Skip to content

Hackers Are Secretly Burning Through Claude Users’ Token Limits

Hackers Are Secretly Burning Through Claude Users' Token Limits

A growing number of Claude users are reporting unexplained consumption of their paid token allowances, pointing to a security issue involving stolen login sessions and unauthorized access. The problem, which has left some independent developers locked out of their accounts and facing business disruptions.

The issue came to light earlier this month when Grant De Swardt, an independent AI consultant based in East Sussex, U.K., noticed anomalies in his Claude Max 20x account. According to a TechCrunch report, De Swardt observed his token usage climbing on a day he had not been working.

In an attempt to isolate the problem, De Swardt disabled all integrations attached to Claude and ceased work the following day. Despite this, token consumption continued to rise. He documented a specific controlled interval where usage jumped from 45% to 55% while no work was performed, scheduled tasks were paused, and cloud execution was disabled.

Unable to determine the cause, he contacted Anthropic requesting an itemized list of his usage. While the company did not provide the list, it acknowledged that something was wrong. Anthropic subsequently suspended his paid account, invalidated his sessions and server-side tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription.

The suspension caused disruption for De Swardt, who operates as a sole proprietor helping small and mid-size businesses set up AI agents for tasks like data entry into accounting software. He told TechCrunch that his entire business infrastructure-including daily admin, website design, and coding-relies on these AI tools.

Upon investigation, Anthropic determined that a compromised Claude session key was used to mint unauthorized OAuth tokens. The company informed him that the account appeared to have been used by an unauthorized third-party service to handle activity for other people, though they could not determine exactly how access was obtained. Anthropic stated that the evidence was consistent with credentials being stolen or the account being connected to an outside service.

This method of theft is particularly difficult for users to detect because account support tracks total usage rather than providing itemized breakdowns, even upon request.

After sharing his experience online, De Swardt discovered he was not an isolated case. On Reddit and GitHub, other users reported similar anomalies, including accounts being auto-upgraded without consent, usage spiking from 0% to 100%, and token allowances being fully depleted daily without any user activity.

Post by Current_Afternoon_76 on Reddit
Post by Current_Afternoon_76 on Reddit

Some of these users shared emails from Anthropic explicitly warning them of the threat. In those communications, the company identified a bad actor using common infostealer malware to steal login sessions from users’ computers. These stolen sessions are then used to access Claude accounts and consume their usage. Anthropic noted that this malware does not originate from using Claude itself and is typically contracted from infected downloads or ads online.

While the company has signed out affected users, invalidated authorizations, and issued refunds in some cases, the incident has left users like De Swardt frustrated. He stated that he found no evidence of malware on his computer and was not sent the warning email that others received, leaving him with no clear explanation for how his account was breached.

Although his account was reinstated after two weeks, the lack of itemized usage data and the difficulty in resolving the issue prompted De Swardt to cancel his subscription. He has since moved to alternative platforms that allow for the use of multiple models, including open-source options, noting that the performance differences are negligible for his work.

He expressed skepticism about returning to the platform without significant changes, citing the inability of users to monitor what is consuming their tokens as a critical vulnerability. “I don’t think there’s any way that these people can protect themselves,” he said.

Maybe you would like other interesting articles?

Leave a Reply

Your email address will not be published. Required fields are marked *