Home / Technology / AI Account Hacked: Tokens Vanish in Mysterious Breach
AI Account Hacked: Tokens Vanish in Mysterious Breach
9 Sep
Summary
- AI consultant discovered unexplained token usage on his account.
- Compromised session key led to unauthorized token minting.
- Users report similar unauthorized AI token consumption incidents.

Grant de Swardt, an independent AI consultant, recently identified suspicious token consumption on his Claude Max 20x account. Despite no work being performed, his token usage inexplicably increased. Upon investigation, Anthropic confirmed a compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens, suggesting a third-party service or credential theft.
This event disrupted de Swardt's business operations, which heavily rely on AI agents for tasks like data management and coding. He reported that Anthropic could not determine the exact access method but confirmed unauthorized activity. The company issued a partial refund and suspended his account.
De Swardt's experience is not isolated. Other Claude users have reported similar issues, including unauthorized account upgrades and rapid token depletion. Some users received warnings from Anthropic indicating their tokens were being stolen via infostealer malware, which targets saved passwords and session data. Anthropic has stated this malware does not originate from its platform.
Following his experience, de Swardt canceled his Claude subscription, citing the difficulty in resolving the issue and the lack of transparent usage tracking. He has since moved to alternative platforms that offer more affordable options and multi-model support, expressing concerns about Anthropic's ability to protect users from such breaches.