Hackers Target Subscribers to Steal Claude Tokens

On August 4, Grant de Swardt, an independent AI consultant from East Sussex, UK, encountered unusual activity with his Claude Max 20x account. Despite not working that day, he observed a significant rise in token usage.
The following day, he deactivated all connected applications and refrained from using Claude, but the token consumption continued to increase. “In the simplest controlled setting, it jumped from 45% to 55% while I was idle, scheduled tasks were halted, and there was no active local Claude Code task,” de Swardt recounted.
Confused about the excessive token consumption, he reached out to Anthropic for a detailed breakdown. Although the company did not provide one, they acknowledged something was amiss. They suspended his paid account, invalidated all his sessions and server-side Claude Code tokens, and offered him a partial refund of £44.49 for the remaining period of his $200-per-month subscription.
This abrupt suspension severely impacted his business, as de Swardt primarily assists small to mid-sized companies in establishing agents—essentially remote engineers—to manage tasks like transferring purchase-order information from emails to accounting software.
As a sole proprietor, he heavily relies on these agents for various operations, including daily administrative work, web design, and coding. “Everything runs through AI these days,” he remarked.
After further investigation, Anthropic informed de Swardt that a compromised Claude session key had been exploited to generate unauthorized Claude Code OAuth tokens. They suggested that an external service may have used his account without permission, but the exact method of access remained undetermined. “The evidence suggests either that my credentials were stolen without my awareness or that my account had been linked to an external service,” he explained.
Essentially, a hacker had infiltrated de Swardt’s account and was covertly extracting his tokens. Since account support monitors total usage without an itemized breakdown, this type of fraud could potentially go unnoticed for months.
After sharing his experience on Reddit, de Swardt found he was not alone in this situation. Several users commented on similar issues, with one claiming their account was auto-upgraded without consent, leading to unexpected charges and excessive usage. Another reported a dramatic increase in usage from 0% to 49% in just 12 minutes after only making a couple of prompts.
One user detailed how their account consumed its maximum tokens daily for three consecutive days without any activity. They even created a GitHub report detailing the incident, echoing de Swardt’s findings.
Two individuals shared emails from Anthropic, where the company had proactively identified and warned them of token theft.
“We have recently identified a malicious actor using common infostealer malware to capture Claude login sessions from users’ computers, subsequently utilizing these sessions to access Claude accounts and deplete their usage,” the email stated. Infostealers are malware programs that stealthily access saved passwords and session data.
Upon noticing suspicious activity, Anthropic disconnected the users, invalidated existing authorizations, issued refunds, and cautioned them about potential malware on their systems.
Anthropic clarified that the malware was not a consequence of using Claude. Such malicious software can originate from various online activities, including downloading infected programs or engaging with harmful ads.
Though de Swardt did not receive a warning email, he asserts that there is no evidence his computer was compromised, leaving him uncertain about the infiltration method.
After a two-week suspension, de Swardt’s Claude account was restored. However, the slow response and absence of detailed token usage left him dissatisfied with the service, prompting him to cancel his subscription in favor of Cursor, which offers a variety of models, including more budget-friendly open-source options.
He believes these alternatives perform comparably to Claude. “There’s not much difference or improvement,” he said, adding that without a resolution to the issues faced, he has no intention of returning. He pointed out that Anthropic still lacks features that would empower users to track and monitor their token consumption. “Without these tools, users are left vulnerable.”
When approached for guidance on identifying misuse, Anthropic chose not to comment.



