Hackers Steal Claude Tokens From Anthropic Subscribers
Grant De Swardt, an AI consultant in the U.K., noticed unauthorized token usage on his Claude Max 20x account, echoing complaints from other users on Reddit and GitHub.

Stock photo for illustration only, not from the actual event
- Multiple Claude subscribers report token depletion without active usage
- Anthropic responded by suspending accounts, issuing refunds, and warning of malware
- Victims found no evidence of computer compromise despite covert token theft
- Some affected users cancelled their subscriptions to switch to alternative platforms
On August 4, 2026, Grant De Swardt, an independent AI consultant based in East Sussex, U.K., noticed unusual activity on his Claude Max 20x account. Despite not working that day, his token usage metrics continued to climb steadily.
The following day, he disconnected all integrations linked to Claude and refrained from performing any work. Yet, token consumption rose once more. In his most strictly controlled observation, consumption surged from 45% to 55% while no work was performed, scheduled tasks were paused, cloud execution was disabled, and no active local Claude Code tasks were running.
When he contacted Anthropic to request an itemized usage list, the company did not provide one but acknowledged the anomaly. Anthropic suspended his paid account, invalidated all active sessions and server-side Claude Code tokens, and issued a partial refund of 44.49 pounds for the remaining time on his 200-dollar-per-month subscription.

Stock photo for illustration only, not from the actual event
"In the clearest controlled interval, it increased from 45% to 55% while I performed no work."
De Swardt explained that the suspension severely disrupted his business operations. His professional role involves helping small and mid-sized businesses configure AI agents for automated tasks, such as loading purchase-order data from emails directly into accounting software. As a sole proprietor, he also relies heavily on these agents for daily administration, website design, and software coding.
This wave of token thefts underscores a critical security vulnerability in the current landscape of generative AI adoption. As individuals and enterprises integrate large language models deeply into daily operations, API tokens and usage quotas effectively function as digital currency. The lack of detailed itemized usage tracking by providers complicates detection for ordinary users, emphasizing the need for robust proactive security monitoring and transparent account auditing.
After sharing his ordeal on Reddit, De Swardt received over 80 comments revealing that he was not alone. Another user reported that their account was auto-upgraded without consent, resulting in credit card charges and token usage jumping instantly from zero to 100 percent. Another customer experienced their max token allowance burning through every day for three days straight without interacting with the platform.
Two impacted individuals published warning emails received directly from Anthropic, which had successfully identified the token theft. In response to suspicious activities, the company signed users out, revoked authorizations, processed refunds, and warned clients about potential malware infections originating from external web sources such as infected software downloads or malicious advertisements.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment