Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something unusual with his $200-per-month Claude Max 20x account on August 4. He wasn’t working that day, but his token usage kept increasing.
The following day, De Swardt disabled everything connected to Claude and stopped using the service. His token consumption still went up. During one controlled period, usage increased from 45% to 55% even though scheduled Cowork tasks were paused or completed, Dispatch and cloud execution were disabled, and there was no active local Claude Code task running.
De Swardt contacted Anthropic and asked for a detailed breakdown of where his tokens were being used. The company did not provide an itemized usage report, but it agreed that something unusual had happened. Anthropic suspended his paid account, invalidated his active sessions and server-side Claude Code tokens, and refunded £44.49 for the unused portion of his $200 monthly subscription.
The suspension created serious problems for De Swardt’s business. As a solo consultant, he helps small and medium-sized businesses set up AI agents for tasks such as automatically transferring purchase-order information from emails into accounting software. He also uses AI agents for his own daily administration, website work and coding.
After investigating the incident, Anthropic told De Swardt that a compromised Claude session key had been used to create unauthorized Claude Code OAuth tokens. According to the explanation he received, his account appeared to have been accessed by an unauthorized third-party service that was using the account to perform activity for other people.
Anthropic could not determine exactly how the attackers obtained access. The company said the evidence was consistent either with credentials or session information being stolen without his knowledge, or with the account having been connected to an outside service.
That means someone may have been quietly using De Swardt’s Claude account and consuming his token allowance without his knowledge. One of the bigger concerns is that Claude support currently tracks overall usage but does not provide users with an itemized breakdown showing exactly what consumed their tokens.
De Swardt later shared his experience on Reddit, where other Claude users reported similar problems. One user claimed their account was automatically upgraded, their credit card was charged, and their usage jumped from zero to 100% without them using Claude. Another reported usage increasing from 0% to 49% in just 12 minutes despite only sending a few prompts and performing a web search.
Another Claude user said their account used up its maximum token allowance every day for three consecutive days even though they had not used it. That user also opened a report on GitHub, where others described similar experiences.
Two users also shared emails from Anthropic confirming that the company had detected suspicious activity and believed their Claude sessions had been compromised.
Anthropic explained in those emails that a malicious actor was using common infostealer malware to steal Claude login sessions from users’ computers. The stolen sessions could then be used to access Claude accounts and consume their available usage. Infostealers are malware designed to steal information such as saved passwords, login sessions and other credentials.
When Anthropic detects suspicious activity, it can sign affected users out, invalidate existing authorizations and provide refunds in some cases. The company also warned that affected computers could potentially be infected with malware.
Anthropic stressed that the malware was not caused by using Claude itself. Infostealers can be distributed through many sources, including infected software downloads and malicious advertisements.
De Swardt did not receive one of those warning emails. He also said he found no evidence that his computer had been compromised, leaving him unsure how attackers gained access to his account.
His Claude account was eventually restored after around two weeks. However, the slow support process and lack of detailed usage information left him frustrated enough to cancel his subscription. He switched to Cursor, which allows users to work with multiple AI models, including cheaper open-source options.
De Swardt said the alternative models perform similarly to Claude for his work and that he did not find Claude significantly better. He said he would not consider returning unless Anthropic addresses the issue and gives users better ways to determine what is consuming their tokens.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
For now, his main concern is that Claude users have limited visibility into their account usage, making it difficult to notice unauthorized activity before a large amount of their AI allowance has already been consumed.
(via TC)



