A man who works alone in East Sussex, U.K., claims that someone took tokens from his paid Claude account through hacking. He discovered the theft not by noticing missing funds, but because his account’s usage kept going up while he was not doing any work.
Grant De Swardt helps small and mid-size companies get AI agents up and running. On August 4, he saw that his Claude Max 20x account was using tokens fast despite him not touching it that day. He cut off everything connected to Claude the very next day. Even then, token use kept going up.
“In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt told TechCrunch.
The Missing Itemized Bill
Anthropic was asked by De Swardt to supply a detailed breakdown of where his allowance was going. It did not deliver one, though it acknowledged that something was wrong. As a result, the company put his paid account on hold, made his sessions and server-side Claude Code tokens null, and granted him a partial refund of £44.49, covering the remainder of his $200-per-month subscription.
The suspension hit his business hard. He relies on agents for daily admin tasks, website design, and coding. “Like everything is just running through AI these days,” he said.
What Anthropic Found
After investigating, Anthropic told De Swardt the culprit was a compromised Claude session key used to mint unauthorized Claude Code OAuth tokens. The company said the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access,” he told TechCrunch.
“They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service.”
Another way to put it is that a hacker silently drained his tokens. Since account support follows total consumption without breaking it down into individual items, and does so even when asked to do otherwise, this sort of pilfering might have continued for months without being noticed at all.
Other Users Report the Same Problem
On Reddit, De Swardt shared his story, and after 80 responses came in, he realized he was not the only one. Other users chimed in with reports that matched his own problems:
- One person said their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.”
- Another saw usage go from 0 to 49% in 12 minutes, when all they had used it for was a couple of prompts and a web search.
- One user said their account burned through its max tokens every day for three days without them using it at all; this person then created a GitHub report about it.
Anthropic’s Malware Warning
Two individuals received notices from Anthropic alerting them that their tokens were under attack, with the firm having detected the theft and sounded the alarm.
The message began with these words: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,”.
Infostealers are a form of malware that install themselves on a user’s machine and take saved passwords, session information, and login details. After Anthropic noticed something out of the ordinary, it logged the users out, rendered existing authorizations null and void, gave back some money, and cautioned them that they might have malware.
The firm added that the malware did not stem from using Claude directly. Instead, such malware can be gathered from numerous online sources, including downloading infected software or clicking on infected ads.
De Swardt’s Doubts
De Swardt says Anthropic never sent him an email like that one. He says he found no sign that his computer was compromised, and he still has no way to determine how hackers managed to get in.
He got his Claude account back after roughly two weeks, yet the trouble of securing prompt assistance, combined with the absence of a detailed breakdown of charges, left him dissatisfied with the service.
He switched from his original service to Cursor because it lets him use multiple models, including more affordable open source ones. He found that these other models perform just as well as Claude, “It’s not that much different or better,” he said, and added that he can’t see going back “without [Anthropic] actually having resolved the issue in any way.”.
No Protection in Sight
He says Anthropic still lacks tools that allow users to see what’s consuming their tokens. “I don’t think there’s any way that these people can protect themselves.”
Anthropic did not respond when asked about how users can spot misuse.
Source: techcrunch.com
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

