← Overzicht

Infostealers siphon Claude Max tokens; Anthropic warns users

· opgehaald 06:11

TechCrunch: attackers use common infostealer malware to grab Claude login sessions, mint unauthorized Claude Code OAuth tokens, and burn Max usage. Anthropic has invalidated sessions, issued refunds, and emailed some victims — but still lacks itemized usage for users to self-detect.

On 8 Sep 2026 TechCrunch reported Claude Max subscribers seeing unexplained token burn. In one documented case (Grant De Swardt, Max 20×), usage rose while he did no work; Anthropic later said a compromised Claude session key minted unauthorized Claude Code OAuth tokens, possibly via a third-party service, suspended the account, invalidated sessions, and refunded part of the month. After he posted on Reddit/GitHub, others reported similar silent drain; Anthropic emails to some users blamed common infostealer malware stealing Claude login sessions from PCs (not Claude itself). The company signs victims out, kills authorizations, and sometimes refunds, but declined to detail how users can spot misuse — and still does not offer itemized usage on request.