The Silent Drain: How Infostealer Malware is Hijacking Claude Accounts
For the modern professional, artificial intelligence has transitioned from a novelty to a critical piece of digital infrastructure. For Grant De Swardt, an independent AI consultant based in East Sussex, U.K., his Claude account was not just a tool—it was the engine room of his business. However, on August 4, that engine began to misfire in a way that would expose a growing, alarming vulnerability in the AI ecosystem: the rise of "token theft."
De Swardt’s experience, which began with a puzzling spike in his token usage, has ballooned into a broader investigation into how malicious actors are exploiting AI session data, leaving users to foot the bill while platforms struggle to provide transparency.
The Chronology of a Digital Heist
The trouble started on a quiet Sunday. De Swardt, who uses the Claude Max 20x subscription to facilitate his work as an AI agent architect, noticed his token usage climbing despite the fact that he was not actively working. Given the nature of his business—helping small and medium-sized enterprises (SMEs) automate tasks like email-to-accounting data entry—he is hyper-aware of his system’s resource consumption.
On August 5, determined to find the source of the drain, De Swardt performed a controlled test. He disconnected all integrations, paused his "Cowork" tasks, disabled cloud execution, and ensured no local Claude Code tasks were running. Despite these precautions, his token usage jumped from 45% to 55%.
"In the clearest controlled interval, it increased from 45% to 55% while I performed no work," De Swardt explained.
He immediately reached out to Anthropic support, requesting an itemized breakdown of his usage to identify the source of the requests. Anthropic was unable—or unwilling—to provide this level of detail. However, the company acknowledged the anomaly. Within a short window, Anthropic suspended his account, invalidated all active sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remainder of his $200-a-month subscription.
The suspension, while necessary to stop the bleed, crippled De Swardt’s business. As a sole proprietor who relies on AI for everything from website design to administrative operations, the loss of access was catastrophic. It took two weeks for his account to be reinstated, during which time his professional operations ground to a halt.
Supporting Data: A Widespread Phenomenon
De Swardt’s story is far from an isolated incident. After documenting his experience on Reddit, he was met with a flood of similar reports. The Reddit thread, which garnered over 80 comments, revealed a pattern of behavior that suggests a coordinated effort by bad actors to exploit AI accounts.
One user reported their account being auto-upgraded without their consent, leading to an immediate charge on their credit card and a rapid depletion of tokens. Another user observed their usage hit 49% in just 12 minutes, despite having performed only a few minor prompts.
The issue has also spilled over into developer communities. A report filed on the official anthropics/claude-code GitHub repository highlighted a user whose account burned through its maximum daily allowance for three consecutive days while completely idle. The thread became a hub for victims sharing similar grievances, many of whom were baffled by the lack of visibility into their own account usage.
The Mechanics of the Breach: Infostealers
After conducting an internal investigation, Anthropic eventually provided De Swardt with a diagnosis: a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens.
The company suggested that a third-party service was using De Swardt’s credentials to "handle activity for other people." While the exact point of entry remains a mystery to De Swardt, Anthropic’s official stance points toward the growing threat of "infostealer" malware.
Infostealers are a specific class of malicious software designed to harvest sensitive data from infected machines. They operate in the background, scraping saved passwords, browser cookies, and—crucially—active session tokens. Once a session token is stolen, the attacker can import it into their own browser or API client, effectively masquerading as the legitimate user.
In some cases, Anthropic has proactively identified this activity, sending warnings to affected users. One such email read: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions… then using those login sessions to access Claude accounts and consume their usage."
The irony, as noted by security experts, is that the infection rarely comes from the AI platform itself. Users can pick up this malware through a variety of vectors: downloading "cracked" software, clicking on malicious advertisements, or visiting compromised websites. Because the session token allows the attacker to bypass multi-factor authentication (MFA) and password prompts, the theft is silent, persistent, and highly difficult to detect until the victim hits their usage limit.
Implications: The Transparency Gap
The most significant takeaway from this crisis is the lack of transparency afforded to the average user. De Swardt’s frustration stems not just from the theft of his tokens, but from the inability to audit his own account.
The Need for Audit Logs
Currently, Anthropic does not provide an itemized list of prompts, IP addresses, or geographic locations associated with token usage. For a business owner like De Swardt, this is a major security flaw. If a company cannot provide a detailed log of activity, it becomes nearly impossible for a user to perform their own forensic analysis or to prove unauthorized access.
The "Black Box" of AI Support
When a user suspects their account is compromised, they are currently at the mercy of the provider’s internal support team. If that team is understaffed or lacks the tools to provide granular data, the user is left in the dark. De Swardt noted that the process of getting his account back was slow and opaque, leading him to ultimately lose faith in the platform.
The Shift Toward Alternatives
The experience has had a permanent impact on De Swardt’s workflow. He has since canceled his Claude subscription in favor of Cursor, an IDE that allows for the use of multiple models, including more affordable open-source options.
"It’s not that much different or better," De Swardt said of his transition. He emphasized that as long as Anthropic fails to provide users with the tools to monitor their own usage—such as session management dashboards or granular activity logs—he has no intention of returning.
The Path Forward: Protecting the User
As AI becomes the backbone of the digital economy, the security of these accounts must be elevated to the level of banking or cloud computing services.
- Session Management: Platforms must provide users with a "Global Sign-out" button that invalidates all active sessions across all devices.
- Usage Transparency: Detailed, exportable logs of prompt activity (at least by timestamp and token count) are essential for accountability.
- Proactive Alerts: If an account’s usage pattern deviates significantly from the user’s historical norm, systems should trigger an automated security hold and a notification to the account owner.
- User Education: As Anthropic has begun to do, platforms must proactively inform users about the risks of infostealer malware, which remains the primary vector for these attacks.
When asked for comment regarding specific measures to help users identify misuse or to provide greater transparency, Anthropic declined to comment.
For now, the burden of security remains largely on the user. In an era where a stolen session cookie can lead to thousands of dollars in unauthorized usage, users must be vigilant about the software they install and the websites they visit. De Swardt’s warning remains stark: "I don’t think there’s any way that these people can protect themselves" without a fundamental shift in how AI providers manage user security and transparency.
Until that shift occurs, the "silent drain" of token theft will likely continue to plague the AI industry, turning productivity tools into liabilities for the very people they were meant to empower.