Hackers are stealing Claude tokens from subscribers
An independent AI consultant in the U.K. discovered unauthorized token usage on his Claude Max 20x account. The activity occurred even when he was not working, and Anthropic suspended his account and issued a partial refund.

On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed unusual activity on his Claude Max 20x account. He had not been working that day, yet his token usage was increasing. The next day, he disabled all connections to Claude and did not engage with the service, but token consumption continued to rise.
De Swardt observed that token usage increased from 45% to 55% during a period when he was not working, and no scheduled tasks were active. Dispatch and cloud execution were disabled, and there was no visible activity from his end. This raised concerns about unauthorized access to his account.
Anthropic, the company behind Claude, suspended De Swardt’s paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49. The company could not determine how the unauthorized third-party service obtained access to his account.
The incident highlights potential vulnerabilities in AI subscription models, where unauthorized third parties could exploit access to consume tokens. This could lead to increased costs for users, potential vendor lock-in, and challenges in governance for companies managing AI tools. Market reactions may include calls for stronger security measures and transparency from service providers.
The situation remains under investigation, with Anthropic and De Swardt working to understand the full scope of the breach. The incident underscores the need for continuous monitoring and improved security protocols in AI platforms to prevent unauthorized access and token theft.