Tuesday, September 8, 2026
venfeedSubscribe

Infostealer malware is draining paid Claude accounts

Attackers lift active sessions from infostealer logs, mint Claude Code OAuth tokens and burn through subscribers' usage. Anthropic is revoking sessions and issuing refunds, without saying how to prevent it.

Venfeed EditorSeptember 8, 20262 min read
ShareXBlueskyLinkedInHNRedditEmail

Attackers are extracting active Claude sessions from infostealer malware logs and using them to consume paid subscribers' token allowances. Anthropic has been signing out affected users, invalidating authorisations and issuing refunds.

In at least one case a stolen session key was used to mint Claude Code OAuth tokens, letting the attacker operate the account persistently rather than only for the life of the captured session.

What victims saw

The accounts documented by TechCrunch show the same pattern: consumption with no corresponding activity.

Grant De Swardt first noticed unauthorised usage on 4 August, on a Claude Max 20x subscription costing $200 a month, watching his allowance move from 45 percent to 55 percent while he did nothing. Another user reported going from zero to 100 percent in half an hour. A third had an account burning through its maximum daily allowance for three days without using it. More cases have surfaced on Reddit and GitHub.

De Swardt's account was later suspended and he received a refund of £44.49.

Why AI subscriptions are a good target

A stolen Netflix login is worth little. A stolen frontier model subscription is worth what the inference costs, and the highest tiers cost hundreds of dollars a month for a reason.

That makes these accounts directly monetisable in a way most consumer credentials are not. An attacker with a working session has metered access to a frontier model with no payment instrument to compromise, no fraud rails to trip, and — as the OAuth minting shows — a route to durable access. Reselling that capacity, or using it for work that would otherwise be refused or logged against the attacker's own identity, is straightforward.

The session-token theft route also bypasses the defence users are told to rely on. Multi-factor authentication protects login. It does nothing about a session cookie lifted from an already-authenticated machine.

What Anthropic has not done

The company identified the problem, cut sessions, invalidated authorisations and refunded. That is competent incident handling.

What is missing is prevention and transparency. Anthropic declined to give itemised usage records to affected users, which means a victim cannot see what was run on their account — an unsatisfying position for anyone whose subscription is attached to their work, and a real problem for a business customer who has to answer questions about what a compromised session did.

The company has also not issued guidance on protection, and the obvious mitigations are not the user's to implement. Shorter session lifetimes, binding sessions to a device or network, anomaly detection on consumption patterns, and requiring re-authentication before minting long-lived OAuth tokens are all platform controls.

A consumption pattern that goes from zero to 100 percent in 30 minutes is exactly the kind of anomaly a provider can detect. In these cases the users noticed first.

The wider pattern

This sits alongside the month's other agent-adjacent security failures: an actively exploited authentication bypass in LiteLLM's MCP handling, an actively exploited Chrome zero-day, and the July incident in which an OpenAI agent reached production systems at Hugging Face.

The common feature is that AI infrastructure has inherited the whole existing attack surface — credential theft, session hijacking, dependency vulnerabilities — while adding tokens that are directly convertible to value.

Anthropic has not said how many accounts were affected.

Venfeed Editor
Editor in chief

Runs the newsroom. Rename this profile in the studio to your own byline.

The Feed · weekdays, 6:30am ET

Every weekday, the AI stories that moved money or shipped code.

No cross-posting, unsubscribe anytime. See all newsletters