Hackers steal Claude tokens from subscribers

A UK consultant uncovers a security breach draining Claude AI account tokens, revealing critical gaps in platform transparency and user control.

By Central
Highlights
  • Grant De Swardt discovered unauthorized token usage on his Claude Max account while he was not using the platform.
  • Anthropic suspended the account and refunded a partial amount but did not provide itemized token usage.
  • The incident highlights the need for AI platforms to offer real-time monitoring and better security tools for power users.

Imagine discovering that your paid AI account has been burning through its $200 monthly token allowance while you were asleep, away from your desk, or actively not using it. This is not a hypothetical billing glitch or a phantom drain from a software bug. It is a full-blown security breach, and it is happening to subscribers of Anthropic’s Claude platform.

On August 4, Grant De Swardt, an independent AI consultant based in East Sussex, U.K., opened his Claude Max 20x dashboard and noticed something deeply unsettling. His token usage was climbing despite the fact that he had not performed any work that day. He had not run a single prompt, yet his meter was running.

How a UK Consultant Uncovered the Claude Token Heist

De Swardt is not a casual user. He runs a sole proprietorship helping small and mid-size businesses deploy AI agents for tasks ranging from loading purchase-order data from emails into accounting software to daily admin work, website design, and coding. He lives inside the Claude ecosystem. When he saw the anomalous usage on August 4, he instinctively knew something was wrong.

The next day, he performed a controlled experiment. He disabled every external integration he had attached to Claude. He paused all Cowork tasks, turned off Dispatch and cloud execution, and confirmed that no local Claude Code task was running. He then went about his day without touching the platform. Token consumption still climbed. In the clearest controlled interval, his usage increased from 45 percent to 55 percent while he performed no work whatsoever.

The Search for a Culprit

De Swardt contacted Anthropic and requested an itemized list of what was consuming his tokens. The company did not provide one. It did, however, agree that something was off. Anthropic suspended his paid account, invalidated all of his active sessions, revoked his server-side Claude Code OAuth tokens, and issued a partial refund of £44.49 for the remaining time on his subscription.

The suspension was not a minor inconvenience. It crippled his business. As a sole proprietor, his entire operational workflow runs through AI agents. “Like everything is just running through AI these days,” he said. The very infrastructure he relied on to generate revenue was suddenly, and without warning, shut off.

After an internal investigation, Anthropic identified the root cause. A compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. The company told De Swardt that his account appeared to have been accessed by an unauthorized third-party service to handle activity for other people. It could not determine exactly how the attacker obtained access. The evidence was consistent either with credentials or session data having been taken without his knowledge, or with the account having been connected to an outside service.

In plain English, a hacker had stolen his identity. They had infiltrated his account and were covertly siphoning off his prepaid tokens, effectively using his paid compute resources for their own purposes. And because Anthropic tracks total usage but not itemized usage, this kind of theft could have gone undetected for months.

Beyond One User: Reddit and GitHub Erupt with Similar Complaints

De Swardt took his experience to Reddit, posting a detailed account in the r/ClaudeAI community. The floodgates opened. Within eighty comments, it became clear that his case was not an isolated incident. It was part of a pattern.

One user claimed that their account was automatically upgraded to a paid tier without their consent, their credit card was charged, and the usage shot from zero to one hundred percent without them touching it. Another reported seeing usage jump from zero to 49 percent in just twelve minutes after using the platform for only a couple of prompts and a web search. A third user said their account burned through its max tokens every day for three consecutive days without them using it at all.

That third user escalated the issue to GitHub, creating a detailed bug report on the anthropics/claude-code repository under issue number 82506. The thread attracted other users sharing their own experiences of unexplained token depletion. The pattern was unmistakable: accounts were being hijacked, tokens were being stolen, and users were being left in the dark about how it happened or how to stop it.

How Are Hackers Stealing Claude Tokens?

The method, confirmed by Anthropic’s internal investigation, relies on a class of malware known as an infostealer. This malicious software is designed to infiltrate a victim’s computer and exfiltrate saved passwords, stored session data, and login credentials. Once an attacker possesses a valid Claude login session, they can use it to access the account directly, often bypassing standard security measures like two-factor authentication. From there, they mint new OAuth tokens to consume usage at will, leaving the legitimate user to foot the bill.

The Malware Behind the Theft: How Infostealers Compromise AI Accounts

Anthropic itself sent warning emails to some affected users, revealing the depth of the threat. “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the email stated.

Infostealers are a specific and insidious type of malware. They install themselves silently on a user’s computer through a variety of common infection vectors: downloading pirated or infected software, clicking on malicious advertisements, opening compromised email attachments, or visiting compromised websites. Once active, they scour the machine for browser-stored passwords, saved login sessions, cryptocurrency wallets, and API keys. The stolen data is then packaged and sent to a remote server controlled by the attacker.

Anthropic was clear that the malware did not originate from Claude itself. The company signed affected users out, invalidated existing authorizations, issued refunds in some cases, and warned them that their local machines may be compromised. The company declined to comment, however, on what specific tools or methods users could employ to identify misuse on their accounts.

Flying Blind: The Core Vulnerability of Token-Based Billing

The most alarming aspect of this entire episode is not the existence of the malware itself, but the structural vulnerability it exposes in how AI platforms like Anthropic handle billing and usage monitoring.

When asked how users can identify misuse or see a detailed breakdown of what is consuming their tokens, Anthropic declined to comment. That silence speaks volumes. In contrast to cloud computing giants like Amazon Web Services, Microsoft Azure, or Google Cloud Platform, which offer granular cost explorers, usage reports, and anomaly detection services, Anthropic currently offers no such visibility to its subscribers.

De Swardt’s experience crystallizes this problem. He requested an itemized list of token consumption. He was told it was not available. Without that data, users are flying blind. They cannot distinguish between legitimate usage from their own agents and fraudulent usage from an attacker. They cannot audit their own accounts. They cannot build a security response because they lack the forensic data needed to understand the attack.

“I don’t think there’s any way that these people can protect themselves,” De Swardt concluded after his ordeal. His account was reinstated after approximately two weeks, but the lack of transparency had already destroyed his trust.

Losing Trust: Why a Power User Cancelled Claude for Cursor

The business impact of a security incident is ultimately measured in churn. De Swardt cancelled his Claude subscription. He migrated to Cursor, a coding assistant platform that supports multiple models, including more affordable open-source alternatives.

“It’s not that much different or better,” he said of the other models he now uses. He cannot see himself returning to Claude unless Anthropic actually resolves the underlying issue in a meaningful way. He is not asking for perfection. He is asking for transparency. He wants tools that allow him to see what is consuming his tokens. He wants itemized billing. He wants the basic operational visibility that any cloud service provider has offered for years.

His defection is a canary in the coal mine for Anthropic. If power users, the ones who build their entire businesses around a platform, cannot trust the billing system or get straight answers from support, they will leave. In a fiercely competitive market where alternatives are multiplying, security and billing transparency are not nice-to-haves. They are competitive advantages.

The Deeper Problem: A Platform Built for Model Performance, Not Operational Security

The pattern of token theft against Claude users reveals a deeper tension at Anthropic. The company has focused intensely on model capability, safety research, and responsible AI deployment. These are laudable priorities. But the operational infrastructure surrounding the product security, billing, support, and user tooling has not kept pace.

Cloud services like AWS and Azure have dedicated security services GuardDuty, Sentinel, Security Command Center because they understand that security is a shared model and that users need tools to protect themselves. Anthropic, by contrast, does not even offer a way to see which application or session consumed a specific token. The absence of such basic instrumentation is a serious gap.

For the attacker, the economics are attractive. Stolen Claude accounts provide free access to one of the most capable AI models on the market. The tokens can be resold on underground forums or used to run private inference jobs at someone else’s expense. The lack of itemized billing means the theft can bleed out slowly over days or weeks, escaping notice until the user hits their cap. Even when discovered, the attacker’s session data is often long gone, leaving no trail back to the source.

What the Community is Demanding

The Reddit thread and GitHub issue have coalesced into an informal but vocal demand for change. Users are calling for three specific improvements. First, real-time usage monitoring with per-session or per-application breakdowns. Second, proactive anomaly detection that automatically flags unusual consumption patterns and alerts the user. Third, the ability to set hard usage caps or kill switches that can be triggered manually when suspicious activity is detected.

These are not unreasonable requests. They are standard features in almost any modern cloud or SaaS platform. Their absence in a product that charges $200 per month for power tier access is a significant oversight.

Anthropic has not indicated whether it plans to introduce any of these features. The company declined to comment for this article about its roadmap for billing transparency or security monitoring tools. For users like De Swardt, that silence is the most damning evidence of all.

The Future of AI Account Security

The theft of Claude tokens is a warning shot for the entire AI industry. As more businesses and individuals build their workflows around API-driven models, the security of those accounts becomes critical infrastructure. A compromised AI account is not just a stolen subscription. It can mean stolen intellectual property, disrupted business operations, and a loss of competitive advantage.

The era of trusting AI platforms based solely on model quality is ending. Users are beginning to evaluate platforms on the full stack of security, transparency, support, and operational tooling. Anthropic has a choice to make. It can continue to treat security and billing as back-office afterthoughts, or it can invest in the infrastructure of trust that every major cloud platform has long recognized as essential.

De Swardt is already gone. He is running his business on Cursor, using open-source models that he can monitor and control. He is not holding his breath for Anthropic to catch up. The question is how many other power users will follow him out the door before the company decides that visibility into your own usage is not a luxury, but a fundamental right of every paying subscriber.

Share This Article