Anthropic has told users that hackers are stealing Claude login sessions and using them to consume subscribers’ token allowances, after an independent consultant in East Sussex found his account being used while he was not working.
Grant de Swardt noticed on 4 August that usage on his Claude Max 20x account was rising despite having carried out no work that day. He then disabled every service connected to Claude and stopped using the account, but consumption continued to increase.
During one controlled period, his usage rose from 45% to 55% while scheduled tasks were paused or complete, cloud execution was disabled and no local Claude Code task was running, he said.
Anthropic did not provide an itemised breakdown of the activity when asked, but agreed that something unusual had occurred. The company suspended the paid account, invalidated all active sessions and server-side Claude Code tokens, and gave him a partial refund of £44.49 for the remaining period of his subscription, which cost 200 US dollars a month.
After investigating, Anthropic told Mr de Swardt that a compromised Claude session key had been used to create unauthorised Claude Code OAuth tokens. The account appeared to have been used by an unauthorised third-party service to carry out work for other people, he said.
Anthropic was unable to establish how access had been obtained. Mr de Swardt said the evidence was consistent either with credentials or session data being stolen without his knowledge, or with the account having been connected to an external service.
The incident disrupted his business. As an independent consultant, Mr de Swardt helps small and medium-sized companies set up AI agents to automate tasks such as transferring purchase-order information from emails into accounting systems.
He also uses agents for much of his own work, including administration, website design and software development. His Claude account was restored after about two weeks, but he said the delay in receiving help and the absence of detailed usage information had undermined his confidence in the service.
Claude users report unexplained token use
After describing what happened on Reddit, Mr de Swardt received dozens of responses from other Claude users reporting unexplained activity.
One user said their account had been upgraded without consent, their card charged and their usage increased from zero to 100% without them using the service. Another reported a rise from zero to 49% in 12 minutes after making only a few prompts and carrying out a web search.
A separate Claude user said their maximum allowance had been consumed every day for three days despite not using the account. The user also opened a report on GitHub, where others described similar experiences.
Two users shared emails from Anthropic warning that their accounts had been targeted. The company said it had become aware of a “bad actor” using common infostealer malware to take Claude login sessions from people’s computers, before accessing their accounts and consuming their usage.
Infostealers are malicious programs that can capture saved passwords, login credentials and session data. They may reach computers through infected software, malicious adverts or other online sources.
Anthropic said the malware was not caused by using Claude itself. When suspicious activity was detected, the company signed affected users out, cancelled existing authorisations, provided some refunds and warned them that their devices might be infected.
Mr de Swardt said Anthropic did not send him one of those warnings and that he had found no evidence that his own computer had been compromised. He said he still did not know how his account had been accessed.
He has since cancelled his Claude subscription and moved to Cursor, which allows users to work with several different models, including cheaper open-source alternatives. In his experience, those models perform comparably to Claude.
“It’s not that much different or better,” he said, adding that he could not see himself returning unless Anthropic resolved the security and account-monitoring issues.
Anthropic has not said what tools are available to help users identify which activity is consuming their tokens. When asked how subscribers could detect misuse, the company declined to comment.
