On 4 August, Grant de Swardt, an independent AI consultant in East Sussex, England, watched his Claude Max 20x account burn tokens on a day he was not working. The next day he disconnected everything attached to Claude and used the service not at all; consumption climbed again, from 45% to 55% in the cleanest window he could construct. Anthropic eventually told him the cause was a compromised Claude key-session, used by someone else to issue unauthorised Claude Code OAuth tokens. The company suspended his paid account, revoked every active session and Claude Code server token, and refunded £44.49 of a $200-a-month subscription. What it never gave him was the thing he asked for first: a breakdown of where the tokens had gone.
The controlled period is worth stating precisely, because it is the whole case. Scheduled tasks in Cowork were paused or finished. Cloud execution through Dispatch was switched off. No local Claude Code task was running. De Swardt did no work. The meter moved ten points anyway. Anthropic would not produce an itemised list when he asked for one, but did acknowledge that the pattern looked unusual.
The suspension that followed was not a minor inconvenience. De Swardt sets up AI agents for small and medium businesses, working in effect as an outside engineer who implements automation — one of his systems pulls data out of purchase orders that arrive by email and loads it into accounting software. As a sole trader he also runs his own daily admin, his site design and his programming through the same agents. Losing the account meant losing the tooling and the delivery capacity at once.
On how the attacker got in, Anthropic's conclusion was hedged. According to de Swardt, the company judged that his account had probably been used by a third-party service showing signs of unauthorised activity, to run other people's jobs. It could not establish how that service obtained access. The possibilities it offered were credentials or session data stolen without the owner's knowledge, or an account connected to an external service.
That leaves the structural problem intact. Support can see total usage volume and does not hand over a detailed breakdown, even on request. A thief who stays under the daily ceiling is therefore invisible by construction, and the theft can run for months without anyone noticing.
De Swardt wrote up what happened on Reddit. Eighty comments later it was clear he was not alone. One user reported being moved automatically to a more expensive plan without consent, money taken from his bank card, and token usage rising on its own from 0% to 100% while he was not using the service at all. Another saw usage go from 0 to 49% in twelve minutes, during which he had sent Claude a handful of prompts and run a web search. A third said his account exhausted its entire daily token limit three days running while he launched no tasks; he opened a GitHub issue, and other users turned up there with the same story.
Two of them published letters from Anthropic. The company had detected the suspicious activity itself and was warning users that their tokens might be stolen. The mechanism described in the letters is mundane: commodity malware lifts Claude login sessions from users' machines, and those sessions are then used to reach the accounts and spend the tokens. The same class of malware takes saved passwords, session data and login credentials generally. Anthropic terminated the affected sessions, revoked live permissions, paid compensation to some users and told them their computers might be infected. It also made a point of saying the malware has nothing to do with using Claude — people pick it up from infected software or by clicking a malicious ad.
De Swardt never received that letter. He says he found no sign his own machine had been compromised and still does not know how anyone reached his account.
Here is where this reads less like a security incident and more like a product gap. Session-stealing malware is the oldest trick in the consumer threat catalogue, and no vendor can stop a customer's laptop from getting infected. The unusual part is that a subscription metered in tokens ships without an itemised meter. Anthropic can tell a user they consumed 55% of their allowance; it cannot, or will not, tell them which sessions, which tools or which machines did the consuming. Every cloud provider that bills by usage solved this a decade ago, because billing disputes are unanswerable without a log. The absence here does not just leave users unable to protect their accounts, as de Swardt argues — it leaves Anthropic unable to prove its own innocence when the meter runs strangely.
The more interesting question is what Anthropic already knows. It found the suspicious activity, it wrote to affected users, it issued refunds. That implies detection running server-side, on signals customers are not shown. De Swardt's compromise was confirmed by the company's own investigation and he still got no warning, which suggests the detection list and the confirmed-compromise list are not the same list. Asked how users can identify improper token use, Anthropic declined to comment.
About two weeks in, his account came back. He had already cancelled. He moved to Cursor, which lets him run several models including cheaper open-weights ones, and reports no meaningful difference in quality; he does not intend to return until the problem is fixed. That is the detail Anthropic should find most expensive. A theft costs it £44.49 and a support ticket. A customer who leaves over the theft, and discovers on the way out that the frontier subscription was not buying him much, costs it the premise of the $200 tier.