NEWS
Stolen Claude Sessions Drain More Than a Token Bucket
Infostealers replay Claude login cookies to drain Max 20x usage, because Anthropic’s meter shows a total and not a ledger.
Grant De Swardt watched his Claude Max 20x usage climb from 45% to 55% on August 5 while he sat idle. Cowork jobs were paused, cloud runs were off, and no local Claude Code task was open. The meter still moved.
Anthropic later told the East Sussex consultant a compromised session key had been used to mint unauthorized Claude Code OAuth tokens. It sent him a partial refund of £44.49, killed his sessions, and froze the $200 plan his whole shop ran on.
A Max Meter Moved While Nobody Typed
De Swardt first noticed the climb on August 4, a day he had not been working. He is an independent AI consultant who sets up agents for small firms, including jobs that pull purchase orders out of email and drop them into accounting software. His own office runs the same way. Daily admin, site work, and code all pass through Claude, which is why a frozen login is not a nuisance. It is a shutdown.
He asked Anthropic for an itemized list of what had burned the allowance. The company did not provide one, though it agreed the pattern looked wrong. After it dug in, staff told him the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access.” The evidence, they said, fit either stolen session data or a hook-up to an outside service.
THE IDLE DRAIN
- The interval: Usage rose from 45% to 55% on August 5 with Cowork paused, Dispatch off, and no local Claude Code job.
- The plan: Claude Max 20x, billed at $200 a month.
- The refund: £44.49 for unused time after Anthropic suspended the paid account.
- The outage: The login came back after about two weeks, then he cancelled.
He posted the episode on Reddit and drew about 80 comments from people watching the same kind of spike. One account was auto-upgraded, charged, and run from 0% to 100% untouched. Another jumped from 0 to 49% in 12 minutes after a couple of prompts and a web search. A third burned its max allowance three days running with the owner doing nothing, then opened a GitHub thread where more users piled on.
Six Stealers Lifted the Same Cookie
Two of those users posted customer emails in which Anthropic said a bad actor was using common infostealer malware to copy Claude login sessions off PCs, then replay them to spend the paid allowance. De Swardt did not get that email. He says he found no malware on his machines and still cannot see how anyone got in.
We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage. Our systems detected this activity on your account, and we’ve therefore removed your card on file and signed out the sessions involved to help block further unauthorized access. If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.
Claude Team, email to affected subscribers
The notice named six malware families and stressed that phones and tablets did not appear to be involved. It also said Anthropic had no reason to believe the malware came from Claude, was installed through Claude, or was tied to anything the owner did inside the product. One emailed customer later said the infection arrived with a pirated game. That is one machine. Anthropic has not said what the others ran.
THE FAMILIES ANTHROPIC NAMED
| Malware | Systems named | What it copies |
|---|---|---|
| Vidar | Windows | Saved passwords, browser cookies, local credentials |
| Lumma (LummaC2) | Windows | Saved passwords, browser cookies, local credentials |
| StealC | Windows | Saved passwords, browser cookies, local credentials |
| RedLine | Windows | Saved passwords, browser cookies, local credentials |
| Acreed | Windows | Saved passwords, browser cookies, local credentials |
| Atomic Stealer (AMOS) | macOS, a small number of Macs | Saved passwords, browser cookies, local credentials |
A replayed cookie never visits the login page, so the password prompt and two-factor check never fire. The server sees an already signed-in browser. Signing the person out kills that copy. It does not clean the PC, which is why Anthropic told people to scan first and only then put a card back on the account.
Extra Usage Can Keep the Tab Open
The prize is not a saved Netflix password. It is a prepaid bucket that resets on a timer and, on some accounts, can keep billing after the included cap is gone. Anthropic’s help center lists a Max 20x plan at $200 a month, a Max 5x tier at $100, and Pro at $20. Max 20x is sold as 20 times Pro capacity per session. Those session limits reset every five hours, with a separate weekly cap on top.
WHAT A STOLEN LOGIN INHERITS
| Plan | Monthly price | Usage vs Pro |
|---|---|---|
| Pro | $20 | Baseline paid bucket |
| Max 5x | $100 | 5x Pro per session |
| Max 20x | $200 | 20x Pro per session |
On Pro and Max, that bucket is shared across Claude and Claude Code, which is why a browser cookie can feed a coding agent the owner never launched. De Swardt’s case went one step further. The stolen session was used to mint Claude Code OAuth tokens, so the drain could keep going even after a web logout if those tokens stayed live.
Paid plans can also switch to extra usage, billed at standard API rates, once the included cap is hit. The owner has to turn that on, set a monthly spend cap or pick unlimited, and prepay. Malwarebytes, reviewing the customer notice, flagged usage credits and auto-reload as the part that turns a hijack into a running tab: a thief can burn the included allowance, spend prepaid credits, and, if auto-reload is on, trigger more buys when the balance drops.
Support still tracks a total, not a line-by-line log, even when a customer asks. A spike can look like a busy afternoon. That is how this kind of theft can run for days before anyone files a ticket.
What a Stolen Session Can Still Open
A replayed Claude cookie inherits whatever that account can already reach, including chat history, files sitting in projects, and any connectors the owner approved. Anthropic has not said whether the sessions in this campaign touched those surfaces or only the usage meter. The accounts it flagged look like card-billed, self-serve logins, the kind no company identity desk can remotely kill.
Google Workspace connectors are available on individual Claude accounts, so a personal Pro or Max login can hold a live grant into Gmail or Drive. Read and search calls run without a fresh click. Send, reply, and delete stay behind an approval gate by default. If the inbox on the other end is a work inbox, the corporate admin who could pull that grant often does not know it exists, because the employee owns the Claude side of the hook-up.
Tom Kleinpeter, co-founder and chief architect at Common Room, said his firm refused local MCP servers for that reason. “We rejected local MCP servers early, full stop. That path meant storing a long-lived API key or token on someone’s machine. Steal that credential, and you can impersonate the user, pull their data, or do anything else the token allows, indefinitely, until someone notices and manually revokes it.”
WHAT WE KNOW
- The vector: Commodity infostealers copy live Claude browser sessions; a replay skips the password and 2FA page.
- The response: Anthropic signed affected people out, stripped saved cards, and refunded charges it classed as unauthorized.
- The product line: Anthropic says the malware was not installed through Claude, and phones and tablets did not appear to be involved.
WHAT IS UNCONFIRMED
- The count: Anthropic has not published how many accounts were hit, or whether any Team or Enterprise seats sat in the mix.
- The reach: It has not said whether replayed sessions opened connectors, project files, or only the usage bucket.
- De Swardt’s path: Staff could not tell if his session was stolen or tied to an outside service, and he received no infostealer warning.
Signing out of Claude kills the stolen cookie. It does not revoke a Google or Microsoft grant that Claude already held. That leftover consent is the part a usage refund never touches.
Claude Logins Already Sell in Bulk
Burning someone else’s Max cap is a cheap way to get frontier-model time. Google Threat Intelligence Group, in a September 8 tracker on adversarial AI, said buyer demand in underground forums is concentrating on Claude credentials on underground markets alongside Gemini logins and coding IDEs such as Cursor Pro, with average resale prices per account more than doubling in 2026. That market is why a cookie jar on a home PC is now worth scraping even when the rest of the loot is old passwords.
Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, has described the next step as cost harvesting, using the victim’s paid access “to conduct operations and generate massive bills as a byproduct.” He called the pattern LLM coin mining. CrowdStrike’s 2026 Threat Hunting Report cites one campaign that pushed nearly 200,000 API requests through a compromised cloud account’s model access in two minutes.
The stealers did not have to be built for Claude. They already vacuum cookies. Operators started picking Claude sessions out of the pile because the sessions spend like cash and, on a Max plan, spend a lot of it. De Swardt’s account looking like a third-party service for other people fits that resale logic: one paid login, many downstream jobs.
Getting the stealer onto the PC is a separate trade, and it is not only cracked games. Huntress documented a July 21-22 malvertising campaign that hit 29 organizations after Bing ads for a Claude desktop app led to a fake installer on a public Claude Artifact and dropped SectopRAT, a trojan that harvests browser logins, cards, cookies, and files. That campaign is not the same as the late-August cookie replay. It is how Claude-branded lures already put stealers on work machines of people who thought they were fetching the official app.
The Freeze That Stopped a Consultant’s Shop
Anthropic’s containment is blunt because the infected device is not its computer. It invalidates sessions, including server-side Claude Code tokens, pulls the saved card so extra usage cannot keep charging, and refunds the charges it can tag as unauthorized. For a casual chat user, that is an afternoon of friction. For someone whose agents load invoices, the freeze is the outage.
HOW THE SUMMER BROKE
- July 21-22, 2026: Huntress traces FakeAgent, a fake Claude desktop installer that hit at least 29 organizations with SectopRAT.
- August 4, 2026: De Swardt sees Max 20x usage climbing on a day he is not working.
- August 5, 2026: With every attached tool off, usage still rises from 45% to 55%.
- Late August 2026: Anthropic emails some customers, names six stealer families, signs them out, and strips saved cards.
- About two weeks after the freeze: De Swardt’s account is restored. He cancels and moves to Cursor.
He said the gap in support, plus the missing itemized log, soured him on Claude. Cursor lets him route work across several models, including cheaper open-source options, and in his view those models are close enough. “It’s not that much different or better,” he said, and he cannot see going back “without [Anthropic] actually having resolved the issue in any way.” He still sees no way for people in his position to protect themselves, because they cannot see what is consuming the tokens.
Asked how users should spot misuse, Anthropic declined to comment. The customer email is the closest public playbook, and it is a playbook that starts after the bucket has already moved.
Scan the PC Before the Card Goes Back
Anthropic’s own notice is the working checklist, and the order matters. A clean login on a dirty PC just mints a fresh cookie for the same stealer.
THE CLEANUP ORDER IN THE NOTICE
- Scan first: Remove malware from every computer used with Claude before signing back in or changing passwords.
- Lock the mailbox: Set a new password on the email that holds the Claude login, sign other devices out of that mailbox, and turn on two-factor authentication there.
- Rotate browser secrets: Change passwords that were saved in the infected browser, including bank, work, and cloud logins, and check card statements if the browser stored payment data.
- Then restore billing: Only after those steps should a card go back on the Claude account if the plan is meant to renew.
- Watch the meter: If usage still moves while Claude is idle, or a strange charge appears, write usersafety@anthropic.com.
Two-factor on Claude itself would not have stopped a cookie that was already trusted. The useful 2FA in this incident is on the email account, after the PC is clean, so the next login is not stolen from a live inbox. People running agents should also treat a sudden refill-then-drain as a session incident, not a billing quirk, and should revoke connector grants in Google and Microsoft, not only the Claude cookie.
De Swardt’s agents are on another stack now. The Max meter he could not itemize is still the product everyone else is watching, and a stolen session still spends like the owner until someone kills it.
-
NEWS4 weeks agoApple Labor Day Deals Hide June’s Memory Price Hike
-
NEWS3 months agoSaudi Arabia Mourns 14 Killed in Aramco Helicopter Crash at Ras Tanura
-
NEWS4 months agoEgypt’s 2026 World Cup Squad: Salah Chases History in Group G
-
GAMING2 weeks agoPalworld 1.0.4 Adds Palpedia Search After the 1.0 Launch
-
BUSINESS2 weeks agoTrump’s Bombardier Threat Lands First on Kansas Shops
-
NEWS3 weeks agoHawaii Reran Its Iniki Playbook as Lowell Missed Kauai
-
NEWS3 weeks agoRussia Hits Kyiv After Witkoff and Kushner Talks
-
ENTERTAINMENT2 weeks agoKing Charles Letter Keeps Harry and Meghan as Private Citizens
