Unauthorized Access to Claude Accounts: Users Report Token Theft
By Editor • September 8, 2026 • 2 min read
In a troubling incident, multiple users of the Claude Max 20x AI service have reported unauthorized access to their accounts, leading to significant token theft. Independent AI consultant Grant De Swardt from East Sussex, U.K., first noticed unusual activity on August 4, 2023, when his token consumption increased despite him not using the service.
After disabling all connected services and still seeing his token usage rise, De Swardt reached out to Anthropic for clarification. While the company did not provide a detailed breakdown of the usage, they acknowledged something was amiss. They suspended his account, invalidated all sessions, and refunded him £44.49 for the remaining subscription period. De Swardt explained how critical these AI agents were to his business operations, stating, "Like everything is just running through AI these days."
A subsequent investigation by Anthropic revealed that a compromised session key was being used to mint unauthorized OAuth tokens. Although the exact method of the breach remained unclear, the company suggested that either session data was stolen without De Swardt's knowledge or his account had been linked to an external service. This security flaw allowed a hacker to siphon tokens from his account without detection for potentially months.
Widespread Reports of Token Misuse
De Swardt's experience resonated with others in the Claude community. In a Reddit post detailing his ordeal, he discovered that numerous users had faced similar issues. One user reported an automatic upgrade to their account without consent, leading to unexpected charges and token usage from 0% to 100%. Others echoed these sentiments, with one account exhausting its maximum tokens daily without any active usage.
As users discussed their experiences, some shared emails from Anthropic, in which the company warned them about a bad actor exploiting infostealer malware to access Claude accounts. This type of malware can infiltrate computers through various online sources, including infected downloads and malicious ads. Anthropic took action by signing out affected users and issuing refunds, but the malware was not traced back to the use of Claude itself.
Frustration with Lack of Support and Transparency
Despite the reinstatement of his account after two weeks, De Swardt expressed dissatisfaction with the support process and the absence of tools for users to monitor token consumption. He ultimately decided to cancel his subscription in favor of Cursor, which offers multiple AI models, including more affordable open-source options. "It’s not that much different or better," he noted regarding Claude's alternatives, adding that he felt unprotected against future breaches.
When approached for comment about user protection against misuse, Anthropic declined to provide additional information, leaving many users concerned about their security and the integrity of their accounts.
Source: techcrunch.com