Claude AI Token Drain Mystery: Consultant Reports Unexplained Usage Spikes on Idle Max 20x Account
By admin | Sep 08, 2026 | 3 min read
On August 4, Grant de Swardt, an independent AI consultant based in East Sussex, UK, noticed something unusual with his Claude Max 20x account. Despite not working that day, his token usage kept climbing. The following day, he disconnected everything linked to Claude and avoided using it altogether—yet his token consumption still increased. Puzzled about what was draining his allowance, he reached out to Anthropic for a detailed breakdown. The company didn't provide one, but acknowledged that something seemed amiss. They suspended his paid account, revoked all his sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining time on his $200-per-month subscription.
De Swardt's work involves helping small and mid-sized businesses implement agents—essentially acting as a forward-deployed engineer for hire—for tasks like automatically pulling purchase-order data from emails into accounting software. As a solo operator, he also depends on agents across his own business for daily admin, website design, and coding. "Everything just runs through AI these days," he remarked. After looking into the matter, Anthropic informed him they'd found the source: a compromised Claude session key had been used to generate unauthorized Claude Code OAuth tokens. "They say the evidence points either to credentials or session data being taken without my knowledge, or to the account being linked to an outside service."
In essence, a hacker had gained access to de Swardt's account and was quietly siphoning off his tokens. Since account support tracks overall usage but not itemized usage—even when requested—this kind of theft could have gone unnoticed for months. He shared his experience on Reddit, and after 80 comments, realized he wasn't alone. One user claimed their "account was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it." Another saw usage jump from 0 to 49 percent in 12 minutes, despite only using it for a few prompts and a web search. A third Claude user reported burning through their max tokens daily for three days without any activity on their end, and filed a GitHub report about it. As with the Reddit thread, others chimed in with similar stories.
Notably, two of those users shared emails from Anthropic where the company—to its credit—had flagged the theft and warned them. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," the email stated. Infostealers are a type of malware that installs itself on a device and harvests saved passwords, session data, and login credentials. When Anthropic detected suspicious activity, it logged users out, invalidated existing authorizations, issued some refunds, and cautioned that they might have malware. The company also clarified that the malware didn't originate from using Claude itself—such infections can come from various online sources, like downloading compromised software or clicking on infected ads.
However, de Swardt never received one of those emails. He maintains he found no evidence his computer was compromised and still has no way to determine how the hackers gained access. His Claude account was restored after roughly two weeks, but the struggle to get timely assistance—combined with the lack of itemized usage details—left a bad taste. He canceled his subscription in favor of Cursor, which supports multiple models, including more budget-friendly open-source options. In his view, these alternatives perform just as well as Claude. "It's not that much different or better," he said, adding that he can't imagine returning "without them actually having resolved the issue in any way." He notes that Anthropic still lacks tools for users to see what's consuming their tokens. "I don't think there's any way that these people can protect themselves."
When asked how users might identify misuse, Anthropic declined to comment.
Comments
Please log in to leave a comment.
No comments yet. Be the first to comment!