415.tech
AI & tech, from the frontlines of Silicon Valley
Anthropic warns that infostealer malware is draining Claude subscribers' token allowances

Anthropic warns that infostealer malware is draining Claude subscribers' token allowances

Anthropic told affected users that a bad actor is lifting Claude login sessions off their computers with common infostealer malware, then spending the stolen accounts' paid tokens — in one case minting unauthorized Claude Code OAuth tokens from a compromised session key. Anthropic signed users out, invalidated authorizations, and issued partial refunds, but account support tracks only total usage, never an itemized breakdown. That detection gap is the developer-side problem: a machine-local infostealer defeats every server-side control, and no tool exists to show what is consuming an allowance, so theft can run for months unnoticed.

Source: techcrunch.com

Post on XEmail

In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task.

Grant De Swardt, AI consultant

Why this matters

  • → Stolen session keys bypass all server-side security, draining paid allowances for months without user awarenes
  • → Anthropic lacks itemized usage tracking, leaving subscribers blind to token theft.
  • → Machine-local infostealer malware defeats provider-side controls entirely.
Session theft meets blind billing
Also in this edition