Grant De Swardt, an independent artificial intelligence consultant from the UK, noticed strange activity on an Anthropic account subscribed to Claude Max 20x – the consumption of tokens began to increase abnormally, which the company could not explain, although they refunded some of the funds.
Image source: anthropoic.com
After discovering the anomaly, Deswart shut down all services connected to Claude the next day and stopped using the system, but the consumption of tokens began to increase again. During the most significant period, he recorded an increase in consumption from 45% to 55% with scheduled Cowork and cloud execution tasks disabled and no active local Claude Code tasks. He asked Anthropic to provide a detailed report – which they did not provide to the victims, but they agreed that the situation was abnormal, suspended paid subscriptions, canceled all sessions and tokens, and also partially refunded – the price of the $200 per month subscription was £44.49 ($60.51).
The company investigated and determined that compromised Claude session keys were used to create unauthorized OAuth tokens for Claude Code. According to De Swardt, Anthropic discovered that his account was likely being used by an unauthorized third-party service to perform tasks for other users, but it was unable to determine how exactly it gained access. The company said credentials or session data could have been stolen without the owner’s knowledge, or the account could have been connected to a third-party service. Therefore, other people’s services can cost Deswat tokens, without him even knowing it. Because Anthropic’s support team tracks overall usage but does not provide detailed token spending statistics, such thefts may go undetected for months.

When experts spoke about the incident on the platform Redditit turns out he’s not the only one with this problem. According to one of the users, his token consumption level increased spontaneously from 0 to 100%, his tariff plan was automatically increased without his consent, and money was debited from his card. In another case, resource consumption increased from 0% to 49% in just 12 minutes – during which time the user entered only a few queries and used web searches. A third person’s token limit on his account was depleted for three days in a row, even though he didn’t use the service at all.
Two victims responded to Anthropic – the company discovered the problem and warned that the tokens were stolen. In one case, a malicious program that stole data was suspected. After detecting suspicious activity, Anthropic forcibly terminates the session, revokes authorization, returns some funds, and issues a warning about possible malware infection. The company also stressed that the malware had nothing to do with the use of Claude itself – its origin could have been infected software downloaded from unofficial sources or clicking on links in malicious ads.
Mr De Swardt received no such letter from Anthropic – he saw no signs that his computer had been hacked and still cannot understand how the attackers gained access to his account. Two weeks later, Anthropic restored access to his account, but he no longer wanted to use the platform and changed it to Cursor, where he could choose from different models, including cheaper open source solutions. According to De Swardt, other models also suit him just as well as the Claude. He said Anthropic still lacks tools that allow users to accurately track the use of their tokens, meaning it won’t be easy to protect against such attacks.
If you find an error, select it with your mouse and press CTRL+ENTER.










