Your Claude subscription is being pillaged by hackers—and Anthropic is MIA
It turns out Claude isn't just generating code; it's generating free labor for cybercriminals. While Anthropic plays it cool with generic security advice, power users are watching their token limits vanish into thin air. Time to check your logs.
The nightmare started for Grant De Swaardt when he realized his Claude Max 20x account was hitting usage ceilings while he wasn't even at his desk. Despite killing every possible integration, the token consumption kept climbing, turning his professional assistant into an invisible ghost employee working for someone else. Anthropic eventually admitted that stolen session tokens were being hijacked to authorize unauthorized OAuth requests, essentially giving bad actors a backdoor key to his account without needing his password.
This isn't an isolated case of bad luck. A growing thread on Reddit and a report on GitHub confirm that users everywhere are seeing their usage graphs spike from zero to hero in minutes. The culprit appears to be infostealer malware—nasty little bits of code that scrape browser sessions—meaning the security failure isn't inside Claude, but on the user's own machine. When Anthropic finally catches these intrusions, they kill the session and offer a pathetic refund, leaving the victim to pick up the pieces.
De Swaardt, fed up with the lack of transparency and the black-box nature of Anthropic's usage monitoring, finally jumped ship to Cursor. Because the company refuses to provide granular logs, users have no idea if they are being hacked or if the platform is just being temperamental. It turns out that when your entire business relies on an AI agent, having that agent suddenly decide to work for a mysterious third party is a pretty significant career pivot.
Source: TechCrunch
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.