Claude tokens

Claude tokens missing? Hackers may be using your account

Reading Time: 5 minutes

Claude users report cases where usage limits disappear quickly, even when they are not actively using the service. In some situations, consumption increases from a few percent to 100% in less than an hour. The situation gained attention after TechCrunch reported cases where tokens and sessions of some Claude subscribers may have been compromised and used without authorization.

The issue is particularly important for users of paid Claude plans, including those using Claude Code, as unauthorized consumption can quickly deplete the available limit and, in certain configurations, can incur additional costs.

Claude usage can increase without the user using the service

A case published on Reddit, in the r/ClaudeAI community, clearly illustrates the problem.

The author of the post states that they discovered two Anthropic invoices: one for a Max 20x subscription and another associated with additional usage. To verify what was happening, they monitored the Usage page without using Claude.

The result was surprising: session usage increased from 11% at 11:09 to 47% at 11:20, and by 11:40 it reached 100%.

In other words, the limit was almost completely consumed in about 31 minutes, while the author claims they were not using Claude during that time.

At the same time, in the area dedicated to Claude Code, the message “No Claude Code instance connected” was displayed, according to the screenshot and description published in the post.

Another concerning element: spending limit

The author states that the additional usage feature was disabled, but they noticed a spending limit of 2,000 euros in the settings.

This detail is relevant for AI account security because a user may start with a fixed subscription but may have associated mechanisms for additional usage or spending limits.

In the case of a compromised session, unauthorized access does not only mean consuming the limit included in the subscription. Depending on the account configuration, there may also be a risk of additional costs.

The author of the post states that they contacted Anthropic via chat and email to find out the source of the consumption and to request assistance.

What do Reddit users say about the Claude issue?

The case does not seem isolated in the ClaudeAI community. In the same discussion, several users reported situations where usage limits were consumed much faster than expected. Some claim to have seen very rapid increases in consumption, while others say they encountered problems even after checking or revoking sessions.

However, there is an important nuance: Reddit comments are user reports and do not, in themselves, constitute evidence of a general breach in Anthropic’s infrastructure.

Several hypotheses appear in the thread: from account bugs and usage calculation issues to compromised sessions or Claude Code being used in the background. Some users even claim to have rotated tokens and closed sessions but continued to observe unusual consumption.

Therefore, it is more accurate to talk about reports of unexplained consumption and investigated cases for possible unauthorized access, not about a confirmation that all Claude accounts have been hacked.

How can Claude sessions and tokens be stolen?

According to the TechCrunch report, Anthropic has identified cases where attackers used infostealer malware to steal authentication information and Claude sessions from users’ computers.

An infostealer is a type of malware specialized in collecting sensitive information from a device. This can include saved passwords, cookies, and data associated with authenticated sessions.

The risk is significant because an already authenticated session can allow an attacker to bypass some of the barriers encountered in a classic authentication attempt.

In such a scenario, the user may not immediately notice a suspicious login. Instead, the first signal may be an indirect one: the Claude limit is consumed without corresponding activity from the user.

Has Anthropic’s infrastructure been compromised?

There is not enough information to say that Anthropic’s infrastructure has been compromised on a general level. There are at least two scenarios that can produce similar results:

The first scenario: the user’s account or session is compromised. An attacker gains access to an authentic session and consumes the account’s resources.

The second scenario: there is a software bug, a usage accounting issue, or legitimate activity that is not clearly displayed to the user.

Reddit posts demonstrate that there are users observing unusual consumption, but they cannot determine the cause on their own.

However, the TechCrunch report adds an important element: Anthropic has warned in some cases about the use of infostealers and the compromise of sessions.

Therefore, users who observe unexplained consumption should treat the situation as a possible security incident until the cause is clarified.

What should you do if Claude consumes your tokens without explanation?

If you notice that the Claude limit decreases while you are not using the service, there are some reasonable measures to take.

1. Immediately check the Usage page

Note the time and usage percentage.

If the percentage increases while you are not sending prompts, take screenshots. These may be useful when contacting support.

2. Close active sessions

If there is a possibility of a compromised session, invalidating sessions can prevent the continued use of that access.

3. Revoke Claude tokens and associated keys

Claude Code users and those using integrations or automations should check active tokens and authentication keys.

4. Check your device for malware

If you suspect an infostealer, the issue should not only be addressed at the Claude account level.

Malware that steals sessions can also target other services used on the same computer.

5. Check additional usage settings

It is important to check if you have additional usage activated beyond the included limit and what the spending cap is.

In the case reported on Reddit, the author claims to have discovered a spending limit of 2,000 euros, even though they stated that extra usage was disabled.

6. Contact Anthropic

If usage continues to increase without explanation, contact Anthropic support and provide:

  • the time you noticed the problem;
  • the initial percentage and the final percentage;
  • screenshot evidence;
  • information about Claude Code and other integrations;
  • any additional invoices or charges;
  • the security measures you have already applied.

Why are Claude tokens a target for hackers?

AI tokens have become a resource with economic value. An attacker who gains access to a paid AI account can utilize the infrastructure already purchased by the victim. In the case of services with generous limits, this can mean a significant amount of AI processing.

Additionally, Claude accounts used professionally may be connected to development tools, software projects, and other services. This means that an AI account should no longer be viewed solely as a tool for conversations.

For a programmer or a company, Claude can become part of the work infrastructure. Compromising a session can thus have more significant consequences than simply losing a few messages.

The issue of consumption transparency

One of the most important aspects revealed by these cases is the need for more detailed monitoring of AI consumption.

If a user only sees that the limit has dropped from 10% to 100%, but cannot precisely identify what activity generated the consumption, investigating an incident becomes difficult.

For AI services with subscriptions and usage limits, detailed activity logs could become an important security component.

The user should be able to identify, as much as possible:

  • when the resource was consumed;
  • what type of service generated the consumption;
  • which session was involved;
  • whether the usage came from Claude Web, Claude Code, or another integration;
  • whether there were unusual activities.

Without this information, distinguishing between a billing error, legitimate consumption, and a compromised account can be difficult to establish.

What does the incident mean for Claude users?

For regular users, the main takeaway is simple: monitoring AI consumption must also be treated as a security measure, not just as a billing issue.

If the Claude limit increases rapidly without the user using the service, the situation should not be ignored.

The Reddit post analyzed here provides a concrete example: usage increased from 11% to 100% in about half an hour, while the author claimed they were not using Claude.

Meanwhile, reports of compromised sessions and infostealers show that users need to pay attention to the security of the device from which they access AI services.

Unexplained consumption of Claude tokens must be investigated

Cases reported in the Claude community and information reported by TechCrunch indicate a problem that users of AI services should not treat lightly.

However, it is important to avoid exaggerated conclusions. Abnormal consumption does not automatically demonstrate that an account has been hacked. There may also be a system error, an accounting issue, or activity that is not evident to the user.

At the same time, the existence of cases where authentication sessions have been compromised shows why AI account security is becoming increasingly important.

As Claude Code and other AI agents are integrated into professional workflows, tokens, sessions, and authentication keys must be protected as carefully as traditional passwords and API keys.

Sources: techcrunch.com, reddit.com

Leave a Reply

Your email address will not be published. Required fields are marked *