On August 4, Grant de Swardt, an independent AI consultant in East Sussex, noticed his Claude Max 20x account usage climbing despite him not working that day.
In this article
Unexplained token drain
The following day, he disabled every tool attached to the service. Token consumption still rose. In a controlled period, usage jumped from 45% to 55% while he performed no work, paused scheduled tasks, and disabled cloud execution. There was no active local task running, yet the drain continued.
De Swardt asked Anthropic for an itemised list of charges. The company did not provide one but agreed the situation was wrong. It suspended his paid account, invalidated all sessions and server-side tokens, and issued a partial refund of £44.49 against his $200 monthly subscription.
Business disruption
The suspension caused significant trouble for his business. He helps small and mid-size companies set up agents to automate tasks, such as loading purchase-order data from emails into accounting software.
As a sole proprietor, he relies on these tools for daily admin, website design and coding. “Like everything is just running through AI these days,” he said.
How the theft happened
Anthropic told de Swardt a compromised session key was used to mint unauthorized OAuth tokens. The company stated the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access.”
They said the evidence suggested credentials or session data were taken without his knowledge, or the account had been connected to an outside service.
Essentially, a hacker accessed the account and covertly siphoned tokens. Because support tracks total usage rather than itemised breakdowns, even upon request, such theft could have gone undetected for months.
A wider problem
De Swardt posted his experience on Reddit. After 80 comments, he found he was not alone. One person claimed their account was auto-upgraded without consent, their credit card charged, and usage shot from 0% to 100% automatically. Another saw usage go from 0 to 49% in 12 minutes after only a couple of prompts and web searches.
One user reported their account burning through maximum tokens for three days without any use and created a GitHub report. Others shared similar experiences there. Two of them posted emails from Anthropic where the company had identified and warned them that their tokens were being stolen.
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the email read. Infostealers are malware that installs on a user’s computer and steals saved passwords, session data and login credentials.
When Anthropic saw suspicious activity, it signed users out, invalidated existing authorisations, issued refunds and warned them they may have malware.
The company also said the malware did not come from using Claude itself. Such software can be picked up from many sources online, from downloading infected software to clicking infected ads.
De Swardt’s response
Anthropic did not send de Swardt one of those emails. He insists he found no evidence his computer was compromised and says he still has no way of determining how hackers gained access.
His Claude account was reinstated after about two weeks. But the difficulty of getting speedy help, plus the lack of an itemised usage report, soured him on the service. He cancelled his subscription in favour of Cursor and its ability to use multiple models, including more affordable open-source options.
In his experience, these other models work as well as Claude. “It’s not that much different or better,” he said, adding that he cannot see going back “without them actually having resolved the issue in any way.” He says Anthropic still lacks tools that allow users to see what is consuming their tokens. “I don’t think there’s any way that these people can protect themselves.”
When asked for information on how users can identify misuse, Anthropic declined to comment.
What it means
Users need to assume their accounts could be accessed by malware on their own devices or through third-party connections. Without detailed usage logs, detecting theft is difficult. Switching to platforms with granular billing and multi-model support may be the only way to avoid this risk.




