Anthropic has revealed that there have been instances of unauthorized consumption of Claude Code tokens from accounts in its generative AI service, Claude, where login sessions were hijacked. According to a report by TechCrunch on September 8 (local time), the issue came to light following complaints from users.

According to Anthropic, the company implemented forced session terminations and invalidated authentication tokens on the server side for some accounts where abnormal activity was detected. It also stated that it has provided refunds to some users.

Regarding the cause of the unauthorized access, the company cited the issuance of unauthorized OAuth tokens for Claude Code using stolen session information. Furthermore, it explained that a common cause identified was "infostealer" malware, which steals login sessions from PCs. However, the company noted that this malware is not contracted through the use of Claude itself.

Users have reported a series of incidents, including unauthorized plan changes and sudden spikes in token usage within short periods. On the other hand, it has been pointed out that the difficulty in early detection of unauthorized use stems from the fact that users can only verify the total amount of token consumption, making it difficult to grasp detailed breakdowns.


Source: