{"id":29669,"date":"2026-09-09T03:34:49","date_gmt":"2026-09-09T01:34:49","guid":{"rendered":"https:\/\/www.mixtv1.com\/index.php\/2026\/09\/09\/hackers-are-stealing-claude-tokens-from-subscribers\/"},"modified":"2026-09-09T03:35:41","modified_gmt":"2026-09-09T01:35:41","slug":"your-claude-account-is-at-risk-hackers-are-stealing-session-tokens","status":"publish","type":"post","link":"https:\/\/www.mixtv1.com\/index.php\/2026\/09\/09\/your-claude-account-is-at-risk-hackers-are-stealing-session-tokens\/","title":{"rendered":"Your Claude Account Is at Risk: Hackers Are Stealing Session Tokens"},"content":{"rendered":"<h2>Unexplained Token Drain: A Security Wake-Up Call for Claude Users<\/h2>\n<p>In early August, Grant De Swardt, an AI consultant based in East Sussex, stumbled upon a troubling anomaly within his Claude Max 20x account. Despite remaining idle on August 4, De Swardt observed his token usage metrics steadily climbing, a clear indicator that his account resources were being siphoned off without his authorization.<\/p>\n<h3>The Mystery of Phantom Consumption<\/h3>\n<p>Determined to identify the source of the drain, De Swardt conducted a rigorous self-audit the following day. He systematically disconnected all integrations, halted active projects, and ensured no local Claude Code tasks were running. Even with his digital workspace completely dormant, the token consumption continued to surge. As he noted in an interview, his usage jumped by 10%-from 45% to 55%-during a period of total inactivity, confirming that the issue was not tied to his own workflows.<\/p>\n<p>This phenomenon highlights a growing vulnerability in the AI-as-a-service landscape. Much like a compromised API key in a software development environment, unauthorized access to AI tokens can lead to significant financial and operational losses. Recent industry reports suggest that as AI agents become more integrated into business infrastructure, they are increasingly becoming targets for malicious actors looking to hijack computational power for unauthorized data processing or automated scraping.<\/p>\n<h3>Anthropic\u2019s Response and Operational Fallout<\/h3>\n<p>When De Swardt reached out to Anthropic for an itemized breakdown of his usage, the company was unable to provide specific logs. However, they acknowledged the irregularity. In a move to mitigate further risk, Anthropic suspended his subscription, invalidated all active server-side tokens, and processed a partial refund of \u00a344.49 for the unused portion of his $200 monthly plan.<\/p>\n<p>For De Swardt, the impact was immediate and severe. His consultancy specializes in deploying AI agents for small and medium-sized enterprises-automating critical back-office functions such as extracting purchase order data from incoming emails and syncing it directly into accounting platforms. The sudden loss of access effectively paralyzed his ability to maintain these essential client services, illustrating how fragile business operations can become when they rely on centralized AI platforms without robust security oversight.<\/p>\n<p><a class=\"echo_read_more\" href=\"https:\/\/techcrunch.com\/2026\/09\/08\/hackers-are-stealing-claude-tokens-from-subscribers\/\" target=\"_blank\"> \u00bb More Info >>><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On August 4, Grant De Swardt, an independent AI consultant based in East Sussex, U.K., stumbled upon a digital mystery. Despite being completely offline, his Claude Max 20x account began racking up inexplicable token usage. By the following day, the situation had escalated; even after severing every connection and abandoning the platform entirely, the mysterious activity persisted<\/p>\n","protected":false},"author":55,"featured_media":29670,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wpai_generated_summary":"","wpai_meta_description":"","footnotes":""},"categories":[1399],"tags":[348,453,3398,36,756],"class_list":["post-29669","post","type-post","status-publish","format-standard","has-post-thumbnail","category-techplus","tag-ai","tag-anthropic","tag-hackers","tag-mixtv","tag-tc"],"_links":{"self":[{"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/posts\/29669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/comments?post=29669"}],"version-history":[{"count":1,"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/posts\/29669\/revisions"}],"predecessor-version":[{"id":29678,"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/posts\/29669\/revisions\/29678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/media\/29670"}],"wp:attachment":[{"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/media?parent=29669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/categories?post=29669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mixtv1.com\/index.php\/wp-json\/wp\/v2\/tags?post=29669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}