Skip to content
Tech News
← Back to articles

Hackers are stealing Claude tokens from subscribers

read original get Yubico YubiKey 5C NFC Security Key → more articles
Why This Matters

An AI consultant discovered his $200/month Claude Max account was quietly burning tokens while he wasn't working, and Anthropic later traced it to a compromised session key used to mint unauthorized Claude Code OAuth tokens. As subscription AI plans become metered business inputs, stolen credentials translate directly into stolen money — and Anthropic's response, suspending the account, cost the user his livelihood tool for a time.

Key Takeaways
Worth a Look

Yubico YubiKey 5C NFC Security Key — If stolen sessions and hijacked API tokens are the worry, a hardware security key is one of the strongest ways to lock down the accounts behind them. The YubiKey 5C NFC works over USB-C or by tapping to a phone, and it's supported by major AI, developer, and cloud services for phishing-resistant sign-in. Keep one on your keychain and a backup in a drawer.

See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

On August 4, Grant de Swardt, an independent AI consultant in East Sussex, UK, noticed something strange going on with his Claude Max 20x account. He hadn’t been working that day, yet his token usage was climbing.

The next day, he disabled everything he had attached to Claude and did not work with it. Token consumption again increased. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” de Swardt told TechCrunch.

What was eating up his token allowance? He had no idea, so he contacted Anthropic and asked for an itemized list. Anthropic didn’t provide one, but it agreed something was off. It suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued him a partial refund of £44.49 for the remaining time on his $200-per-month subscription.

The suspension wreaked havok on his business, he told TechCrunch. His job is to help small and mid-size businesses set up agents — a sort of forward-deployed engineer for hire — for tasks like automatically loading purchase-order data from emails into the accounting software.

As a sole proprietor, he relies on agents throughout his whole business, too: daily admin tasks, website design, coding. “Like everything is just running through AI these days,” he said.

After investigating, Anthropic told de Swardt it found the culprit: A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told him the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access,” he told TechCrunch. “They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service.”

In other words, a hacker was able to obtain access to de Swardt’s account and was covertly siphoning off his tokens. Because account support tracks total usage but not itemized usage, even upon request, this kind of theft could have gone on for months undetected.

He posted his experience on Reddit and after 80 comments, he discovered he was not alone. One person claimed that their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another saw usage go from 0 to 49% in 12 mins, when all they had used it for was a couple of prompts and a web search.

One Claude user said their account burned through its max tokens every day for three days without them using it at all; this person then created a GitHub report about it. Like with the Reddit post, others users shared similar experiences there, too.

Two of them posted emails from Anthropic where the company had — to its credit — identified and warned them that their tokens were being stolen.

... continue reading