The Mechanics of Session Token Theft

Recent reports indicate that attackers are leveraging infostealer malware to compromise user machines and extract active session cookies. By stealing these tokens, bad actors can bypass standard authentication and gain direct access to a user's Claude account. Once inside, they mint unauthorized OAuth tokens to siphon off the subscriber's monthly token allowance, often using the hijacked accounts to power third-party services or other users' AI tasks.

The Visibility Gap in AI Platforms

A significant challenge for users is the lack of transparency regarding token consumption. Anthropic’s current support infrastructure does not provide itemized logs of usage, meaning users cannot easily audit their activity to identify anomalous patterns. In documented cases, users observed their token limits hitting 100% while their accounts were completely idle. Because the platform lacks granular reporting, this theft can persist for weeks or months before a user notices the discrepancy in their subscription value.

Defensive Limitations and Platform Risks

While Anthropic has begun identifying and proactively signing out users suspected of being compromised, the burden of security remains largely on the individual. Users who fall victim to these attacks are often left with little recourse beyond manual account resets and partial refunds. The lack of clear diagnostic tools or usage transparency has led some power users to migrate to alternative platforms like Cursor, which offer more flexibility in model selection and better visibility into how tokens are being consumed. To mitigate risk, users should treat their browser session data with the same level of security as a password, as modern infostealers prioritize these tokens to gain persistent, authenticated access to high-value AI accounts.