Hackers Are Draining Paid Claude AI Accounts — Users Fight for Refunds
Hackers used stolen logins to burn people's paid AI time — without them lifting a finger.
Imagine paying a monthly subscription and then finding out someone else used almost all of it — while you weren't doing anything. That's what happened to Grant De Swardt, an AI consultant in the U.K. He noticed his Claude Max account was burning through its usage allowance even on days he didn't work. He asked for an itemized list from Anthropic, the company behind Claude, but it couldn't break things down that way.
After investigating, Anthropic found the real cause: a hacker had stolen a session key from his computer and used it to create tokens for other people to use his account. This kind of theft isn't just one person's bad luck. Other users reported similar problems on Reddit and GitHub. Some said their usage went from zero to 49% in minutes. Anthropic later admitted in emails that a "bad actor" was using malware to steal login sessions from people's computers.
The scary part is that users can't easily detect or prove the theft. There's no itemized bill that shows exactly which conversations or tasks used your credits. Anthropic suspended De Swardt's account, refunded a small portion, and then reinstated it — but the experience drove him to cancel. He switched to a different AI tool called Cursor.
The lesson: If you pay for any AI service, keep an eye on your usage numbers. And be careful about what you download or click, since thieves often plant these "infostealer" programs on otherwise normal-looking websites or software.
- Hackers use malware to steal saved login data and silently consume paid AI subscriptions.
- Victims often only realize after seeing unusual usage spikes — there's no itemized activity log.
- Anthropic says the theft doesn't come from Claude itself; users can get infected from downloads or fake ads.
Why It Matters
Your paid AI credits can be drained invisibly by criminals — check your usage and protect your logins.