Thousands of Anthropic Claude users report that their token allowances are being silently consumed by unauthorized third parties exploiting stolen session credentials. The issue centers on infostealer malware that targets user devices, allowing attackers to harvest login data and access Claude accounts without the owner’s knowledge.
Grant de Swardt, an independent AI consultant based in East Sussex, UK, first identified the anomaly on August 4. Despite not performing any work that day, his Claude Max 20x account showed a steady increase in token usage. When he paused all connected tools and tasks the following day, consumption still rose from 45% to 55% during the testing period.
De Swardt contacted Anthropic for an itemized breakdown of his usage, but the company could not provide one. Instead, Anthropic suspended his account, invalidated existing sessions and tokens, and issued a partial refund of £44.49 against his $200 monthly subscription. The incident disrupted his workflow as a sole proprietor who relies on AI agents for daily administrative tasks, coding, and website design for small and mid-size businesses.
Anthropic later informed de Swardt that a compromised session key had been used to mint unauthorized Claude Code OAuth tokens. While the company suggested the evidence pointed to either stolen credentials or a connection to an outside service, it could not definitively determine how access was obtained.
De Swardt shared his experience on Reddit, where he discovered many other users reporting similar incidents. One user claimed their account was auto-upgraded and charges began accruing without consent, while another saw usage jump from 0% to 49% within twelve minutes of sending only a few prompts. Some individuals reported their accounts burning through maximum tokens daily for several days without any interaction.
In response to the growing problem, Anthropic sent warning emails to some affected subscribers, acknowledging that a bad actor is using common infostealer malware to steal Claude login sessions and consume usage. The company clarified that the malware typically originates from sources unrelated to Claude, such as downloading infected software or clicking on malicious advertisements.
When suspicious activity is detected, Anthropic signs out affected users, invalidates authorizations, provides refunds where possible, and advises checks for malware. However, de Swardt did not receive such a notification. He insists there is no evidence his computer was compromised, stating he remains unable to determine how hackers gained access to his account.
After approximately two weeks, de Swardt’s account was reinstated. However, the difficulty in obtaining timely support and the lack of detailed usage tracking led him to cancel his subscription. He switched to Cursor, a platform that supports multiple models including affordable open-source options. According to de Swardt, these alternatives perform comparably to Claude, and he sees no reason to return without better security measures.
He emphasized that Anthropic currently lacks tools allowing users to monitor exactly what is consuming their tokens, leaving them vulnerable to prolonged, undetected theft. When asked for guidance on identifying misuse, Anthropic declined to comment.
Cursor with open-source models sounds like a solid escape. Self-hosting really is the ultimate security.
Has anyone else noticed similar token drains on other AI platforms, or is this isolated to Claude Max?
De Swardt claims no compromise, yet his account spiked. Maybe he clicked a phishing link he didn’t notice?
No itemized usage logs? That’s a major red flag for any subscription service. How can you debug theft without data?
Infostealer malware is nasty. Always use a password manager and enable MFA to protect your accounts.