← All stories

Claude Max Account Hit by Unauthorized OAuth Token Minting

Anthropic determined that a compromised Claude session key on a Claude Max 20x subscriber account was used to mint unauthorized Claude Code OAuth tokens, consuming the subscriber’s token allowance.

Why it matters

Unauthorized OAuth tokens can consume a subscriber’s capped model-token allowance before the subscriber uses it, reducing access to paid Claude Code capacity until sessions and tokens are revoked.

Hackers are stealing Claude tokens from subscribers | TechCrunch

TechCrunch

What changed

Anthropic determined that a compromised Claude session key on Grant De Swardt’s Claude Max 20x account was used to mint unauthorized Claude Code OAuth tokens, consuming his token allowance. TechCrunch reported that De Swardt saw usage rise from 45% to 55% during a period with no work, no active local Claude Code task, paused or completed scheduled tasks, and disabled cloud execution.

Anthropic suspended the $200-a-month account, invalidated its sessions and server-side Claude Code tokens, and issued a £44.49 partial refund. The company reportedly could not determine how the third party obtained access. De Swardt said support could provide aggregate usage but not an itemized record of the activity; other users described similar unexplained depletion in Reddit comments and a GitHub report.

Why it matters

Unauthorized token minting can use a subscriber’s paid, capped Claude capacity before the legitimate user does. The lack of attributable usage records can delay detection, while account-wide suspension stops both the apparent abuse and legitimate work.

For consultants such as De Swardt, who use Claude for coding, administration and client automation, the effect can extend beyond the account holder. If an affected account is needed to set up or maintain an agent workflow, small and mid-size business clients could face delayed support or deployment until secure access is restored. That transmission is interrupted if the consultant can shift to another account or tool, or if client workflows run independently.

The historical parallel

The case resembles the 2018 incident in which attackers used Tesla’s exposed cloud environment for concealed cryptocurrency mining: in both, unauthorized activity consumed computing resources paid for by the victim and could blend into aggregate usage. Tesla locked down and decontaminated its cloud platform within a day, although the total unauthorized mining remained unknown.

The difference is material. Tesla’s incident involved an exposed Kubernetes administration console and AWS credentials; this one concerns a subscriber’s Claude session key and OAuth-token minting. The access route in the Claude case remains unresolved, but the Tesla precedent shows that revocation can end active misuse without reconstructing prior consumption.

How the effects could spread

A compromised session key can first deplete a Claude Max subscriber’s token allowance. If the subscriber is an AI consultant, token exhaustion or account suspension can then constrain client-facing automation work, delaying setup or maintenance for businesses that depend on that consultant. The chain becomes more likely when client workflows require the affected account; it is dampened by backup accounts, alternative tools or independent deployed workflows.

Impact assessment

  • Claude Max subscribers: paid capacity can be depleted immediately by unauthorized activity.
  • AI consultants: session invalidation and suspension can interrupt coding, administration and client-agent work over days.
  • Small and mid-size business clients: workflow setup or support may be delayed if their consultant’s affected account is operationally necessary.
  • Anthropic: revocations and refunds can contain individual cases, but unattributed usage reports may increase security and support demands.

Scenarios

Our outlook (informed speculation):

Most likely: If the incident reflects compromised session data or third-party connections affecting a limited set of accounts, affected operators will reset sessions, review connected services and add backup access for critical work over coming weeks. This is more likely while Anthropic’s response remains focused on individual-account containment. Further reports of revocations and unauthorized OAuth activity would support this path; evidence of a broader service-level flaw would weaken it.

Upside: If Anthropic treats the attribution gap as a product-security problem, it could add itemized usage, token-origin information or tighter controls on session-derived OAuth tokens within six to 12 months. Earlier detection could reduce reliance on disruptive account-wide suspensions. New visibility and fewer unexplained exhaustion reports would support this outcome; aggregate-only usage records would weaken it.

Downside: If compromised session data can be reused or obtained through connected third-party services, more token-metered AI users may segment credentials and move critical automations to accounts with clearer audit trails over six to 12 months. Repeated unauthorized OAuth activity and suspensions would support this path; investigations tying cases to isolated user-side exposure would weaken it.

What to watch next

  • Additional substantiated reports linking compromised Claude sessions to unauthorized Claude Code OAuth tokens.
  • Whether Anthropic introduces attributable usage records or stronger controls on session-derived OAuth tokens.
  • Whether AI consultants adopt backup accounts, segmented credentials or alternative tools for client-critical automations.
Sources (3)
  1. TechCrunchHackers are stealing Claude tokens from subscribers | TechCrunch
  2. techcrunch.comPoor cloud security let hackers mine cryptocurrency on Tesla’s dime
  3. wired.comHack Brief: Hackers Enlisted Tesla’s Public Cloud to Mine Cryptocurrency

Comments

No comments yet.