Hackers Stole Claude AI Tokens From Paying Subscribers, and Anthropic Couldn't Tell Users What Was Happening

A British AI consultant watched his $200-a-month Claude account drain on days he never touched it. He was not the only one.

AI2Day Newsdesk4 min read
A futuristic AI network integrating with various cybersecurity vendor logos
Share

Key points

  • On August 4, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed his Claude Max account consuming tokens on a day he had not worked.
  • Anthropic confirmed a compromised session key, the stored login credential that keeps you signed in, was used to mint unauthorised access tokens and funnel his usage to unknown third parties.
  • Anthropic sent warning emails to some affected users but did not contact de Swardt, who only discovered the wider problem after posting on Reddit.
  • Anthropic refunded de Swardt £44.49 and suspended his account; he cancelled his subscription after roughly two weeks without a full explanation.
  • Anthropic currently provides no itemised usage log, meaning token theft of this kind could run undetected for months.

Grant de Swardt runs a one-person business in East Sussex helping small companies set up AI agents, software that can carry out multi-step tasks on its own, for things like pulling purchase-order data from emails into accounting software. Claude, Anthropic's AI assistant, powers most of what he does daily: admin, website work, coding. So when his Claude Max 20x subscription, which costs $200 a month, started burning through its token allowance (a token is roughly a word or part of a word; your plan gives you a fixed number before you hit a limit) on days he was not working, he noticed.

On August 5 he disabled every connected tool and ran no tasks himself. His usage still climbed, from 45 percent to 55 percent, with nothing running.

He contacted Anthropic and asked for an itemised breakdown of what was consuming his tokens. Anthropic could not provide one. It did, however, agree something was wrong: it suspended his account, invalidated all active sessions, and issued a partial refund of £44.49 for the remaining days on his plan.

What actually happened to his account?

Anthropist told de Swardt that a compromised Claude session key, the stored credential that keeps you logged in without re-entering your password, had been used to create unauthorised OAuth tokens. OAuth tokens are short-lived digital passes that let one application access your account on your behalf. Someone had used his login to generate those passes and was quietly running their own activity through his account.

Anthropics own email to other affected users, first reported by TechCrunch, named the method: infostealer malware. Infostealers are malicious programs that install silently on a computer, then copy saved passwords and session data. Anthropic told those users the malware did not come from Claude itself. It can arrive through many routes: downloaded software, infected adverts, cracked apps.

Anthropics email read: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage."

De Swardt says he found no evidence of malware on his machine and still does not know how access was obtained.

Was this just one person?

No. After posting his experience on Reddit, de Swardt collected more than 80 replies from users describing similar patterns: accounts upgraded without consent, usage jumping from zero to 49 percent in 12 minutes after a couple of prompts, or hitting the daily maximum for three consecutive days with no activity at all.

Anthropics response varied. Some users received proactive warning emails; de Swardt did not.

What should Claude subscribers do right now?

Anthropics current dashboard does not show a line-by-line breakdown of what consumed your tokens. That gap is the core problem: without it, you cannot tell whether unusual usage is your own or someone elses.

For now, four practical steps can reduce your exposure.

  • Check active sessions in your Anthropic account settings and revoke any you do not recognise.
  • Sign out and sign back in to invalidate old session tokens.
  • Run a malware scan on any computer you use to access Claude. Free tools from reputable security vendors will catch most common infostealers.
  • Watch your usage bar regularly. If it moves on days you have not worked, contact Anthropic support immediately and request an account review.

De Swardt's account was reinstated after about two weeks. He cancelled anyway, switching to Cursor, a coding tool that connects to several AI models including cheaper open-source options. "I can't see going back," he told TechCrunch, "without them actually having resolved the issue in any way." Anthropic declined to comment on what tools, if any, users can use to spot misuse.

Common questions

Can I see exactly what is using my Claude tokens?

Not currently. Anthropic's dashboard shows total usage but no itemised log, so distinguishing your own activity from unauthorised access requires contacting support directly.

Does this mean Anthropic's systems were hacked?

Anthropics own infrastructure does not appear to have been breached. The attack worked by stealing login sessions from users' computers using widely available malware, then using those sessions to access accounts normally.

© 2026 AI2Day