Back

 Industry News Details

 
Claude users are reporting stolen tokens — even when they aren’t using Claude. Posted on : Sep 09 - 2026
One Claude Max subscriber noticed his token usage increasing even though he wasn’t working or running any Claude tasks. After investigating, Anthropic found that a compromised session key had been used to generate unauthorized Claude Code OAuth tokens.
 
What’s even more concerning is that other users have reported similar experiences — with some seeing their entire token allowance consumed within minutes or over several days without actively using Claude.
 
Anthropic says an infostealer malware campaign may be responsible, stealing login sessions from users’ computers and using them to access Claude accounts.
 
The bigger issue is visibility. If users can’t see exactly what is consuming their tokens, suspicious activity can continue for days or even months before being noticed.
 
🔐 AI accounts are becoming valuable targets, and protecting session credentials is becoming just as important as protecting passwords.
 
#AI #Cybersecurity #Claude #Anthropic #AIsecurity #Infostealer #GenAI