Skip to main content
Update

Malware is stealing Claude sessions to mint fake OAuth tokens and use accounts as their own

TechCrunch reports infostealer malware is stealing logged-in Claude sessions from users devices and using them to mint fake OAuth tokens that burn through the real owners quota. Anthropic itself was not hacked.

By Nattapon YongpaiboonCo-founder, Claude Thailand Community

TechCrunch reported that infostealer malware (which steals saved passwords and logged-in sessions) is being used to impersonate real Claude account owners. This is not Anthropic being hacked, it’s malware sitting on users’ own machines.

Illustration of a four-step flow. Step one is malware on the device, an infostealer stealing a logged-in session. Step two is minting a fake OAuth token, taking the stolen session to impersonate the owner without their knowledge. Step three, highlighted in orange, is using our quota as their own, burning through someone else’s work via our account, labeled with usage spiking abnormally. Step four is Anthropic automatically signing the user out. Below is a summary strip of three real cases: a Max 20x account where usage moved from 45 to 55 percent and got a £44.49 refund, another user whose usage spiked from 0 to 49 percent within 12 minutes, and another account that maxed out its quota every day for three days straight

How it works

The malware steals a Claude session key from an infected machine, then uses that session to mint a fake OAuth token to run its own work through the victim’s account, burning quota without them noticing. Anthropic confirmed the malware didn’t come from using Claude itself, but from other sources like downloading infected software or clicking on infected ads.

Real cases that got reported

Grant De Swardt, a Max 20x subscriber, noticed his usage climbed from 45% to 55% during a stretch where he wasn’t doing any work, with scheduled tasks and cloud execution both turned off. After Anthropic investigated and confirmed his session key had been stolen to mint a fake OAuth token, he received a £44.49 refund for the unused time.

After he posted on Reddit, other users came forward with similar experiences. One saw usage spike from 0% to 49% within 12 minutes, despite having only run a couple of prompts and a web search. Another reported via GitHub that their account maxed out its quota every single day for three days straight without any use at all.

How Anthropic responded

When the system detects anomalous behavior, Anthropic signs the user out, invalidates existing sessions/tokens, issues partial refunds, and sends a warning email that the machine may be infected. That said, De Swardt told TechCrunch, “I don’t think there’s any way that these people can protect themselves,” since there’s no tool for users to break down their own usage in detail, and Anthropic itself declined to comment on its detection methods. The article doesn’t give a total figure for how many accounts were affected.

Writer’s take

I think this is a good reminder that security doesn’t rest on Anthropic alone, our own machines have to be secure too. If you’ve ever installed cracked software or a sketchy browser extension, the risk goes up considerably.

If you’re using Claude, it’s worth checking your own usage. If the numbers move strangely while you’re not actually using it, check your machine right away.


Details in this article come from TechCrunch’s reporting. Read the original via the link below.

Read the original >

Get it by email

New articles, Claude updates and community event announcements. Sent occasionally, never often enough to annoy you.

The newsletter is written in Thai

Carry on the conversation in our Facebook group

Ask questions, share techniques, show your work and hear about upcoming events. The group is where most of the talking happens.