Hackers steal Claude tokens from subscribers via compromised session keys
Anthropic has warned users that hackers are stealing Claude tokens from paid subscribers after a UK consultant discovered his account was consuming usage while he was idle.
Grant de Swardt, an independent AI consultant in East Sussex, noticed on August 4 that his Claude Max 20x account was burning tokens on a day he did no work. After he disabled everything attached to Claude, usage still climbed from 45% to 55% during a controlled interval with no active tasks, he told TechCrunch.
Anthropic suspended his $200-per-month account, invalidated his sessions and server-side Claude Code tokens, and refunded £44.49. Its investigation found a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. The company said the account appeared to have been used by an unauthorized third-party service to handle activity for other people, but it could not determine how access was obtained.
De Swardt posted his experience on Reddit and, after 80 comments, found he was not alone. One person said their account was auto-upgraded without consent, their credit card charged, and usage jumped from 0% to 100%.
Because Anthropic support tracks total usage but not itemized usage, even on request, such theft could go undetected for months.
Token theft can drain paid Claude accounts silently for months because Anthropic does not provide itemized usage breakdowns, leaving subscribers unable to detect or prove unauthorized consumption.