Hackers Exploit Claude AI Tokens, Impacting Subscribers’ Accounts
2 min read
In early August, Grant De Swardt, an AI consultant based in East Sussex, U.K., noticed unexplained increases in token consumption on his Claude Max 20x account despite not actively using the service. After disabling all connected tools and pausing tasks, his token usage continued to rise, prompting him to contact Anthropic, the company behind Claude. While Anthropic did not provide a detailed breakdown of token usage, it acknowledged irregular activity, suspended his account, invalidated session tokens, and issued a partial refund.
De Swardt’s business, which relies heavily on AI-driven agents for tasks like automating purchase order processing and daily administrative work, was disrupted by the suspension. Upon investigation, Anthropic identified that a compromised Claude session key had been used to generate unauthorized OAuth tokens, allowing a third party to consume tokens without permission. The company could not determine exactly how the credentials were obtained but suggested either stolen session data or unauthorized external service connections.
This incident is not isolated. Discussions on Reddit and GitHub reveal multiple Claude users experiencing sudden, unexplained spikes in token usage, sometimes accompanied by unauthorized account upgrades and charges. Anthropic has informed some affected users via email that malware known as infostealers—designed to capture login sessions and credentials—was responsible for the breaches. The company has responded by signing out affected users, invalidating tokens, issuing refunds, and advising on potential malware infections.
Anthropic clarified that the malware was not linked to the Claude platform itself but could be contracted through various online activities. However, De Swardt did not receive such a warning and found no evidence of malware on his devices, leaving the source of the breach unclear.
Following a two-week suspension, De Swardt’s account was reinstated, but the experience led him to cancel his subscription. He cited the lack of detailed token usage information and slow customer support as key reasons, opting instead for alternative AI platforms offering multiple models and greater transparency.
The incident underscores a broader issue: users currently lack tools to monitor detailed token consumption, making it difficult to detect unauthorized use promptly. Anthropic has not provided guidance on how users can identify or prevent such misuse, raising concerns about account security and transparency in AI service usage.