Someone else was burning through Grant De Swardt’s $200-a-month Claude subscription while he slept. And Anthropic couldn’t tell him exactly how much was stolen, or from where.
De Swardt, an independent AI consultant based in East Sussex, U.K., first noticed the problem on August 4 when his Claude Max 20x token usage kept climbing even though he hadn’t done any work that day. The next day, he turned everything off. Scheduled tasks paused, cloud execution disabled, no active local Claude Code sessions running. Still, his token count went from 45% to 55%. As TechCrunch reported, he contacted Anthropic and asked for an itemized breakdown. The company didn’t provide one. Instead, it suspended his account, invalidated his sessions, and issued a partial refund of £44.49.
Anthropic eventually told him what had happened: a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. A third-party service had been using his account to handle activity for other people. Whether that access came from stolen credentials, session hijacking, or a connected external service, Anthropic couldn’t definitively say.
This is a meaningful security failure, and not just for De Swardt. When he posted about the incident on Reddit, dozens of users surfaced with similar stories. One said their account was auto-upgraded without consent and charged to their credit card, with usage jumping from 0% to 100% instantly. Another saw their quota go from 0 to 49% in twelve minutes after doing almost nothing. A GitHub thread collected more cases. Some users received proactive emails from Anthropic warning them that an infostealer malware campaign was targeting Claude login sessions, stealing saved passwords and session data from infected machines. Others, including De Swardt, got no such warning at all.
The infostealer angle matters because it’s a well-documented threat category, not some novel attack. Malware like Redline and Raccoon have been harvesting browser sessions for years. What’s specific to Anthropic’s situation is what happens after access is gained: because Claude’s usage tracking shows aggregate consumption but not itemized activity, users have no reliable way to spot the theft until it’s already significant. And when they flag it, there’s no audit trail to share with them.
For developers and founders building on Claude, especially through Claude Max or API-heavy setups, this is worth taking seriously. Session token hygiene, regular credential rotation, and monitoring for unexpected usage spikes are not optional if you’re running agents that touch billing-sensitive accounts. Anthropic’s tooling currently offers none of that visibility natively.
De Swardt cancelled his Claude subscription after his account was reinstated. He moved to Cursor, which supports multiple models including cheaper open-source alternatives. His assessment was blunt: the other models work just as well. And without real usage transparency from Anthropic, he sees no reason to return. When asked how users should identify misuse, Anthropic declined to comment.




