Anthropic warns Claude users after hackers allegedly siphon subscription tokens
Claude subscribers are reporting unexpected usage, with TechCrunch attributing some cases to allegedly stolen sessions and infostealer malware — but Anthropic has not yet published a detailed public advisory.

Claude subscribers are reporting a deeply unpleasant surprise: account usage allegedly rising while they are not using the service. TechCrunch reports that affected users were told infostealer malware may have stolen Claude login sessions, allowing attackers to consume paid Claude Code allowances.
The report is potentially important for anyone using Claude for software development, particularly customers on expensive plans whose usage limits can translate into a very real bill. But this is a security story with a large warning label: no detailed Anthropic security bulletin or direct public incident statement was located during the initial investigation.
What is being reported
TechCrunch reports that some Claude users noticed token usage increasing while their accounts were inactive. The publication says Anthropic told affected users that infostealer malware had been used to steal login sessions, and that those sessions were allegedly used to access accounts and consume Claude Code usage.
One affected user reportedly received a partial refund of £44.49 after paying for a $200-per-month plan. A related public GitHub issue describes Claude Max usage being consumed while the account owner was inactive. These are reported accounts and user evidence, not an independently measured estimate of the incident’s size.
The distinction matters. A stolen session could indicate malware on an individual computer, a compromised browser or another account-specific problem; it does not automatically establish a platform-wide breach. The public evidence reviewed for this draft does not prove how many users were affected, exactly how access was obtained or whether the reported malware mechanism applies in every case.
What users should do
Anyone who sees unexpected Claude or Claude Code usage should preserve account records, review active sessions and rotate credentials according to Anthropic’s current guidance. Users should also check their devices for infostealers and avoid assuming that a password change alone removes every existing session. The exact response steps should come from Anthropic’s official support or security channels.
Developers using agentic coding tools should pay particular attention to API keys, browser sessions, local credential stores and shared machines. A coding assistant account can expose more than a chat history if it is connected to repositories, terminals or paid usage, which makes unexplained token consumption worth investigating quickly.
Anthropic may still issue a fuller advisory. Until then, the strongest confirmed fact is that users and a major technology publication have reported suspicious consumption. The alleged malware method, scope and platform responsibility remain unconfirmed.
Our opinion
Unexpected AI usage is not a harmless billing oddity when a subscription costs $200 a month and the account may be tied to development tools. Anthropic should publish a clear incident update if it has identified a recurring attack pattern. Until it does, report this as a credible but unconfirmed account-security warning — not as proof that Claude itself has been breached.