On August 4, Grant De Swardt noticed his Claude Max 20x account's token usage was climbing even when he wasn't working. The next day, after disabling all attached tools, token consumption again increased — from 45% to 55% in one controlled interval, he told TechCrunch. De Swardt contacted Anthropic, which suspended his paid account, invalidated all sessions and server-side tokens, and issued a partial refund of £44.49.
Anthropic's investigation found that a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told De Swardt the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access."
De Swardt posted his experience on Reddit and discovered others had similar problems. One user reported their account was auto-upgraded and credit card charged without consent, with usage jumping from 0% to 100%. Another saw usage go from 0 to 49% in 12 minutes after minimal use. A GitHub issue on the Claude Code repository also collected similar reports.
Two users posted emails from Anthropic in which the company warned: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Anthropic signed affected users out, invalidated authorizations, and issued some refunds.
Because Anthropic's account support tracks total usage but not itemized usage even upon request, such theft could go undetected for months. The suspension also disrupted De Swardt's business, as he relies on agents for daily admin, website design, and coding. "Like everything is just running through AI these days," he said.