Live · 7am IST · DailyFeatured
Reel
AI Intelligence Daily
Featured

Hackers are stealing Claude tokens from subscribers

An independent AI consultant in the U.K. discovered unauthorized token usage on his Claude Max 20x account. The activity occurred even when he was not working, and Anthropic suspended his account and issued a partial refund.

Published 9 September 2026 · ID 2026-09-09-hackers-are-stealing-claude-tokens-from-subscribers
Hackers are stealing Claude tokens from subscribers

On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed unusual activity on his Claude Max 20x account. He had not been working that day, yet his token usage was increasing. The next day, he disabled all connections to Claude and did not engage with the service, but token consumption continued to rise.

De Swardt observed that token usage increased from 45% to 55% during a period when he was not working, and no scheduled tasks were active. Dispatch and cloud execution were disabled, and there was no visible activity from his end. This raised concerns about unauthorized access to his account.

Anthropic, the company behind Claude, suspended De Swardt’s paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49. The company could not determine how the unauthorized third-party service obtained access to his account.

The incident highlights potential vulnerabilities in AI subscription models, where unauthorized third parties could exploit access to consume tokens. This could lead to increased costs for users, potential vendor lock-in, and challenges in governance for companies managing AI tools. Market reactions may include calls for stronger security measures and transparency from service providers.

The situation remains under investigation, with Anthropic and De Swardt working to understand the full scope of the breach. The incident underscores the need for continuous monitoring and improved security protocols in AI platforms to prevent unauthorized access and token theft.

Sources

Share on X Share on LinkedIn