On August 4, Grant De Swardt, an independent artificial intelligence consultant based in East Sussex, United Kingdom, noticed a peculiar anomaly while reviewing his Claude Max 20x account. Despite taking the day off and performing zero professional tasks, his daily token usage metrics were steadily climbing.
The following day, in an effort to isolate the problem, De Swardt systematically disabled every application, integration, and tool he had ever attached to his Claude account and refrained from doing any work whatsoever. Even with all external connections severed, his token consumption continued to tick upward.
"In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task," De Swardt explained.
Stumped as to what was quietly devouring his expensive token allowance, De Swardt reached out to Anthropic support to request an itemized list of his account activity. While the company could not provide a granular breakdown of how the tokens were being spent, support representatives acknowledged that his usage patterns were abnormal and indicative of an underlying issue. Anthropic swiftly suspended his paid account, invalidated all of his active sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 to compensate for the remaining time on his $200-per-month subscription.
For a sole proprietor, however, the sudden suspension wreaked immediate havoc on daily operations. De Swardt operates as a forward-deployed engineer for hire, helping small and mid-size businesses set up custom agents capable of handling complex administrative workflows, such as automatically extracting purchase-order data from incoming emails and inputting it directly into accounting software.
Running a lean operation as a solo consultant means that De Swardt relies heavily on AI agents to manage his own business infrastructure, handling everything from routine daily administrative tasks and website design to advanced software coding. "Like everything is just running through AI these days," he noted, highlighting how deeply integrated these language models have become in modern freelance workflows.
After conducting an internal investigation into the incident, Anthropic followed up with De Swardt to share their findings. The company concluded that a compromised Claude session key had been leveraged by malicious actors to mint unauthorized Claude Code OAuth tokens. According to De Swardt, Anthropic informed him that his account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access."
Furthermore, Anthropic officials told him that the available evidence was consistent either with credentials and session data being surreptitiously harvested without his knowledge, or with the account having been inadvertently connected to an outside service at some point in the past.
In practical terms, an unauthorized third party had managed to secure access to De Swardt’s account and was covertly siphoning off his valuable token allocation. Because standard account support systems track aggregate usage metrics rather than itemized, transaction-level consumption, this type of stealthy theft could easily persist for weeks or months entirely undetected by the account holder.
Determined to see if others were experiencing similar mysterious depletions, De Swardt posted about his frustrating ordeal on a public Reddit forum. After the thread accumulated more than 80 comments, he quickly discovered that he was far from alone in his predicament.
One community member claimed that their account "was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it." Another user reported watching their token usage spike from zero to 49% within a mere 12-minute window, despite having used the platform for nothing more than a couple of basic prompts and a standard web search.
Another Claude subscriber recounted that their account burned through its maximum allowable token limit every single day for three consecutive days without any active input on their part, prompting them to open a formal GitHub issue report to track the glitch. Much like the Reddit discussion, multiple developers and users chimed in on the GitHub thread to report eerily similar experiences of vanishing tokens and unexpected account activity.
Several affected users shared copies of direct email warnings they had received from Anthropic, highlighting instances where the company’s internal monitoring systems had successfully identified and flagged the ongoing token theft.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage," the official warning email read.
Infostealers represent a pervasive category of malicious software designed to silently infiltrate a user’s local machine, systematically harvesting saved web browser passwords, sensitive session cookies, active login credentials, and authentication tokens.
Upon detecting unusual patterns of activity, Anthropic’s security systems took protective measures by signing users out of compromised sessions, invalidating existing authorization tokens, issuing targeted refunds, and warning victims that their local hardware might be infected with malware.
The company also emphasized that the infostealer malware did not originate from using the Claude platform itself. Such malicious payloads are frequently distributed across the broader internet through a wide variety of vectors, ranging from downloading pirated or infected software packages to clicking on malicious online advertisements.
Notably, Anthropic did not send one of these security warning emails to De Swardt. He maintains that he has found no evidence whatsoever indicating that his personal computer was compromised by malware, leaving him with no definitive answers as to how hackers managed to infiltrate his account credentials.
De Swardt’s Claude account was eventually reinstated by the platform after a suspension period lasting approximately two weeks. However, the cumbersome process of trying to secure timely support for a critical business interruption, compounded by the complete lack of granular, itemized usage transparency from Anthropic, left a lasting negative impression. Ultimately, the experience soured him on the platform entirely, leading him to cancel his subscription and migrate his workflow to Cursor, an AI-first code editor that offers the flexibility to utilize multiple different underlying models, including more cost-effective open-source alternatives.
Reflecting on his transition, De Swardt noted that these alternative models perform comparably to Claude in daily use. "It’s not that much different or better," he said, adding that he sees no compelling reason to return to Anthropic "without them actually having resolved the issue in any way."
He argues that Anthropic still critically lacks the internal auditing tools required to let users monitor precisely what tasks or processes are consuming their token allowances in real-time. Without such visibility, he believes customers remain exposed. "I don’t think there’s any way that these people can protect themselves."
When approached by reporters for further details regarding best practices or technical guidance on how users can proactively identify account misuse or unauthorized token drainage, Anthropic declined to provide a comment.
Leave a Reply