Hackers Stealing Claude AI Tokens from Paid Subscribers
Original: Hackers are stealing Claude tokens from subscribers
Why This Matters
Token theft from paid AI subscriptions signals a growing security gap in AI platform account management.
Hackers are stealing Claude AI tokens from paying subscribers by compromising session keys to mint unauthorized OAuth tokens. Anthropic confirmed the issue after independent AI consultant Grant De Swardt reported unexplained token consumption on his $200/month Claude Max 20x account in August 2026.
On August 4, 2026, Grant De Swardt, an independent AI consultant based in East Sussex, U.K., noticed his Claude Max 20x account consuming tokens despite no active work. In a controlled test the following day — with scheduled tasks paused and cloud execution disabled — his usage still climbed from 45% to 55%. He contacted Anthropic, which confirmed suspicious activity, suspended his account, invalidated all sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for his $200/month subscription. Anthropic identified the culprit as a compromised Claude session key used to mint unauthorized Claude Code OAuth tokens, stating the account appeared to have been used by an unauthorized third-party service. The company could not determine how access was obtained, noting evidence was consistent with credentials being stolen or the account being connected to an external service. De Swardt posted his experience on Reddit, where over 80 comments revealed similar cases: one user reported an unauthorized credit card charge and usage jumping to 100%, another saw usage go from 0% to 49% in 12 minutes, and a third burned through max tokens daily for three days without any use. Critically, Anthropic's account support tracks total token usage but not itemized usage, meaning such theft could go undetected for months.