Users on Claude’s paid plans are losing tokens at times when they are not using the model at all. The cause is common malware that collects active Claude login credentials from computers. Attackers then use these logins to run their own tasks on someone else’s subscription. Anthropic is already sending warning emails to affected users, terminating their sessions, and issuing partial refunds. The problem is that victims have no way to find out where their tokens are going.
No work in the morning, yet the limit was still being used up
On August 4, Grant de Swardt, an independent artificial intelligence consultant from East Sussex, England, noticed something strange about his Claude Max 20x account. He was not working that day, yet his token usage was increasing. The next day, he disconnected all devices linked to Claude and once again did no work. Usage continued to rise. “Usage kept increasing while I was doing nothing,” de Swardt told TechCrunch. According to him, scheduled tasks on the Cowork platform were paused or completed, cloud execution was disabled, and no local Claude Code task was running.
Because he had no idea what was consuming his limit, he contacted Anthropic and requested an itemized usage report. He did not receive one, but the company acknowledged that something was wrong. It blocked his paid account, invalidated all sessions and server tokens for Claude Code, and refunded him just under forty-five pounds for the unused portion of the subscription, which costs two hundred dollars per month. The block disrupted his business. He makes a living setting up agents for small and medium-sized companies, such as automatically transferring order data from emails into accounting software. As a sole trader, he used agents for everything else as well, including routine administration, website creation, and programming. His entire daily workflow runs through artificial intelligence.
How the key theft works
After investigating, Anthropic wrote to de Swardt with its findings. Someone had obtained the login key for his account, started using it as their own, and as a result de Swardt’s tokens were being depleted. According to the company, the account appeared to be used by a suspicious third-party service that was handling other people’s activity through it. However, it was not possible to determine how the attackers had gained access. Anthropic said the evidence suggested either that someone had stolen the login data without the owner’s knowledge or that the account had been connected to an external service.
Technically, the method bypasses both the password and two-factor authentication. The malware does not seek login credentials, but rather what is known as a session cookie. This is a browser record that keeps you logged in even after you close the window. An attacker can then use such a record to generate additional access tokens, which works like making copies of a key from the stolen original. Customer support monitors overall usage, but it will not provide an itemized breakdown even upon request. This type of theft can therefore continue for months before anyone notices.
De Swardt described his experience on Reddit, and after eighty comments it was clear that he was not alone. One user claimed that his account had been upgraded to a higher-tier plan without his consent, his card had been charged, and usage had risen on its own from zero to one hundred percent even though he had done nothing with the model. Another user watched his limit rise from zero to 49 percent within twelve minutes, despite having submitted only a few queries and performed one web search. Another subscriber reported that his account had exhausted the entire daily limit for three consecutive days while he was not using it at all, and he filed a report about the issue on GitHub. Similar experiences also appeared beneath his post there.
Anthropic’s statement
Two users published emails in which Anthropic warned them about their disappearing tokens. The messages stated that the company had recently discovered the use of common infostealer malware to steal Claude login credentials from users’ computers. Attackers then used these logins to access the accounts and consume their limits. Infostealers are malicious programs that install themselves on a computer and extract stored passwords, login data, and access credentials from it.
When the company detected suspicious activity, it logged users out, invalidated issued permissions, refunded some of them, and warned them about the presence of malware on their computers. It also removed saved payment methods from affected accounts so that no one could use them to make purchases. At the same time, it emphasized that the malware had not infiltrated the Claude service itself. Malicious code can be downloaded from many places, from installing an infected program to clicking on a fraudulent advertisement. Security specialists recommend that subscribers scan their computers with antivirus software focused on infostealers, review active sessions on their accounts, and regularly monitor their own usage.
De Swardt received no such warning. He insists that he found no infection on his computer and still has no way to determine how the attackers got in. Anthropic restored his account after about two weeks. However, the slow resolution and lack of an itemized usage report discouraged him from using Claude so much that he canceled his subscription and switched to Cursor, where he can choose among several models, including cheaper open-source options. According to him, these models work just as well. Haas adds that he sees no reason to return to Anthropic until the company resolves the problem in some way. He says a tool that would allow users to verify what consumed their tokens is still unavailable, leaving users with no way to protect themselves effectively. When asked how users are supposed to identify abuse, Anthropic declined to answer.



