On August 4th, Grant de Swardt, an independent AI consultant from East Sussex, UK, noticed something strange going on with the Claude Max 20x account. Although he was not working that day, his token usage was increasing.
The next day, he disabled everything that was connected to Claude, making it unusable. Token consumption has increased again. “In the most clearly controlled intervals, this value increased from 45% to 55% when I was not doing any work, scheduled Cowork tasks were paused or completed, dispatch/cloud execution was disabled, and there was no corresponding active local load code task,” de Swardt told TechCrunch.
What used up his token allotment? He had no idea, so he contacted Anthropic and asked for an itemized list. Anthropic didn’t provide any information, but agreed that something was wrong. His paid account was suspended, all sessions and server-side Claude Code tokens were disabled, and he was given a partial refund of £44.49 for the remainder of his $200 per month subscription.
The outage has hit his business hard, he told TechCrunch. His job is to help small and medium-sized businesses set up agents (a type of forward-deployed engineer) that do tasks such as automatically loading purchase order data from email into accounting software.
As a sole proprietor, he relies on agents throughout his business, including day-to-day administrative tasks, website design, and coding. “Everything seems to be run by AI these days,” he said.
After investigating, Anthropic informed de Swardt that the culprit had been identified. A compromised Claude session key was used to create a fraudulent Claude code OAuth token. The company told him the account “appeared to have been used by a potentially unauthorized third-party service to process the activity of others, but we could not determine how it gained access.” “They claim the evidence is consistent with either the credentials/session data being obtained without my knowledge or the account being connected to an external service.”
In other words, the hacker had access to De Swart’s account and was secretly siphoning off his tokens. Account Support tracks total usage, but not itemized usage, even if requested, so this type of theft can go undetected for months.
He posted his experience on Reddit, and after 80 comments, he realized he wasn’t alone. One person claimed that his account was “auto-upgraded without my consent, my credit card was charged, and my usage automatically went from 0% to 100% without me touching it.” Another company saw usage go from 0 to 49 percent in 12 minutes, even though they were only using it for a few prompts and web searches.
One Claude user said that his account had been completely unused for three days, maxing out his maximum tokens each day, and he created a Github report about it. Similar to the Reddit post, other users also shared similar experiences there.
Two of them posted emails from Anthropic in which the company identified and alerted them that their tokens had been stolen.
“We recently became aware of a malicious actor who was using common information-stealing malware to steal Claude login sessions from people’s computers and use those login sessions to access and consume Claude accounts,” the email said. Infostealer is a type of malware that installs itself on a user’s computer and steals saved passwords, session data, and login credentials.
When Anthropic noticed suspicious activity, it signed the user out, disabled their existing authentication, issued a partial refund, and warned them that they may have been infected with malware.
The company also said that the malware was not caused by using Claude himself. Such malware can be obtained from various sources online, ranging from downloading infected software to clicking on infected advertisements.
Anthropic did not send those emails to Mr. de Seward. He claims he has found no evidence that his computer was compromised and says there is still no way to determine how the hackers gained access.
Mr. de Swardt’s Claude account was restored approximately two weeks later. But he was frustrated by the difficulty in getting help quickly with the problem and the lack of bulleted instructions. He canceled his subscription in favor of Cursor and its ability to use multiple models, including more affordable open source options.
In his experience, these other models work just as well as Claude. “It’s not that different, and it’s better,” he said, adding that he couldn’t imagine going back “unless we actually solve the problem in some way.” He said Anthropic still lacks tools that allow users to see what their tokens are being spent on. “I don’t think there’s any way for these people to protect themselves.”
When asked for information on how users can identify abuse, Anthropic declined to comment.
If you make a purchase through links in our articles, we may earn a small commission. This does not affect editorial independence.
