On August 4, Grant De Swardt noticed something strange. He’s an independent AI consultant based in East Sussex, U.K. He wasn’t working that day. Still, his token usage on Claude Max 20x kept climbing.
The next day, he disabled everything connected to Claude. He didn’t touch the platform at all. Still, token consumption increased again. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled cowork tasks were paused or completed, dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt said.
What was consuming his token allowance? He had no idea. So he contacted Anthropic directly and requested an itemized breakdown. Anthropic didn’t provide that specific breakdown. Still, the company agreed something was genuinely wrong. It suspended his paid account. It invalidated all his sessions and server-side Claude Code tokens. It also issued a partial refund of £44.49 for remaining time on his $200-per-month subscription.
Read More: Claude Code Specialists Are Up 938% on Fiverr: What That Work Actually Is
This suspension caused real damage to his business, he explained. His job involves helping small and mid-size businesses set up AI agents. He functions somewhat like a forward-deployed engineer for hire. His work includes tasks like automatically loading purchase-order data from emails into accounting software.
As a sole proprietor, he relies heavily on AI agents throughout his entire business. That includes daily admin tasks. It includes website design. It also includes coding work. “Like everything is just running through AI these days,” he said.
After investigating, Anthropic identified what it believed caused the issue. A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens.
According to De Swardt, the company said his account
“appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access.” He added: “They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service.”
In other words, a hacker gained access to De Swardt’s account. That hacker was covertly siphoning off his tokens without his knowledge. Because account support tracks total usage but not itemized usage, even upon request, this kind of theft could continue undetected for months.
Read More: Anthropic Signs Out Claude Users After Malware Steals Login Sessions
De Swardt shared his experience on Reddit. After 80 comments, he discovered he wasn’t alone in this experience. One person claimed their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another user saw usage jump from 0% to 49% in just 12 minutes. They had only used the platform for a couple of prompts and one web search.
One Claude user reported their account burning through maximum tokens daily for three straight days. This happened without them using the platform at all. This person then created a GitHub report documenting the issue. Similar to the Reddit thread, other users shared comparable experiences there too.
Two users posted emails they received directly from Anthropic. To the company’s credit, Anthropic had identified and warned them that their tokens were being stolen.
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the email read. Infostealers are a specific type of malware. They install themselves on a user’s computer and steal saved passwords, session data, and login credentials.
When Anthropic detected suspicious activity, it took several protective steps. The company signed affected users out. It invalidated existing authorizations. It issued some refunds. It also warned users that they may have malware on their devices.
The company clarified something important too. This malware didn’t originate from using Claude itself. Such malware can come from many different online sources. That includes downloading infected software. It also includes clicking on infected advertisements.
Notably, Anthropic never sent De Swardt one of these warning emails. He insists he found no evidence that his own computer was compromised. He says he still has no way to determine exactly how hackers gained access to his account.
Read More: Anthropic is making Claude Code’s auto mode on by default
De Swardt’s Claude account was eventually reinstated after about two weeks. Still, the difficulty of getting timely help soured him on the platform overall. That, combined with the lack of itemized usage data, pushed him toward a different solution. He canceled his subscription in favor of Cursor. That platform offers the ability to use multiple models, including more affordable open-source options.
Based on his experience, these alternative models perform just as well as Claude. “It’s not that much different or better,” he said. He added that he can’t see returning to Claude “without [Anthropic] actually having resolved the issue in any way.”
He says Anthropic still lacks proper tools. Specifically, users have no way to see exactly what’s consuming their tokens. “I don’t think there’s any way that these people can protect themselves,” he said.
When asked for information on how users can identify misuse, Anthropic declined to comment.






