no new charge. You already paid; they spend prepaid quota. In-plan usage never touches your card; only separately purchased usage credits appear as additional charges (Claude Help Center). The bank sees no new transaction, so there is nothing for fraud systems to score. The exception is the user whose account got upgraded without consent. That did produce a real charge, but a subscription payment to Anthropic from a card that already pays Anthropic gives fraud screening little reason to look twice. Second, there is no per-task itemization. Claude’s settings do include a usage page showing overall consumption and history (Claude Help Center), but what a subscriber gets is aggregate: no per-session list, no record of what ran or how much each run burned. De Swardt caught the theft only because he happened to glance at the bar while idle; a heavy user who routinely runs at 70–80% could lose a quarter of the quota and plausibly never notice. He put it bluntly to TechCrunch: Anthropic gives users no “tools that allow users to see what’s consuming their tokens,” and without an itemized view, subscribers have no way to protect themselves. Third, there is no institutional recovery. Compute is consumed on the spot; burned tokens are gone. The £44.49 refund was Anthropic’s case-by-case decision; the company’s support page says only that its team can “check refund eligibility” (Anthropic Help Center), which is not a codified dispute process the way a card chargeback is.

Anthropic’s own detection did work: the company spotted the anomaly, signed users out, and sent the emails. But when TechCrunch asked how users can identify misuse themselves, Anthropic declined to comment. The platform sees what the user cannot. That information gap is the biggest hole in the security model of subscription AI products today.

What attackers want the quota for, neither Anthropic nor any of the coverage says; here I can only reason from mechanism, and I can’t verify it. Two monetization paths fit best. One is resale: stolen AI accounts already have a market track record. Group-IB found ChatGPT credentials saved on more than 100,000 infostealer-infected devices circulating on dark web marketplaces back in 2023 (Group-IB), and stolen quota is zero-cost inventory. The other is self-use: scraping cleanup, bulk content generation, workloads that would otherwise cost API money. Credentials harvested by infostealers have long been sold in bulk as “stealer logs” on dark web markets and Telegram channels (Flare). Whether a Claude session has already become a new priced field in those logs, I found no publicly verifiable marketplace records to confirm; mechanically, it lines up.

One detail deserves an honest note: De Swardt says a scan turned up no evidence of infection on his machine. Anthropic’s email also raised a second possibility, an unauthorized external service connected to the account. So at the level of any individual victim, whether the session was stolen by local malware or leaked through some third-party tool was never pinned down case by case. The overall attribution to infostealers comes from Anthropic; at the case level, some pieces don’t line up.

What to do now

If you subscribe to Claude, or to any AI product, a few things are worth doing today.

Scan for malware first, then change passwords. The order matters. Anthropic’s email stresses this: signing out only invalidates sessions that were already stolen; it does not remove the malware. If an infostealer is still on the machine, the new password and the fresh session get stolen right back. Run a full antivirus scan, remove what it finds, confirm the machine is clean, and only then change passwords and log back in.

Check your active sessions. Claude’s settings list every logged-in device, browser, and approximate location (official guide). Terminate anything you don’t recognize.

Watch the usage bar for two signals. Anthropic’s email describes the typical symptom: limits that “looked like they refilled and then drained while you weren’t using Claude.” The other signal is usage climbing while you aren’t working. Get in the habit of glancing at the bar when you’re idle. Until the platform ships per-task itemization, user-side detection comes down to this bar, the aggregate usage page, and the active-session list.

Treat your email account as equally important ground. Your Claude account hangs off your email address; an attacker who takes the mailbox can walk password-reset flows into every account attached to it (NCSC). Change the email password, sign out other devices, turn on two-factor authentication. Anthropic removed saved payment methods for affected users; Malwarebytes advises re-adding yours only after every cleanup step above is done and the machine is confirmed clean. For ongoing anomalies, contact usersafety@anthropic.com.

Stay away from pirated software and cracks. Among these victims, the one who publicly traced their infection found a pirated game at the start of it. Pirated and cracked software is a standard distribution channel for infostealers; Microsoft’s analysis of Lumma Stealer describes cracked copies of legitimate apps bundled with the malware and spread through file-sharing platforms (Microsoft).

A closing judgment. Subscription AI quota is turning into a real, stealable asset class, while the security infrastructure around it is still little more than a percentage bar. The credit card system took decades to arrive at itemized statements and dispute rights; I expect AI subscription platforms will have to get there too: per-session usage logs, alerts on anomalous consumption, revocable fine-grained credentials. Until then, the user side has only the steps above, and the platform side’s debt is exactly what De Swardt meant when he said subscribers have no way to protect themselves. He has since moved to Cursor. What drives users away may not be the incident itself, but the fact that after it happens, you can see nothing.

References