9 Sep 2026, Wed

Unauthorized Access and Token Theft Plague Anthropic’s Claude AI, Leaving Users Outraged and Businesses Disrupted.

East Sussex, U.K. – Grant De Swardt, an independent AI consultant with a focus on empowering small and medium-sized businesses through AI integration, found his operations thrown into disarray on August 4th when he noticed an alarming anomaly within his Claude Max 20x account. Despite not actively engaging with the platform that day, his token usage was inexplicably climbing. This unsettling trend persisted. The following day, in a deliberate effort to isolate the issue, De Swardt meticulously disabled all external integrations and ceased any direct interaction with Claude. Yet, the token consumption continued its upward trajectory. "In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task," De Swardt recounted to TechCrunch, underscoring the perplexing nature of the situation.

The mystery of the escalating token usage left De Swardt without answers. He promptly reached out to Anthropic, the developer of Claude, requesting a detailed breakdown of his account activity. While Anthropic did not furnish an itemized report, the company acknowledged that something was indeed amiss. As a precautionary measure, they suspended De Swardt’s paid account, invalidated all his active sessions and server-side Claude Code tokens, and issued him a partial refund of £44.49 for the remaining duration of his $200-per-month subscription.

The abrupt suspension of his Claude account had a devastating impact on De Swardt’s business. As a sole proprietor, his livelihood hinges on the seamless operation of AI agents for a wide array of critical functions. His core business involves acting as a "forward-deployed engineer for hire," assisting small and mid-sized enterprises in establishing sophisticated AI agents. These agents are designed to automate intricate tasks, such as the automated ingestion of purchase-order data directly from emails into accounting software, thereby streamlining financial operations and reducing manual data entry errors. Beyond client work, De Swardt relies heavily on AI for his own daily administrative tasks, website development, and coding projects. "Like everything is just running through AI these days," he remarked, highlighting the pervasive integration of AI in his professional workflow. The disruption caused by the account suspension meant that essential business processes were grinding to a halt, impacting his ability to serve clients and manage his own operations.

Following an internal investigation, Anthropic identified the root cause of the anomaly: a compromised Claude session key had been exploited to mint unauthorized Claude Code OAuth tokens. The company informed De Swardt that his account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access." De Swardt relayed Anthropic’s explanation: "They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service." In essence, a malicious actor had successfully breached De Swardt’s account and was covertly siphoning off his valuable token allowance. The lack of granular usage tracking within Anthropic’s account support, even when specifically requested by users, meant that this form of digital theft could potentially continue undetected for extended periods, leading to significant financial losses and operational disruptions.

Seeking answers and community support, De Swardt shared his experience on Reddit, posting in the r/ClaudeAI subreddit. His detailed account of the sudden and unexplained token surge garnered significant attention, with over 80 comments quickly accumulating. It soon became apparent that De Swardt was not an isolated victim. Other users began to report strikingly similar incidents. One individual claimed their account had been "auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it." Another user described a rapid escalation of token usage from 0% to 49% within a mere 12 minutes, despite only having engaged with Claude for a couple of prompts and a single web search. The pattern of unexplained token depletion continued to emerge within the Reddit thread, indicating a widespread vulnerability.

Adding further weight to these claims, another Claude user reported that their account had exhausted its maximum token allowance daily for three consecutive days without any user interaction. This persistent issue prompted the user to file a formal report on GitHub, specifically within the "claude-code" repository, detailing the problem. Similar to the Reddit discussion, the GitHub issue tracker also became a platform for other users to share their parallel experiences of unauthorized token consumption.

The gravity of the situation was further underscored by the fact that at least two affected users shared screenshots of emails they had received from Anthropic. To the company’s credit, these communications indicated that Anthropic had proactively identified and alerted these users to the fact that their tokens were being illicitly consumed. One such email explicitly stated: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage." The email elaborated on the nature of infostealer malware, describing it as a type of malicious software that infiltrates a user’s computer to steal saved passwords, session data, and login credentials, thereby facilitating unauthorized access to online accounts.

Upon detecting suspicious activity, Anthropic stated in these communications that they had taken steps to secure affected accounts. These measures included automatically signing out users, invalidating existing authorizations, issuing partial refunds where applicable, and issuing warnings to users about the potential presence of malware on their systems. Crucially, Anthropic emphasized that the malware responsible for these breaches did not originate from the use of Claude itself. Instead, they explained that such infostealer malware can be acquired through a multitude of online vectors, ranging from downloading infected software to inadvertently clicking on malicious advertisements.

Despite Anthropic’s explanation and the existence of these warning emails for some users, De Swardt pointed out that he had not received such a notification. He maintained that he found no evidence of his own computer being compromised and expressed his continued inability to definitively determine how the hackers had gained access to his account. This lack of clarity left him feeling exposed and vulnerable.

De Swardt’s Claude account was eventually reinstated after approximately two weeks. However, the arduous process of seeking prompt assistance and the fundamental lack of transparency regarding token usage had significantly soured his perception of Claude and Anthropic’s support infrastructure. Consequently, he made the decision to cancel his subscription. He has since transitioned to Cursor, a platform that offers the flexibility of utilizing multiple AI models, including more cost-effective open-source alternatives. De Swardt asserted that, in his professional experience, these alternative models perform on par with Claude. "It’s not that much different or better," he stated, adding that he sees no incentive to return to Claude "without [Anthropic] actually having resolved the issue in any way."

De Swardt concluded by emphasizing a critical deficiency he perceives in Anthropic’s current offerings: the absence of robust tools that empower users to monitor and identify precisely what is consuming their allocated tokens. "I don’t think there’s any way that these people can protect themselves," he lamented, highlighting the inherent vulnerability of users who lack visibility into their account activity. When approached for comment on how users can identify and prevent such misuse, Anthropic declined to provide any specific guidance or information. This lack of transparency from the company further fuels user concerns and raises questions about the security and accountability measures in place for AI platforms handling sensitive user data and resources. The incidents involving Grant De Swardt and other users serve as a stark reminder of the evolving cybersecurity landscape in the burgeoning field of artificial intelligence and the critical need for enhanced security protocols and user-centric transparency from AI providers.

Leave a Reply

Your email address will not be published. Required fields are marked *