On August 4, Grant De Swardt, an AI consultant based in East Sussex, U.K., noticed unusual activity on his Claude Max 20x account. Despite not using the service, his token usage steadily increased. Attempts to disable all connected services did not stop the rise in consumption. After contacting Anthropic, the company behind Claude, his account was suspended, sessions invalidated, and a partial refund issued. Anthropic later identified that a compromised session key had been exploited to generate unauthorized OAuth tokens, allowing a third party to consume his token quota without permission. This unauthorized access disrupted De Swardt's business, which relies heavily on AI agents for various operational tasks. Further investigation revealed that multiple Claude users experienced similar issues, with some accounts rapidly depleting tokens without user activity. Anthropic attributed these incidents to infostealer malware that captures login sessions from infected devices, enabling attackers to access accounts remotely. The company responded by invalidating sessions, issuing refunds, and advising users to check for malware, though it emphasized that the malware was not linked to Claude itself. De Swardt, who found no evidence of malware on his devices, criticized Anthropic for lacking detailed usage tracking tools, making it difficult for users to detect unauthorized activity. After his account was restored, he chose to cancel his subscription in favor of alternative AI platforms offering more transparency and flexibility. Anthropic declined to provide further details on how users can identify or prevent such misuse. This situation underscores the challenges AI service providers face in securing user accounts and the importance of enhanced monitoring capabilities to protect subscription resources.