FTFuture Technology
Hackers Are Draining Claude Subscribers' AI Credits and Anthropic Is Finally Talking About It
SECURITY

Hackers Are Draining Claude Subscribers' AI Credits and Anthropic Is Finally Talking About It

· 3 min read · By Nath Connell

Key takeaways

  • Hackers are stealing Claude API tokens by gaining unauthorised access to subscriber accounts through phishing and credential stuffing
  • Victims on pay-as-you-go API plans face unexpected charges; flat-rate subscribers lose their monthly allowances
  • Anthropic confirmed the issue and is urging users to enable two-factor authentication and audit API keys
  • There is an active underground market for stolen AI API credentials used for spam, content generation, and resale

Imagine paying for a premium AI subscription and then watching your monthly allowance drain away while you slept. That is exactly what happened to at least one Claude user last month, who noticed his account was consuming tokens at a rapid rate despite him not being logged in or actively using the service. Since then, Anthropic has confirmed the issue is real and has warned its user base that hackers are actively stealing Claude API tokens from subscribers.

This is a meaningful security story, not a niche one. Claude's subscriber base has grown substantially through 2026 as Anthropic has positioned itself as the serious, safety-focused alternative to OpenAI's ChatGPT. Many of those users are professionals and developers paying for Claude Pro or the API access tier, where token consumption translates directly to money spent. Having those tokens stolen is not just annoying, it is financially damaging.

How the Attack Works

The details emerging from TechCrunch suggest this is primarily a credential theft and session hijacking problem rather than a flaw in Anthropic's infrastructure itself. Attackers are obtaining Claude login credentials through the usual means: phishing, credential stuffing from previously leaked databases, and in some cases malware that extracts saved passwords from browsers. Once inside an account, they use the API access to run their own queries, burning through the victim's token allowance.

For users on flat-rate subscription plans, this means their monthly limits get exhausted before they can use them. For users on pay-as-you-go API plans, the implications are worse, because uncapped usage could result in significant unexpected charges before the victim even notices.

This attack pattern is not new. Similar token-theft campaigns have targeted OpenAI API users before, and there is an active underground market for stolen AI API credentials. Access to a high-tier AI account is commercially useful, whether for running spam campaigns, generating content at scale, or reselling access to others who want to avoid paying for it themselves.

What Anthropic Is Doing

Anthropologic has issued warnings to users and is advising people to enable two-factor authentication on their accounts, review their usage dashboards regularly for unexpected consumption spikes, and revoke any API keys they do not recognise. The company is also, according to reports, working on better anomaly detection to flag unusual usage patterns before they run out of control.

The future, in 3 minutes a day. The biggest tech story explained every morning, free. Get the briefing →

But here is the uncomfortable truth: two-factor authentication should have been more aggressively encouraged or required from the start. Any platform where account access has real financial value needs stronger default security. Making 2FA optional is a choice, and it is one that leaves users exposed.

The broader issue is that AI subscriptions are now worth stealing in a way they simply were not two or three years ago. A Claude Pro account or a high-tier OpenAI API key is a monetisable asset, and the security posture of these platforms has not always kept pace with the commercial value they represent.

What You Should Do Right Now

If you are a Claude subscriber, log in and check your usage dashboard today. If you are seeing consumption you cannot account for, change your password immediately and revoke all active API keys before generating new ones. Turn on two-factor authentication if you have not already done so. If you have automatic billing enabled and suspect unauthorised use, contact Anthropic's support team directly and document everything.

Also worth doing: use a password manager and make sure your Claude credentials are unique and not reused from any other service. Credential stuffing attacks only work because people reuse passwords, and that is one vulnerability that is entirely within your control to close.

Anthropologic being transparent about this, rather than quietly patching it, is the right call. But the fact that it got to this point at all suggests the industry needs to treat AI account security with the same urgency it brings to everything else.

Sources

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.

Enjoyed this? Get the briefing.

One email, every weekday: the top story, a useful tool, and what matters in tech - in under 3 minutes.

More from Future Technology

Security

Your Windows 11 upgrade checklist, eleven months into an unpatched Windows 10

Security

"A Shipping Partner Breach Just Exposed Thousands of Trezor Buyers"

Security

"A Chinese Hacking Crew Turned a VMware Bug Into a Ransomware Pipeline"

Security

Home Network Security Settings for 2026: Nine Router Changes Worth Twenty Minutes