Anthropic Confirms Claude Account Hacked After Users Lose Access

Multiple Claude users have recently reported on social media that their account quotas were being depleted rapidly without any active usage. Anthropic’s investigation revealed that hackers gained unauthorized access to user accounts by stealing login sessions via malware, subsequently exploiting the victims’ valuable call quotas.
The breach was first identified by Grant D'Arcy, an independent AI consultant based in East Sussex, UK, on August 4. Although he was not actively working, his Claude Max 20x account usage continued to rise. The following day, he disabled all tools connected to Claude, paused scheduled tasks and cloud execution functions, and observed that usage still jumped from 45% to 55% even when no Claude Code tasks were running locally.
After contacting Anthropic’s customer support, the company acknowledged the anomaly, suspended his paid account, revoked all login sessions and server-side Claude Code tokens, and issued a refund of £44.49 for the remaining subscription period. The Claude Max 20x subscription costs up to $200 per month. This sudden suspension severely impacted D'Arcy, who runs his own business and relies on AI to help small and medium enterprises deploy intelligent agents for automatically extracting purchase orders and inputting them into financial systems, as well as for daily administrative work, website design, and programming.
Following a thorough investigation, Anthropic informed D'Arcy that the attacker had used a leaked Claude session key to generate unauthorized Claude Code OAuth tokens. The company discovered that his account appeared to be used by a suspicious third-party service to process other users’ tasks, though they could not determine how the attacker initially gained access. TechCrunch noted that since Anthropic’s current customer service system only displays total usage, it cannot provide itemized records, meaning such misuse might go undetected for months.
As the incident spread across communities like Reddit and GitHub, more victims emerged. Some users reported that their accounts were automatically upgraded and charged without consent, with usage jumping from zero to 100% instantly; others noted that sending just a few prompts and performing one web search consumed nearly half their quota within 12 minutes; some even claimed to have been drained of their daily quotas after being idle for three consecutive days.
Several users shared Anthropic’s security reminder emails, which indicated that the company recently discovered attackers using common information-stealing malware to harvest passwords, session data, and login credentials stored on users’ computers. Anthropic stated that upon detecting suspicious activity, they force users to log out, revoke authorization, and provide refunds as appropriate. They also advised users to check their devices for infection, noting that such malware often spreads through unofficial downloads or malicious ads. However, D'Arcy did not receive this security alert and has found no evidence of his computer being compromised.
About two weeks after his account returned to normal, citing dissatisfaction with the slow resolution process and the lack of detailed usage breakdowns, D'Arcy decided to cancel his subscription and switched to Cursor, which supports multi-model calls. Industry insiders suggest that Anthropic still lacks necessary management tools to help users accurately identify the sources of quota consumption. In response to further media inquiries, Anthropic has remained silent.
Related article
OpenAI Readies New Dual-Directional Voice Model GPT-Bidi-1
OpenAI is reportedly preparing to release GPT-Bidi-1, a next-generation bidirectional audio model designed to revolutionize ChatGPT’s voice capabilities. By adopting a bidirectional architecture, this breakthrough eliminates the limitations of tradit
OpenAI Launches Math and AI Advisory Group; Mysterious Model Solves 100 World-Class Problems in 24 Days
On September 22, OpenAI announced the formation of an "Advisory Group on Mathematics and Artificial Intelligence." Headquartered at the Institute for Advanced Study in Princeton, this independent body comprises nine mathematicians who operate separat
Senspeech X2.5 Twin Stars: First Million-Token Context on the Edge, Fully Trained with Domestic Computing Power
On September 1st, iFLYTEK’s wholly-owned subsidiary, Ciyuan Xinghuo, officially launched and open-sourced two edge-side general large models: Xinghuo X2.5-4B and Xinghuo X2.5-1.7B. These models are the first of their kind to natively support a contex
Related Special Topic Recommendations
Comments (0)
0/500

Multiple Claude users have recently reported on social media that their account quotas were being depleted rapidly without any active usage. Anthropic’s investigation revealed that hackers gained unauthorized access to user accounts by stealing login sessions via malware, subsequently exploiting the victims’ valuable call quotas.
The breach was first identified by Grant D'Arcy, an independent AI consultant based in East Sussex, UK, on August 4. Although he was not actively working, his Claude Max 20x account usage continued to rise. The following day, he disabled all tools connected to Claude, paused scheduled tasks and cloud execution functions, and observed that usage still jumped from 45% to 55% even when no Claude Code tasks were running locally.
After contacting Anthropic’s customer support, the company acknowledged the anomaly, suspended his paid account, revoked all login sessions and server-side Claude Code tokens, and issued a refund of £44.49 for the remaining subscription period. The Claude Max 20x subscription costs up to $200 per month. This sudden suspension severely impacted D'Arcy, who runs his own business and relies on AI to help small and medium enterprises deploy intelligent agents for automatically extracting purchase orders and inputting them into financial systems, as well as for daily administrative work, website design, and programming.
Following a thorough investigation, Anthropic informed D'Arcy that the attacker had used a leaked Claude session key to generate unauthorized Claude Code OAuth tokens. The company discovered that his account appeared to be used by a suspicious third-party service to process other users’ tasks, though they could not determine how the attacker initially gained access. TechCrunch noted that since Anthropic’s current customer service system only displays total usage, it cannot provide itemized records, meaning such misuse might go undetected for months.
As the incident spread across communities like Reddit and GitHub, more victims emerged. Some users reported that their accounts were automatically upgraded and charged without consent, with usage jumping from zero to 100% instantly; others noted that sending just a few prompts and performing one web search consumed nearly half their quota within 12 minutes; some even claimed to have been drained of their daily quotas after being idle for three consecutive days.
Several users shared Anthropic’s security reminder emails, which indicated that the company recently discovered attackers using common information-stealing malware to harvest passwords, session data, and login credentials stored on users’ computers. Anthropic stated that upon detecting suspicious activity, they force users to log out, revoke authorization, and provide refunds as appropriate. They also advised users to check their devices for infection, noting that such malware often spreads through unofficial downloads or malicious ads. However, D'Arcy did not receive this security alert and has found no evidence of his computer being compromised.
About two weeks after his account returned to normal, citing dissatisfaction with the slow resolution process and the lack of detailed usage breakdowns, D'Arcy decided to cancel his subscription and switched to Cursor, which supports multi-model calls. Industry insiders suggest that Anthropic still lacks necessary management tools to help users accurately identify the sources of quota consumption. In response to further media inquiries, Anthropic has remained silent.
OpenAI Readies New Dual-Directional Voice Model GPT-Bidi-1
OpenAI is reportedly preparing to release GPT-Bidi-1, a next-generation bidirectional audio model designed to revolutionize ChatGPT’s voice capabilities. By adopting a bidirectional architecture, this breakthrough eliminates the limitations of tradit
OpenAI Launches Math and AI Advisory Group; Mysterious Model Solves 100 World-Class Problems in 24 Days
On September 22, OpenAI announced the formation of an "Advisory Group on Mathematics and Artificial Intelligence." Headquartered at the Institute for Advanced Study in Princeton, this independent body comprises nine mathematicians who operate separat
Senspeech X2.5 Twin Stars: First Million-Token Context on the Edge, Fully Trained with Domestic Computing Power
On September 1st, iFLYTEK’s wholly-owned subsidiary, Ciyuan Xinghuo, officially launched and open-sourced two edge-side general large models: Xinghuo X2.5-4B and Xinghuo X2.5-1.7B. These models are the first of their kind to natively support a contex





Home






