Last month, Grant De Swardt, an AI consultant in the UK, noticed unexplained token usage on his Claude Max 20x account despite not using the service. After disabling all connected services, his token consumption inexplicably continued to rise. Anthropic investigated and found that a compromised Claude session key had allowed unauthorized parties to mint Claude Code OAuth tokens, effectively siphoning off usage from his account. Anthropic suspended his account, invalidated sessions, and partially refunded him, though this disruption severely impacted his business operations, which heavily rely on AI agents for automation.
De Swardt’s case is not isolated. Numerous Claude users reported sudden spikes in token consumption without their activity—some were auto-upgraded or charged unexpectedly. Many shared their experiences on Reddit and GitHub, revealing that hackers are exploiting infostealer malware to capture users’ Claude login sessions. Anthropic confirmed that this malware, which steals credentials from infected devices, is the root cause of these breaches. When suspicious activity is detected, Anthropic signs affected users out and warns them to check for malware on their systems, emphasizing that the infections do not originate from Claude itself.
Anthropic’s response includes invalidating tokens, issuing refunds, and raising awareness among users. However, the company has yet to provide detailed tools for subscribers to monitor token usage or identify unauthorized consumption, leaving many users frustrated and vulnerable. De Swardt, in particular, criticized the lack of transparency and advocate for better user controls and security measures. His account was eventually reinstated after two weeks, but he cancelled his subscription in favor of other AI providers offering more visibility and cost control over usage.
The incident highlights significant security challenges in the AI subscription ecosystem, where token usage translates directly into financial cost. It underscores the risks users face from malware outside AI platforms and the urgent need for AI companies to enhance account security, usage transparency, and customer support. As AI agents gain sophistication and integration with user workflows deepens, preventing unauthorized access to accounts and ensuring clear visibility into token expenditure are critical for protecting customers and building trust in these emerging services.
Start the discussion with a take, question, or market read.