Executive Overview
The rapid integration of generative artificial intelligence into daily workflows has transformed how independent consultants, small businesses, and enterprise teams operate. Platforms like Anthropic’s Claude have transitioned from novelty chat interfaces into robust operational engines, executing complex coding tasks, managing administrative back-ends, and orchestrating multi-agent systems. However, as the utility and economic value of these AI services scale, they have also become prime targets for cybercriminals.
A growing security crisis is quietly unfolding across high-tier AI developer accounts, driven by sophisticated infostealer malware and systemic platform blind spots. Independent developers and power users are discovering that their premium token allowances—often costing hundreds of dollars a month—are being siphoned away in the dark by unauthorized third parties.
This investigative report examines the disturbing phenomenon of AI token theft through the lens of affected professionals, such as Grant De Swardt, an independent AI consultant based in the U.K. His ordeal exposes critical vulnerabilities in account management, a troubling lack of itemized token auditing tools across major AI providers, and the real-world operational chaos that follows when a vital digital infrastructure is abruptly severed. As cybercriminals leverage stolen session credentials to hijack computing power for illicit proxy services, the incident raises pressing questions about user safety, platform accountability, and the inherent risks of relying entirely on centralized AI ecosystems.
Detailed Chronology: The Anatomy of a Stealthy Breach
The Mystery of the Creeping Meter
The trouble began on a quiet Monday, August 4. Grant De Swardt, an independent AI consultant operating out of East Sussex, U.K., noticed an anomaly on his Claude Max 20x subscription account. Despite not performing any work that day, his token consumption metrics were steadily climbing.
As a forward-deployed engineer for hire who builds automated workflows—such as pipelines that load purchase-order data directly from emails into accounting software—De Swardt relies heavily on automated scripts and AI agents. Naturally, his first assumption was that a rogue local script or an overlooked scheduled task was burning through his quota.
Determined to isolate the variable, De Swardt took exhaustive troubleshooting steps the following day. He completely disabled every integration, extension, and tool attached to his Claude account and actively refrained from doing any work. Yet, the token consumption continued its inexorable climb.
In a meticulously documented controlled interval, De Swardt observed his token usage leap from 45% to 55% during a period when zero work was performed, scheduled Cowork tasks were either paused or completed, cloud execution features were disabled, and no corresponding local Claude Code tasks were active.
"In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task," De Swardt recalled.
Hitting a Wall of Platform Opacity
Baffled by the mysterious drainage of his expensive $200-per-month subscription tier, De Swardt reached out to Anthropic support. He requested an itemized breakdown of his token usage to pinpoint which prompts, sessions, or API calls were draining his allowance.
Anthropic did not provide an itemized list—revealing a significant transparency gap in the platform’s backend infrastructure—but support representatives agreed that anomalous activity was clearly taking place. Swiftly, the company suspended his paid account, invalidated all active sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his billing cycle.
While swift security measures are generally welcomed, the suspension wreaked absolute havoc on De Swardt’s business. Operating as a sole proprietor, his entire operational framework relies on AI agents. From daily administrative duties and website design to complex coding and client deployment tasks, his business model is deeply embedded in the ecosystem.
"Like everything is just running through AI these days," De Swardt noted, describing the immediate paralysis he faced when his primary digital assistant was abruptly locked out.
The Investigation and the Culprit
After conducting a backend investigation, Anthropic ultimately reported back to De Swardt with an unsettling explanation: a compromised Claude session key had been leveraged to mint unauthorized Claude Code OAuth tokens.
According to the information relayed to him, the account "appeared to have been used by an unauthorized-looking third-party service to handle activity for other people." However, Anthropic’s diagnostic tools could not definitively determine how the initial access was obtained.
"They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service," De Swardt explained.
Essentially, an unknown actor had covertly hijacked his session credentials and was siphoning his token allowance to fuel an unauthorized proxy or third-party service. Because Anthropic’s current customer support and dashboard metrics track only aggregate usage rather than itemized transactional logs, this type of sophisticated theft can operate completely undetected for weeks or even months.
Supporting Context & Metrics: A Widespread Epidemic
Finding Company on Reddit and GitHub
Seeking answers and hoping to see if others were experiencing similar anomalies, De Swardt shared his ordeal in a post on the r/ClaudeAI Reddit community. The response was immediate and overwhelming, generating scores of comments from users reporting identical, inexplicable token drains.
The anecdotal evidence painted a picture of a systematic issue rather than an isolated glitch:
- The Auto-Upgrade Victim: One Reddit user claimed their account was upgraded without consent, their credit card was charged, and usage spiked from 0% to 100% automatically without them interacting with the interface.
- The Rapid Drain: Another user reported that their token usage surged from 0% to 49% in a mere 12 minutes, despite having only submitted a couple of basic prompts and performing a single web search.
- The Ghost Runner: A third user documented a nightmare scenario where their account burned through its maximum allowable token quota every single day for three consecutive days while completely sitting idle. This user escalated the issue by filing a formal report on the official Anthropic Claude Code GitHub repository, where numerous other developers corroborated similar stories.
The Infostealer Connection
As support tickets piled up across these forums, a clearer narrative began to emerge. A subset of affected users shared official warning emails they had received directly from Anthropic’s security team—confirming that the platform was waking up to a coordinated attack vector.
One such email read:
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage."
Infostealer malware represents a particularly insidious class of cyber threat. Once installed on a victim’s machine—often via pirated software downloads, deceptive malicious ads, or compromised email attachments—these scripts scour local system files, web browsers, and application caches. They bypass traditional password fields by extracting active session cookies, saved login credentials, and authentication tokens directly from local storage.
When Anthropic’s internal telemetry detected this abnormal behavioral patterns, the platform’s automated response protocols kicked in: users were forcefully signed out, existing API authorizations and session keys were invalidated, partial refunds were processed, and security alerts were dispatched warning of potential malware infections on the host machine.
The Accountability Gap
Despite Anthropic attributing the breaches to common infostealer malware, the narrative did not neatly apply to all victims. De Swardt, for instance, maintains that he conducted thorough forensic checks on his own systems and found zero evidence of a compromise. To this day, he remains frustrated by the lack of clear diagnostic data showing exactly how the breach occurred.
Furthermore, while Anthropic took corrective measures for some users by issuing warnings and refunds, many others were left navigating prolonged account suspensions with little visibility into the root cause. When pressed by journalists for comment or for guidance on how everyday users can proactively identify and mitigate misuse, Anthropic declined to comment.
Official Statements & Industry Implications
The fallout from these token-hijacking incidents highlights a broader systemic vulnerability within the burgeoning generative AI economy. As enterprise-grade and pro-sumer AI tiers command substantial monthly fees—ranging from $20 to upwards of $200—accounts have essentially evolved into high-value digital currency wallets.
The Value of Stolen Compute
In the underground cybercrime economy, raw computing power and high-tier API access are heavily monetized. Bad actors routinely seek out compromised accounts to bypass stringent rate limits, train competing models, run automated scraping operations, or resell pooled access to third parties on dark-market forums.
By hijacking premium accounts like Claude Max tiers, cybercriminals gain access to massive context windows and rapid processing speeds without incurring the direct financial overhead or leaving a traceable credit card trail.
The Demand for Granular Telemetry
A core grievance voiced by De Swardt and echoed across developer communities is the archaic state of account telemetry. In traditional cloud computing environments—such as Amazon Web Services (AWS), Google Cloud Platform (GCP), or Microsoft Azure—users have access to granular, itemized logs detailing every single API request, IP address, timestamp, token count, and resource consumption metric down to the second.
In contrast, consumer and pro-sumer AI platforms frequently offer opaque usage meters. Users are presented with a generalized percentage bar (e.g., "55% used") with virtually no insight into what generated the load. Without itemized transaction histories, users are flying blind, unable to distinguish between legitimate heavy usage, runaway local scripts, or covert cybercriminal activity.
Future Outlook: Moving Beyond Blind Trust
After a frustrating two-week ordeal, De Swardt’s Claude account was eventually reinstated. However, the combination of sluggish administrative support, the lack of transparency tools, and the lingering threat of unmitigated session hijacking permanently soured his relationship with the platform.
Rather than returning to Claude, De Swardt cancelled his subscription entirely and migrated his workflows to Cursor, an AI-first code editor that supports multiple model integrations. Crucially, Cursor allows users to plug in more affordable open-source or alternative models, reducing reliance on any single proprietary ecosystem.
Reflecting on his decision, De Swardt noted that alternative models perform just as capably for his daily professional requirements, stating that Anthropic’s offerings are "not that much different or better." He firmly declared that he cannot justify returning to a platform "without them actually having resolved the issue in any way."
Lessons for the AI Industry
As generative AI solidifies its place as the backbone of modern knowledge work, platform developers must reckon with the evolving threat landscape. To maintain user trust and safeguard professional livelihoods, the industry must urgently adopt several key security and transparency enhancements:
- Granular Usage Auditing: AI providers must implement detailed, itemized activity dashboards that allow users to view timestamps, associated IP addresses, session identifiers, and exact token costs for every prompt or API call.
- Proactive Anomaly Detection & Alerts: Automated security layers should flag unusual consumption spikes—such as high utilization during atypical working hours or idle periods—and trigger immediate two-factor authentication (2FA) verification challenges before allowing tokens to burn.
- Robust Session Management: Enhanced cryptographic binding between local applications, OAuth tokens, and hardware identifiers can help prevent stolen session cookies from being successfully re-minted or deployed on remote third-party servers.
- Responsive Support Infrastructure: As AI tools become mission-critical business assets, platform providers must scale their support operations to ensure that falsely flagged or compromised accounts can be investigated and restored rapidly, minimizing downtime for independent operators.
Until the AI industry closes these security gaps and provides users with the diagnostic visibility standard in other tech sectors, developers and small business owners remain uniquely vulnerable. In the new digital gold rush, AI tokens are valuable currency—and safeguarding them will require far more than automated logouts and silence from platform providers.

Belum ada komentar. Jadilah yang pertama berkomentar!