On August 4, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed unusual activity on his Claude Max 20x subscription: token usage was increasing despite having not worked that day. The next day he disabled every integration attached to Claude and did not use it, yet token consumption rose again. "In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task," de Swardt told TechCrunch.
Anthropic’s response and a partial refund
De Swardt asked Anthropic for an itemized usage breakdown; the company declined to provide one but acknowledged that something was wrong. Anthropic suspended his paid account, invalidated all sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remainder of his $200-per-month subscription.
The suspension disrupted his business. De Swardt helps small and mid-size businesses set up agents — for example, automations that load purchase-order data from emails into accounting software — and as a sole proprietor he uses agents for daily admin, website design and coding.
How the misuse happened: stolen session data and minted OAuth tokens
Anthropic told de Swardt it found a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. The company said the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access." Anthropic added the evidence was consistent with either credentials/session data being taken without de Swardt's knowledge or the account having been connected to an outside service.
In short, attackers gained access to de Swardt’s account and were covertly siphoning tokens. Because Anthropic’s account support tracks total usage but not itemized per-action usage — even on request — such theft could potentially go unnoticed for months.
Other users report similar incidents
De Swardt posted his experience on Reddit and discovered he was not alone. One commenter said their account "was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it." Another user reported usage jumping from 0% to 49% in 12 minutes after only issuing a couple of prompts and a web search.
One Claude user said their account burned through its maximum tokens every day for three days while they did not use it and opened a GitHub issue about the incident. Several other users shared similar experiences in the Reddit and GitHub threads.
Two users posted emails from Anthropic showing the company had identified and warned them that their tokens were being stolen. The emails stated a bad actor was using common infostealer malware to steal Claude login sessions from people's computers, then using those sessions to access Claude accounts and consume their usage. Infostealers are malware that install on a user's computer and steal saved passwords, session data and login credentials.
Anthropic’s actions and the malware’s origin
When Anthropic saw suspicious activity, it signed affected users out, invalidated existing authorizations, issued some refunds, and warned them they may have malware. The company also said the malware did not originate from using Claude itself: such infostealers can be acquired from many online sources, from downloading infected software to clicking on malicious ads.
De Swardt did not receive one of those warning emails, and he says he found no evidence his computer was compromised. He still does not know how the attackers gained access to his account.
Aftermath and switching providers
De Swardt’s Claude account was reinstated after about two weeks, but the slow support response and lack of itemized usage data damaged his confidence in Claude. He canceled his subscription and switched to Cursor, which can use multiple models including cheaper open-source options.
He said the alternative models perform as well as Claude. "It’s not that much different or better," he said, adding he cannot see returning "without [Anthropic] actually having resolved the issue in any way." He also believes Anthropic still lacks tools that let users see what is consuming their tokens. "I don’t think there’s any way that these people can protect themselves."
Anthropic was asked for guidance on how users can identify misuse but declined to comment further.
Why this matters
The incidents highlight a risk when session credentials are compromised and billing is token-based: attackers can silently consume paid usage. For users, this underlines the value of stronger endpoint security, regular malware checks, and demanding more detailed usage reporting. For providers, it emphasizes the need for faster support, transparent itemized billing, and tools that help customers detect and contain unauthorized token consumption.



