Hackers are stealing Claude tokens from subscribers
- ID
- 22531
- Status
- summarized
- Published
- 09 Sep 2026, 5:10 AM
- Fetched
- 09 Sep 2026, 6:02 AM
- Provider
- TechCrunch
- Category
- technology
- Original URL
- https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers/
- Source URL
- https://techcrunch.com/feed/
Summary
- Score
- 7.5
- Created
- 09 Sep 2026, 6:03 AM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
Independent AI consultant Grant de Swardt discovered his $200/month Claude Max 20x account was burning tokens while he wasn't working, even after disabling all attached integrations. Anthropic investigated and found a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens, with an unknown third-party service using his account to handle activity for other people. Anthropic suspended his paid account, invalidated all sessions and server-side tokens, and issued a £44.49 partial refund—disrupting his agent-building business.
Why it matters
If you use Claude Code or Claude OAuth tokens in production agents, a stolen session key can let attackers mint tokens and drain your quota—and Anthropic's response is to suspend your entire account, not just block the attacker. Audit your Claude Code OAuth tokens and session keys now, and treat session credential hygiene as operational risk: a compromise doesn't just cost tokens, it takes your whole account offline.
Discussion angle
Anthropic's incident response nuked the victim's whole account instead of isolating the attacker—what does that mean for sole proprietors and small teams building businesses on Claude Code agents, and what mitigations (token rotation, separate accounts, monitoring) actually help?