AI & Technology

Hackers Steal Token Balances from Claude Subscribers

DROPIDEA By Admin
September 9, 2026 17 views
DROPIDEA | دروب ايديا - Hackers Steal Token Balances from Claude Subscribers

A recent incident affecting users of the AI assistant «Claude» reveals a troubling security vulnerability: the ability of attackers to breach subscriber accounts and covertly drain their usage token balances without their knowledge. More alarmingly, this type of theft can continue for months without being detected, due to the absence of precise tools that allow users to know who is consuming their balance.

How did the story begin?

An independent AI consultant from the United Kingdom noticed something strange in his paid «Claude Max» account. Even though he wasn't working on the platform one day, his token consumption rate kept rising steadily. The next day, he shut down all tools and tasks linked to his account and refrained from working entirely, yet the consumption rate continued to climb from 45% to 55% without any activity on his part.

Baffled by this phenomenon, he contacted «Anthropic», the company that develops the platform, and requested a detailed list of how his balance was being spent. The company was unable to provide that list, but acknowledged that there was a problem. It suspended his paid account, revoked all his sessions and login tokens stored on its servers, and granted him a partial refund of the remaining amount from his monthly $200 subscription.

The culprit: a compromised login session

After an investigation, «Anthropic» informed the user that it had found the source of the problem: a compromised session key that had been used to generate unauthorized access tokens. The company explained that the account «appeared to have been used by a suspicious external service to run activities on behalf of other people», without being able to determine how that party had obtained access.

In clearer terms, an attacker was able to access the account and covertly siphon off its token balance. And because technical support only tracks total consumption without breaking it down, this theft could have continued for a long time without detection.

Multiple cases, not isolated ones

When the user shared his experience on discussion platforms, he discovered he was not the only victim. Others reported similar suffering, and among the most notable accounts were:

  • A user who said his account was automatically upgraded without his consent, his credit card was charged, and consumption jumped from 0% to 100% without him touching the account.
  • Another who observed consumption rising from 0 to 49% in just 12 minutes, despite having executed only a few simple commands and a single search operation.
  • A third user whose entire balance was drained daily over three consecutive days without any actual use on his part.

Infostealer software

«Anthropic» sent warning messages to some of those affected, clarifying the nature of the threat, which stated: «We recently detected a malicious actor using common information-stealing software (Infostealers) to seize Claude login sessions from users' devices, then using them to access their accounts and consume their balances».

Infostealer software is a type of malware that installs itself on the victim's device and steals saved passwords, session data, and login credentials. The company confirmed that this software does not come from using «Claude» itself, but can be picked up from various sources online, such as downloading infected programs or clicking on tainted advertisements.

Upon detecting suspicious activity, the company took the initiative to log out the affected users, revoke existing permissions, grant some of them financial refunds, and warn them of the possibility that their devices were infected.

Absence of protection and tracking tools

Although the consultant's account was reactivated after about two weeks, the difficulty of obtaining quick support and the absence of a detailed consumption list prompted him to cancel his subscription and turn toward alternatives that allow the use of multiple models, including lower-cost open-source options. He noted that these models perform their tasks with nearly comparable efficiency.

The most important observation remains that, according to the affected user, the platform still lacks tools that allow users to see precisely what is consuming their balance, making self-protection from this type of breach extremely difficult.

Conclusion and lessons learned

This incident highlights the importance of securing users' devices against infostealer software, and the necessity of exercising caution when downloading programs or clicking on links and advertisements. It also reveals the need for AI platforms to develop transparent tools to monitor consumption and immediately alert users when any unusual activity is detected on their accounts.

✦ بقلم فريق دروب أيديا

DROPIDEA

We hope this article has added real value to you. At DROPIDEA, we always strive to deliver high-quality content that helps you grow and evolve in the digital space. Follow us for more useful articles and guides.

Tags

#كلود #أنثروبيك #أمن سيبراني #الذكاء الاصطناعي

Share Article