Hackers are stealing Claude tokens from subscribers
Source Entity
Julie Bort

Anthropic is investigating reports of unauthorized token usage on Claude accounts following a discovery by a user in the UK. The company has since issued warnings to subscribers to remain vigilant against potential account compromises.
The Rising Threat of AI Account Hijacking
In a concerning development for the generative AI sector, users of Anthropic’s Claude have reported instances of unauthorized token consumption. The issue came to light on August 4, when Grant de Swardt, an independent AI consultant based in the UK, observed significant activity on his 'Claude Max 20x' account despite being inactive. This incident highlights a growing vulnerability in subscription-based AI platforms where 'tokens' act as a form of digital currency that can be exploited by malicious actors.
The Anatomy of the Token Theft
De Swardt’s investigation into his account was meticulous. Even after disabling all external integrations, pausing scheduled tasks, and ensuring no local Claude Code tasks were active, his token usage climbed from 45% to 55%. This controlled observation suggests that the unauthorized access was not a result of a user-side configuration error, but rather an external exploitation of the account credentials or API access tokens. When an account is compromised in this manner, it allows attackers to leverage the powerful processing capabilities of models like Claude for their own data-intensive tasks at the subscriber's expense.
Challenges in Forensic Accountability
One of the most troubling aspects of this report is the difficulty in obtaining transparency from service providers. Upon contacting Anthropic, de Swardt requested an itemized list of his token usage to identify where the activity originated. The fact that the company could not provide this granular data points to a significant gap in the current security architecture of many Large Language Model (LLM) platforms. Without an audit trail, users are left in a position of vulnerability, unable to verify if their accounts are being used for malicious code generation or illicit data processing.
Broader Implications for AI Security
As AI tools become increasingly integrated into professional workflows, they are becoming high-value targets for cybercriminals. Unlike traditional software, where a breach might result in data theft, an AI breach allows for the theft of computational resources. This 'resource hijacking' can be difficult to detect, as evidenced by de Swardt’s experience, because the AI itself is performing the tasks requested by the attacker. This event serves as a wake-up call for both providers and users regarding the necessity of multi-factor authentication (MFA) and more robust session management.
Future Trends and Mitigation
Looking ahead, we can expect a shift toward more rigorous security protocols within the AI-as-a-Service industry. Companies like Anthropic will likely need to implement real-time usage alerts, enhanced API key rotation, and more transparent logging systems to protect their user base. As the market matures, the ability to track and verify every token spent will become a standard requirement rather than an optional feature. For now, users are advised to monitor their usage statistics closely and report any anomalies to the provider immediately.
Conclusion
The incident involving Grant de Swardt underscores the reality that AI platforms are not immune to the security challenges facing the broader digital landscape. While Anthropic has acknowledged the issue and suspended affected accounts, the event remains a critical reminder of the importance of proactive security measures. As the reliance on these models grows, the gap between platform convenience and platform security must be bridged to maintain user trust and prevent the widespread abuse of expensive computational resources.