Technology· Cybersecurity

Hackers are stealing Claude tokens from subscribers

An independent AI consultant, Grant De Swardt of East Sussex, found his Claude Max 20x subscription consuming tokens while he was not using the service. Anthropic suspended his account, invalidated session and server-side tokens, issued a partial refund, and later told him the activity appeared linked to a compromised session key that minted unauthorized Claude Code OAuth tokens.

By AI NewsroomPublished about 2 hours agoUpdated about 2 hours ago3 views
Hackers are stealing Claude tokens from subscribers

Why It Matters

If session credentials can be stolen and used to drain paid usage, subscribers risk unexpected charges and service disruption; the problem is amplified because Anthropic’s support tracks only total usage, not itemized activity, which can let theft go unnoticed.

Key Facts

  • Date of first incident noticed: August 4, 2026
  • Affected user: Grant De Swardt, independent AI consultant, East Sussex, U.K.
  • Model and plan: Claude Max 20x, $200-per-month subscription
  • Partial refund issued: £44.49
  • Company actions: Suspended account; invalidated sessions and server-side Claude Code tokens; signed some users out and issued some refunds.

On August 4, Grant De Swardt, an AI consultant in East Sussex, noticed his Claude Max 20x account's token usage rising even though he was not using the service. He disabled integrations and paused scheduled tasks, but usage climbed again the following day. After contacting Anthropic, the company suspended his paid account, invalidated active sessions and server-side Claude Code tokens, and issued him a partial refund of £44.49 on his $200-per-month plan.

Anthropic later told De Swardt its investigation found a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens and that the account appeared to be used by an unauthorized third-party service. The company said it could not determine precisely how the session data was obtained, describing evidence consistent with either stolen credentials/session data or an account connection to an outside service.

Other Claude users reported similar unexplained bursts of usage on Reddit and in a GitHub report; examples included accounts being auto-upgraded, unexpected charges, and usage jumping from near-zero to high percentages within minutes. Anthropic emailed some affected customers to warn that a bad actor was using infostealer malware to capture saved login sessions from users’ machines and then use those sessions to access Claude accounts and consume tokens. In response to suspicious activity, Anthropic has signed affected users out, invalidated authorizations, and issued some refunds.

De Swardt said he found no evidence his machine was compromised and that Anthropic did not send him one of the malware-warning emails. His account was reinstated after about two weeks, but he cancelled the subscription and moved to a different product (Cursor) because he felt Anthropic lacked tools to reveal what is consuming tokens. Anthropic declined to provide guidance on how users can identify misuse. The incident highlights a gap: because support records total usage without itemized logs, unauthorized consumption could potentially continue undetected for months.

Keep Reading