Claude’s quota disappeared mysteriously; Anthropic confirmed that the account was hacked.
2026-09-09 07:29Cybersecurity🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
4mentions
SummaryAI generated
On September 8, 2026, several Claude users noticed that their account quotas were quickly consumed without any apparent action. British consultant Grant Deswart encountered this issue on August 4, and his account’s usage continued to rise even when there were no local tasks. Anthropic confirmed that hackers used stolen login sessions to exploit the quotas. The attackers obtained session keys through information theft malware and generated OAuth tokens, consuming quotas or automatically upgrading subscriptions without the users’ knowledge. Since Anthropic’s customer service system could only view total usage without detailed records, the theft may have gone undetected for several months. Due to slow processing and lack of detailed recording tools, Deswart ultimately canceled his subscription and switched to Cursor. Anthropic has suspended the relevant accounts, cancelled the tokens, and refunded the fees.