On August 4, Grant De Swardt, an independent AI consultant based in East Sussex, U.K., encountered a perplexing issue with his Claude Max 20x account. Despite not actively working with the AI, he observed a consistent and unexplained increase in his token usage. This anomaly, which began subtly, escalated into a significant disruption for his business, prompting a deep dive into the security vulnerabilities of AI platforms and raising critical questions about user protection and transparency.
The Escalating Mystery
The initial signs of trouble appeared on August 4th. De Swardt, who leverages AI agents extensively to manage his consultancy – a role that involves setting up sophisticated AI-driven solutions for small and medium-sized businesses – noticed his token meter climbing without any direct interaction. This was particularly concerning given that his day was not dedicated to AI-driven tasks.
Seeking to isolate the problem, De Swardt implemented a stringent control experiment on August 5th. He meticulously disabled all integrations and paused any scheduled AI tasks, ensuring no active local Claude Code tasks were running. Despite these measures, his token consumption continued to rise. "In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task," De Swardt recounted to TechCrunch. This stark observation confirmed that an external, unknown force was actively depleting his AI resources.
Seeking Resolution and Facing Setbacks
Perplexed and unable to identify the source of the drain, De Swardt reached out to Anthropic, the developer of Claude, requesting an itemized breakdown of his token usage. Anthropic did not provide the requested detailed log, a point that would become a recurring frustration for De Swardt and others experiencing similar issues. However, the company acknowledged that something was amiss with his account.
In response to the suspected compromise, Anthropic took immediate action: it suspended De Swardt’s paid account, invalidated all his active sessions, and revoked server-side Claude Code tokens. He was subsequently issued a partial refund of £44.49 for the remaining duration of his $200-per-month subscription. While these measures aimed to contain the damage, the suspension had a cascading negative impact on De Swardt’s business operations. As a sole proprietor, his consultancy relies heavily on AI for day-to-day administrative tasks, website development, and coding. "Like everything is just running through AI these days," he emphasized, highlighting the integral role AI plays in his professional workflow.
Unveiling the Culprit: A Compromised Session Key
Following an internal investigation, Anthropic identified the root cause of the unauthorized token consumption: a compromised Claude session key had been exploited to generate unauthorized Claude Code OAuth tokens. The company communicated to De Swardt that his account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access." Anthropic presented two potential scenarios: either De Swardt’s credentials or session data were stolen without his knowledge, or his account had been inadvertently connected to an external, compromised service. In essence, a hacker had gained unauthorized access to De Swardt’s account and was covertly siphoning off his valuable AI processing power. The lack of granular usage tracking, even upon request, meant that such a breach could potentially go undetected for extended periods, leading to significant financial losses and operational disruptions.
A Wider Pattern Emerges
De Swardt’s experience, initially a solitary and baffling incident, soon revealed itself to be part of a larger trend. He shared his predicament on Reddit, posting his experience on the r/ClaudeAI subreddit. The response was swift and significant, with over 80 comments flooding in, many detailing eerily similar situations. One user reported their account being "auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it." Another user described their token usage jumping from 0% to 49% in just 12 minutes, despite only using Claude for a few prompts and a single web search.
The GitHub Issue and Anthropic’s Warning
The issue gained further traction when another Claude user reported their account expending its maximum tokens daily for three consecutive days without any user activity. This user subsequently initiated a GitHub issue report, documenting their experience. The GitHub thread, much like the Reddit discussion, saw an outpouring of similar accounts from other users.
Crucially, two users shared emails from Anthropic that indicated the company had, to its credit, detected and flagged instances of token theft. These emails provided a more direct explanation of the attack vector. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage," the email stated. Infostealer malware, as explained, is designed to infiltrate a user’s computer and pilfer sensitive data such as saved passwords, session cookies, and login credentials.
Anthropic’s proactive measures, upon detecting suspicious activity, included forcibly signing out affected users, invalidating existing authorizations, issuing refunds, and warning users about potential malware infections on their systems. The company was clear in its communication that the malware did not originate from using Claude itself, but rather from external sources, such as downloading compromised software or clicking on malicious advertisements.
Lingering Questions and Shifting Loyalties
Despite Anthropic’s subsequent investigation and explanation, De Swardt remained convinced that his personal computer was not compromised and expressed a continued lack of clarity on precisely how his account credentials were obtained. His Claude account was eventually reinstated after approximately two weeks. However, the protracted resolution process and the persistent lack of granular usage data left him disillusioned with the platform.
"I don’t think there’s any way that these people can protect themselves," De Swardt lamented, underscoring his belief that users currently lack adequate tools to monitor and safeguard their AI resource consumption. This sentiment led him to cancel his Claude subscription and migrate to Cursor, a platform that offers the flexibility of using multiple AI models, including more cost-effective open-source alternatives. De Swardt found these alternative models to be on par with Claude’s performance, stating, "It’s not that much different or better." He expressed little inclination to return to Claude unless Anthropic implemented robust solutions to address these security and transparency concerns.
When approached for comment regarding user identification of misuse and preventive measures, Anthropic declined to provide specific details. This lack of public guidance leaves users in a precarious position, potentially vulnerable to similar exploitation without clear avenues for detection or protection. The incident highlights a critical juncture in the rapidly evolving AI landscape, where the convenience and power of advanced AI tools must be balanced with robust security protocols and transparent usage monitoring to maintain user trust and ensure business continuity. The implications extend beyond individual users, raising broader questions for AI providers about their responsibility in securing user accounts and providing the necessary tools for transparency and control in an increasingly AI-dependent world.
