Hackers used common info-stealing trojans to steal Claude login sessions from users' computers, allowing them to access accounts and consume subscription token quotas without cracking passwords. A user reported in August that their account was using tokens during non-working hours, with similar cases later appearing on Reddit and GitHub. Anthropic said it is aware of the issue and is forcibly logging out affected users, revoking authorizations, and issuing refunds, but has not provided a detailed usage breakdown for users to self-check.