In a troubling development for users of Claude, a popular AI tool, hackers have been exploiting vulnerabilities to steal tokens from unsuspecting subscribers. This issue came to light when Grant De Swardt, an independent AI consultant from East Sussex, U.K., noticed unusual token consumption on his account despite not using the service.
On August 4, De Swardt observed a 10% increase in token usage overnight, prompting him to disable all connected services. Yet, token consumption continued to rise. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work,” he reported.
Seeking answers, De Swardt reached out to Anthropic, the company behind Claude, for an itemized usage report. While Anthropic did not provide the requested details, it acknowledged the issue, suspending his account and issuing a partial refund of £44.49 for the remaining subscription period.
The suspension had a significant impact on De Swardt’s business, which relies heavily on AI agents for various tasks, including data entry and website design. “Everything is just running through AI these days,” he noted.
After further investigation, Anthropic informed De Swardt that a compromised session key had been used to mint unauthorized OAuth tokens. The company indicated that his account appeared to have been accessed by an unauthorized third-party service, although the exact means of access remained unclear.
De Swardt’s experience resonated with other users, as he shared his story on Reddit, uncovering a community of individuals facing similar issues. One user reported an automatic upgrade to their account without consent, while another experienced a rapid spike in usage despite minimal interaction with the service.
In response to the growing concerns, Anthropic confirmed that it had identified a malicious actor using infostealer malware to compromise user accounts. This malware can capture saved passwords and session data, leading to unauthorized access.
Upon detecting suspicious activity, Anthropic took action by signing users out, invalidating existing authorizations, and issuing refunds. However, the company clarified that the malware did not originate from using Claude itself, emphasizing that such threats could arise from various online sources.
De Swardt, who did not receive a warning email from Anthropic, expressed frustration over the lack of clarity regarding the breach. He ultimately canceled his subscription in favor of alternative services that offer more transparency and flexibility.
Despite having his account reinstated after two weeks, De Swardt remains dissatisfied with Claude’s lack of tools for monitoring token usage. “I don’t think there’s any way that these people can protect themselves,” he stated, highlighting the need for improved security measures.
When approached for further information on how users can identify misuse, Anthropic declined to comment.
