When Security Fails: A User's Tale of Token Theft
On August 4, Grant De Swardt, an independent AI consultant based in East Sussex, U.K., noticed something unsettling about his Claude Max 20x account. He hadn't been working that day, yet his token usage was climbing.
"In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,"
De Swardt told TechCrunch.
This wasn't an isolated incident. The next day, he disabled everything attached to Claude and still observed token consumption increasing. This was not a case of misconfigured automation or unexpected usage—it pointed to something far more sinister: unauthorized access.
Unraveling the Investigation
De Swardt contacted Anthropic directly, requesting an itemized list of his token usage. The company did not provide this information but acknowledged that something was amiss. They suspended his paid account, invalidated all sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription.
But what truly mattered wasn't just the financial impact—it was the disruption to his business operations. As a sole proprietor who relies heavily on AI agents for daily administrative tasks, website design, and coding, De Swardt's entire workflow was at risk. He noted that "everything is just running through AI these days," making the loss of service even more devastating.
How the Breach Occurred
After a thorough investigation, Anthropic identified the root cause: a compromised Claude session key that allowed hackers to mint unauthorized Claude Code OAuth tokens. The company reported that the account appeared to have been used by an unauthorized third-party service for activities unrelated to the original user.
The breach highlighted a critical gap in how companies track and report usage—especially when it comes to AI platforms where token consumption can be monetized. While account support tracks total usage, there's no itemized breakdown of what specifically consumed those tokens. This oversight makes it nearly impossible for users to detect misuse quickly, potentially allowing theft to go undetected for months.
Widespread Reports of Similar Incidents
De Swardt shared his experience on Reddit, where it sparked a wave of similar reports from other Claude users. One user reported that their account was auto-upgraded without consent, with charges applied to their credit card and usage shooting from 0% to 100% automatically. Another noticed rapid consumption of tokens over just 12 minutes, despite minimal activity.
One particularly disturbing case involved a user whose account burned through its maximum token allowance every day for three consecutive days without any interaction from the owner. This individual opened a GitHub issue detailing their experience and received confirmation from Anthropic that similar cases had been identified.
Anthropic's Response and Omissions
Anthropic did send warning emails to affected users, informing them that infostealer malware was being used to gain access to Claude login sessions. Infostealers are malicious programs that install themselves on computers and steal saved passwords, session data, and other credentials.
However, De Swardt didn't receive such an email. He insists he found no evidence of his computer being compromised and remains puzzled by how hackers gained access. The company stated that the malware did not originate from using Claude itself but could come from downloading infected software or clicking on malicious ads.
The lack of communication from Anthropic about the exact breach mechanism left many users confused and vulnerable. De Swardt's case exemplifies a broader issue: when security fails, transparency must follow.
Consequences for Users
After his account was reinstated following two weeks, De Swardt canceled his subscription in favor of Cursor, which offers more affordable open-source alternatives and greater flexibility. He expressed that these models work as well as Claude, and he doesn't see returning without Anthropic addressing the underlying security issues.
"I don't think there's any way that these people can protect themselves," De Swardt lamented, emphasizing the lack of tools for users to monitor their token consumption. He believes the current system leaves customers blind to potential threats and vulnerable to exploitation.
A Systemic Problem
What strikes me about this situation is how it exposes systemic flaws in AI platform security and accountability. As artificial intelligence becomes increasingly integrated into business operations, the stakes for data protection and usage transparency rise accordingly.
The incident with Claude isn't just a single bug or oversight—it's a warning sign that the industry must take seriously. If companies like Anthropic can't provide clear insights into how their systems are being used, they're failing in their fundamental duty to protect customer assets and trust.
Why This Matters Now
With AI adoption accelerating across industries, incidents like this could multiply quickly. The financial implications extend beyond individual users—they impact businesses that rely on predictable costs and secure environments for AI development and deployment.
From a policy perspective, this highlights the urgent need for clearer standards around how tech companies report security breaches and manage customer data. Customers should have access to detailed usage reports and robust mechanisms for identifying and responding to unauthorized activity.
What's Next for Claude?
Anthropic has acknowledged the vulnerability, but the response so far seems reactive rather than proactive. Users are left with no clear path forward, and companies that offer AI services must do better. The responsibility isn't just technical—it's ethical.
In my experience covering AI trends, I've seen how quickly user trust can erode when platforms fail to safeguard basic security measures. As we move deeper into the age of AI, it's crucial that companies build transparency and accountability into their core offerings, not as an afterthought.
Conclusion
The unauthorized token theft affecting Claude users is more than just a cybersecurity issue—it's a reflection of how poorly prepared many AI platforms are for real-world abuse. For now, De Swardt and others must navigate a new landscape where their digital investments feel less secure.
Until Anthropic addresses the lack of itemized reporting and provides tools to help users monitor their usage effectively, the risk of being silently exploited will remain high. This case serves as a wake-up call to the entire AI industry: customer trust must be earned through openness, not just convenience.
Key Facts
- Primary Entity: Grant De Swardt
- Location: East Sussex, U.K.
- Account Type: Claude Max 20x
- Incident Date: August 4, 2026
- Token Consumption Pattern: Increased from 45% to 55% without work
- Refund Amount: £44.49
- Account Suspension Duration: Two weeks
- Breaching Entity: Hackers
Background
Grant De Swardt, an independent AI consultant based in East Sussex, U.K., discovered unauthorized token consumption on his Claude Max 20x account on August 4, 2026. Despite not working on that day, his token usage increased from 45% to 55%. After disabling all attached services and still observing consumption increases, he contacted Anthropic. The company suspended his account, invalidated sessions and tokens, and issued a partial refund of £44.49 for the remaining subscription time. De Swardt's business relies heavily on AI agents for administrative tasks, website design, and coding, making this breach particularly disruptive. Similar incidents were reported by other Claude users, including unauthorized auto-upgrades and rapid token depletion without user activity.
Quick Answers
- What happened to Grant De Swardt?
- Grant De Swardt discovered unauthorized token consumption on his Claude Max 20x account on August 4, 2026. His token usage increased despite no work being performed.
- When was Grant De Swardt's account compromised?
- Grant De Swardt's account was compromised on August 4, 2026, when he noticed his token usage increasing without any activity.
- Who is Grant De Swardt?
- Grant De Swardt is an independent AI consultant based in East Sussex, U.K., who relies heavily on Claude for business operations.
- Why was Grant De Swardt's account suspended?
- Grant De Swardt's account was suspended by Anthropic after unauthorized token consumption was detected and confirmed.
- How much was Grant De Swardt refunded?
- Grant De Swardt received a partial refund of £44.49 for the remaining time on his $200-per-month subscription.
- What did Grant De Swardt do after the breach?
- Grant De Swardt canceled his Claude subscription in favor of Cursor, which offers more affordable open-source alternatives and greater flexibility.
- How long was Grant De Swardt's account suspended?
- Grant De Swardt's account was suspended for approximately two weeks before being reinstated.
- What type of tokens were consumed without authorization?
- The unauthorized consumption involved Claude Code OAuth tokens on Grant De Swardt's Claude Max 20x account.
Frequently Asked Questions
What was the token consumption pattern observed by Grant De Swardt?
Grant De Swardt observed his token usage increasing from 45% to 55% during a controlled interval when he performed no work, with scheduled tasks paused and cloud execution disabled.
What was the cause of Grant De Swardt's unauthorized token consumption?
The unauthorized token consumption was caused by a compromised Claude session key that allowed hackers to mint unauthorized Claude Code OAuth tokens.
Did Grant De Swardt receive warning emails from Anthropic?
Grant De Swardt did not receive warning emails from Anthropic, despite the company sending such notices to other affected users.
What was the financial impact on Grant De Swardt?
Grant De Swardt received a partial refund of £44.49 for his remaining subscription time and canceled his Claude subscription due to the breach.
How did Grant De Swardt respond to the breach?
Grant De Swardt canceled his Claude subscription in favor of Cursor, which offers more affordable open-source alternatives and greater flexibility for his business needs.
What does Grant De Swardt say about the current security measures?
Grant De Swardt believes that Anthropic lacks tools for users to monitor token consumption effectively and that customers are left blind to potential threats.
Source reference: https://techcrunch.com/2026/09/08/hackers-are-stealing-claude-tokens-from-subscribers/


Comments
Sign in to leave a comment
Sign InLoading comments...