For AI consultants and power users, the "Claude" ecosystem has become more than just a chatbot; it is a central nervous system for business automation. However, a growing wave of reports suggests that this infrastructure is increasingly vulnerable to a silent, sophisticated form of digital larceny. Users are discovering that their paid token allowances—the lifeblood of their AI-driven workflows—are being siphoned off by unauthorized third parties, leaving victims with little recourse and a growing sense of insecurity.
The issue, which appears to be linked to the exploitation of session tokens via "infostealer" malware, has sparked a crisis of confidence among the very power users Anthropic relies on to champion its technology. As individual professionals report significant financial and operational disruptions, questions are mounting regarding the security transparency of major AI platforms.
The Chronology of a Digital Heist
The alarm was first sounded in early August by Grant De Swardt, an independent AI consultant based in East Sussex, U.K. On August 4, De Swardt noticed an anomaly in his Claude Max 20x account. Despite a day off from professional obligations, his token usage dashboard showed a steady, inexplicable climb.
De Swardt, well-versed in the technical nuances of AI workflows, immediately initiated a troubleshooting protocol. On August 5, he disconnected all third-party integrations, paused his "Cowork" tasks, disabled cloud execution, and ensured no local Claude Code tasks were active. Despite this "clean room" environment, the token consumption continued to rise, jumping from 45% to 55% in a short, controlled interval.
"In the clearest controlled interval, it increased from 45% to 55% while I performed no work," De Swardt noted. When he reached out to Anthropic support, he was met with a wall of procedural opacity. The company was unable—or unwilling—to provide an itemized list of his token usage. However, they acknowledged that the activity was anomalous. Anthropic took the drastic step of suspending his paid account, invalidating all active sessions, and issuing a partial refund of £44.49 for his $200-per-month subscription.
For a sole proprietor whose business operations—ranging from website design to automated accounting—are almost entirely routed through AI agents, the suspension was catastrophic. It forced a total halt to his professional output, highlighting the precarious nature of relying on a centralized, "black box" service provider.
A Broader Pattern of Exploitation
De Swardt’s experience was far from an isolated incident. After sharing his ordeal on Reddit, he was joined by a chorus of users reporting identical symptoms. The thread, which quickly garnered over 80 comments, became a repository for digital frustration.
One user reported that their account was "auto-upgraded" without their consent, triggering credit card charges while their usage shot from 0% to 100% without any manual input. Another user documented a similar spike—0% to 49% in just 12 minutes—despite only performing two simple prompts. A third user, who eventually escalated their grievance to GitHub, reported their account burning through its entire max token limit for three consecutive days while completely dormant.
These reports point to a systemic vulnerability rather than a one-off technical glitch. The consistency across these accounts—rapid, unexplained depletion of resources—suggests that bad actors are systematically harvesting access credentials and repurposing them to power their own AI operations or secondary services.
The Mechanism: How Infostealers Operate
As the reports mounted, Anthropic began to acknowledge a specific threat vector: infostealer malware. In communications with some affected users, the company clarified the nature of the breach.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers," the company stated in an email to a victim. Infostealers are a insidious class of malware designed to live silently on a host machine, scraping browser cookies, saved passwords, and active session tokens.
Unlike a password-stealing virus that requires a user to enter their credentials on a fake site, session token theft allows a hacker to "hijack" a browser session that is already authenticated. By stealing the session cookie, the attacker can present themselves to the Anthropic servers as the legitimate, logged-in user, bypassing two-factor authentication (2FA) entirely.
Anthropic maintains that the source of the malware is not their own platform but rather the broader digital ecosystem—infected software downloads, malicious advertisements, or compromised browser extensions. However, for the victim, the distinction is largely academic. The result is the same: their professional tools are weaponized against them, and their subscription fees are redirected to fund unauthorized activity.
The Transparency Gap: Why Users Feel Vulnerable
The most significant point of friction between Anthropic and its power users is the lack of granular visibility into account activity. De Swardt and others have argued that the inability to view an itemized log of token usage—where it was spent, what prompts were issued, and from which IP addresses—makes it impossible for users to protect themselves.
In the case of De Swardt, even after an internal investigation, Anthropic’s feedback remained vague. They informed him that his session key had been used to "mint unauthorized Claude Code OAuth tokens" and suggested the account was being used by a third-party service. Yet, they could not explain how the initial breach occurred.
When victims request the kind of data that is standard in cloud computing—such as detailed access logs or usage breakdowns—they are met with silence or boilerplate responses. This lack of transparency has led to a breakdown in trust. For professionals who manage sensitive client data and rely on AI for business continuity, the inability to audit their own account usage is a major red flag.
Implications for the AI Industry
The "token theft" phenomenon serves as a wake-up call for the broader AI industry. As LLMs move from novelty chatbots to mission-critical infrastructure, the security protocols governing them must evolve accordingly.
1. The Security Paradox of "Seamless" Logins
The very convenience that makes AI tools popular—persistent, long-lived sessions that allow users to jump back into their workflows instantly—is exactly what makes them attractive targets for session hijacking. The industry is now facing a trade-off: either tighten security with frequent re-authentication (which disrupts workflow) or develop more sophisticated anomaly detection that can flag suspicious token usage in real-time.
2. The Need for Auditable Logs
In the traditional software-as-a-service (SaaS) world, administrative dashboards that allow users to view active sessions, revoke specific devices, and export usage logs are standard. Anthropic’s current stance—declining to comment on how users can identify misuse—is increasingly viewed as untenable by the professional community. To maintain its status as an enterprise-grade tool, the company must provide users with the tools to police their own accounts.
3. User Migration and Platform Loyalty
For De Swardt, the ordeal was the final straw. After his account was reinstated, he opted to cancel his subscription and transition his workflows to Cursor, which allows for the use of multiple models, including open-source alternatives. This "platform churn" is a warning to AI providers: users are willing to pay for premium models, but they are not willing to endure unpredictable downtime, lack of security transparency, and the potential for financial loss.
Conclusion: A New Era of Digital Hygiene
The incident highlights a shifting reality in cybersecurity. As AI becomes integrated into every facet of our digital lives, users must treat their AI platform logins with the same level of caution they reserve for their primary banking accounts.
However, the burden of security cannot rest solely on the user. While individuals should exercise caution regarding software downloads and browser extensions, platforms like Anthropic have a responsibility to provide the infrastructure necessary to detect and mitigate unauthorized activity. Until companies provide robust, transparent auditing tools, the "invisible thief" will likely continue to find easy prey in the cloud.
For now, the lesson is clear: for those who build their businesses on the back of generative AI, the cost of an "always-on" connection may be higher than the monthly subscription price. It is a reminder that in the race to deploy the most advanced models, the foundational pillars of user control and account security must not be left behind.
