Key Takeaways:
- **Mysterious Token Drain:** AI users, particularly on Anthropic’s Claude, are reporting significant, unexplained token consumption, often leading to unexpected charges and service disruptions.
- **Compromised Security:** Investigations point to compromised session keys, unauthorized OAuth tokens, and infostealer malware as root causes, highlighting vulnerabilities in user account security.
- **Transparency Deficit:** A lack of itemized usage tracking and inconsistent communication from AI service providers leaves users unable to identify misuse or adequately protect themselves.
The Ghost in the Machine: When AI Tokens Disappear into Thin Air
Imagine your electricity bill skyrocketing, but the power company can’t tell you which appliances are drawing the most energy. Now, apply that frustration to the burgeoning world of AI, where digital “tokens” power every interaction, query, and task. This is the perplexing reality faced by independent AI consultant Grant De Swardt, whose experience with Anthropic’s Claude highlights a growing concern: mysterious, unauthorized token usage draining user accounts and eroding trust.
On August 4, De Swardt, based in East Sussex, U.K., noticed an unsettling trend. His Claude Max 20x account, typically a workhorse for his business, was consuming tokens even on a day he hadn’t actively used it. The next day, after meticulously disabling all attachments and refraining from interaction, the consumption continued to climb. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt recounted to TechCrunch, puzzled by the invisible drain.
The Unseen Drain: Grant De Swardt’s Ordeal
What was siphoning off his valuable token allowance? De Swardt had no answers, so he turned to Anthropic, requesting a detailed, itemized list of his usage. To his dismay, Anthropic couldn’t provide one. However, the company did acknowledge an anomaly, suspending his paid account, invalidating all associated sessions and server-side Claude Code tokens, and issuing a partial refund of £44.49 against his $200-per-month subscription.
While the refund offered some financial solace, the suspension itself plunged De Swardt’s business into disarray. As a sole proprietor, his livelihood hinges on leveraging AI agents to automate critical tasks for small and mid-size businesses – from ingesting purchase-order data into accounting software to designing websites and handling daily administrative duties. “Like everything is just running through AI these days,” he explained, underscoring the profound impact of his AI tools being abruptly taken offline.
Unmasking the Culprit: Stolen Credentials and Session Keys
After a period of investigation, Anthropic offered De Swardt a partial explanation: a compromised Claude session key had been used to mint unauthorized Claude Code OAuth tokens. The company suggested the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people,” though they couldn’t pinpoint how the access was obtained. “They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service,” De Swardt conveyed. This pointed to a clear breach of security – a hacker had gained access to his account, silently siphoning off tokens. Crucially, because Anthropic’s account support only tracks total usage, not itemized usage (even upon request), such theft could have persisted for months undetected, a stark warning for all users of AI services.
A Growing Chorus: Others Report Similar Anomalies
De Swardt’s singular experience quickly proved to be part of a larger, unsettling pattern. Sharing his ordeal on Reddit, he was met with a flood of similar anecdotes, accumulating over 80 comments. One user claimed their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another recounted usage spiking from 0 to 49% in a mere 12 minutes, despite only using it for a couple of prompts and a web search.
The phenomenon extended beyond Reddit. A Claude user documented their account burning through its maximum tokens daily for three consecutive days without any personal interaction, prompting them to create a GitHub report. There, too, other users chimed in with identical complaints. In a testament to Anthropic’s responsiveness in some cases, two users even posted emails from the company, confirming that their tokens were indeed being stolen and offering a warning.
Anthropic’s Response: Malware Warnings and Inconsistent Communication
The emails from Anthropic to these users shed more light on a potential cause: “We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” Infostealers are insidious forms of malware that infiltrate a user’s system to pilfer saved passwords, session data, and login credentials. Upon detecting suspicious activity, Anthropic took commendable steps: signing users out, invalidating existing authorizations, issuing refunds, and advising them about potential malware infections. The company also clarified that the malware did not originate from Claude itself, but could be picked up from various online sources, such as infected software downloads or malicious advertisements.
However, a critical inconsistency remained: Grant De Swardt never received such an email. He maintains he found no evidence of his computer being compromised and is still left without a definitive explanation for how hackers gained access to his account. This highlights a potential gap in Anthropic’s ability to consistently identify and communicate the specific nature of every breach to its affected users.
The Trust Deficit: A User’s Reckoning
De Swardt’s Claude account was eventually reinstated after approximately two weeks, but the experience left a bitter taste. The protracted struggle for adequate support and the persistent absence of itemized usage tracking ultimately soured him on the platform. He subsequently canceled his subscription, opting instead for Cursor, a multi-model platform that offers the flexibility of integrating more affordable open-source options.
In his professional assessment, these alternative models perform just as effectively as Claude. “It’s not that much different or better,” he asserted, declaring he couldn’t envision returning “without [Anthropic] actually having resolved the issue in any way.” De Swardt remains convinced that Anthropic still lacks fundamental tools for users to monitor and understand their token consumption. “I don’t think there’s any way that these people can protect themselves,” he concluded, echoing the frustration of many in the AI community.
The Path Forward (or Lack Thereof): Calls for Transparency
When approached for guidance on how users can proactively identify and protect against such misuse, Anthropic conspicuously declined to comment. This silence only amplifies the concerns raised by users like De Swardt, underscoring a critical need for greater transparency and robust user-facing security tools from AI service providers. As AI becomes increasingly integral to daily business operations and personal workflows, the security and accountability of these platforms are paramount.
Bottom Line
The incidents of unexplained token consumption on AI platforms like Claude expose significant vulnerabilities in both account security and user transparency. While AI companies like Anthropic have taken steps to address specific breaches, the lack of itemized usage tracking and consistent communication leaves users exposed and frustrated. For the AI ecosystem to thrive, providers must prioritize developing robust security measures, offering granular usage insights, and establishing clear, consistent protocols for informing and assisting users when their digital assets are at risk. Without these safeguards, the promise of AI will be overshadowed by the specter of unseen drains and eroding trust.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
{content}
Source:{feed_title}

