In early August, Grant de Swardt, an AI consultant from the UK, noticed unusual activity on his Claude Max 20x account despite not using the service. His token consumption increased significantly without any corresponding work. After disabling all integrations and pausing tasks, the unauthorized usage continued. Upon contacting Anthropic, the company behind Claude, de Swardt’s account was suspended, sessions invalidated, and he received a partial refund for his subscription.
Anthropic identified that a compromised Claude session key had been used to generate unauthorized OAuth tokens, allowing a third party to consume tokens without permission. The company could not determine exactly how the credentials were obtained, but the evidence suggested either stolen session data or unauthorized connections to external services.
De Swardt’s experience is not isolated. Discussions on Reddit and GitHub reveal multiple users reporting similar unauthorized token usage, with some accounts rapidly consuming their monthly allotments without user interaction. Anthropic confirmed that a malware strain known as an infostealer is responsible for stealing login sessions from users’ devices, which are then exploited to access accounts and drain tokens.
Anthropic has responded by signing out affected users, invalidating tokens, issuing refunds, and advising users to check for malware on their devices. The company emphasized that the malware is not linked to the Claude platform itself but can be acquired through various online threats.
Despite these measures, some users, including de Swardt, remain dissatisfied with the lack of detailed usage tracking and timely support. De Swardt ultimately canceled his Claude subscription, opting for alternative AI platforms that offer more transparency and flexibility. He expressed concerns that without better tools to monitor token consumption, users remain vulnerable to similar attacks.
Anthropic declined to provide further details on how users can detect misuse or additional security enhancements. This incident highlights ongoing challenges in securing AI service accounts and the importance of improved user controls and transparency in subscription-based AI platforms.