Recently, several Claude users have reported on social platforms that their account quotas were rapidly being consumed without them using the service. According to Anthropic's investigation, hackers illegally accessed user accounts by stealing Claude login sessions through malware and secretly used their valuable call quotas.

The incident was first noticed by Grant D'Arcy, an independent AI consultant in East Sussex, UK, on August 4th. That day, he wasn't working, but his Claude Max 20x account usage kept increasing. The next day, he immediately disabled all tools connected to Claude, paused scheduled tasks and cloud execution functions, and even when no Claude Code tasks were running locally, the usage still jumped from 45% to 55%.

After communicating with Anthropic's customer service, the official acknowledged the abnormality in his account, then suspended the paid account, revoked all login sessions and server-side Claude Code tokens, and refunded £44.49 for the remaining subscription time. It is reported that the subscription price for Claude Max 20x is as high as $200 per month. The sudden suspension of the account directly impacted D'Arcy, who runs his own business. He relied on AI to help small and medium enterprises deploy intelligent agents to automatically extract purchase orders and input them into financial systems, and his daily administrative work, website design, and programming also heavily depended on this tool.

After a thorough investigation, Anthropic informed D'Arcy that the attacker had used a leaked Claude session key to generate unauthorized Claude Code OAuth tokens. The company found that his account seemed to be used by a suspicious third-party service to handle other people's tasks, but they still couldn't determine how the attacker obtained access. TechCrunch, a tech media outlet, pointed out that since Anthropic's current customer service system can only view total usage, it cannot provide users with detailed itemized usage records, so such misuse might not be detected for months.

As the incident spread on communities like Reddit and GitHub, more victims came to light. Some users reported that their accounts were automatically upgraded and charged without consent, with usage jumping from zero to 100% instantly; others said that they had sent just a few prompts and performed one web search, and the quota was nearly half consumed within 12 minutes; some even claimed to have been drained of their daily quotas after being idle for three consecutive days.

Some users shared Anthropic's security reminder emails, which showed that the company recently discovered attackers were using common information-stealing malware to steal passwords, session data, and login credentials saved on users' computers. Anthropic stated that once suspicious activity is detected, they will force users to log out, revoke authorization, and refund as appropriate. They also reminded users to check if their devices were infected with such malware, which spreads through unofficial downloads or malicious ads. However, D'Arcy himself did not receive this security alert, and has not found any evidence of his computer being hacked yet.

About two weeks after the account returned to normal, due to dissatisfaction with the slow handling progress and the lack of detailed usage details, D'Arcy eventually decided to cancel his subscription and switched to Cursor, which supports multi-model calls. Industry insiders believe that Anthropic still lacks necessary management tools to help users accurately identify the sources of quota consumption. In response to further questions from the media, Anthropic has chosen to remain silent.