Someone was using his Claude account. He wasn't at his computer
A UK consultant watched his paid AI limit drain while he did nothing. Anthropic later told users that malware is stealing Claude logins — and that there's no bill you can check to see who's spending your money.
On August 4, Grant De Swardt, an independent AI consultant in East Sussex, UK, noticed his Claude account was burning through its allowance. He hadn't been working that day. The next day he switched off everything connected to the account and again did nothing. Usage went from 45% to 55% anyway.
He asked Anthropic for an itemized list — a simple question: what exactly is spending my tokens? The company didn't provide one. It agreed something was wrong, suspended his paid account, killed all his sessions, and refunded £44.49 of his $200-per-month subscription. Then it told him what it had found: a compromised session key had been used to mint unauthorized Claude Code tokens. Someone else was using his account, and Anthropic could not determine how they got in.
A session key is the little pass your computer keeps so you don't have to log in every morning. Steal that pass and you don't need a password — you're already inside. The malware doing this is nothing exotic: an infostealer, the ordinary junk you can pick up from a fake download or a bad ad. Anthropic said in emails to affected users that a bad actor is using "common infostealer malware" to take Claude login sessions from people's computers and burn their usage. It also said the malware doesn't come from using Claude itself.
Here's the part that should bother anyone who pays for anything by the month. Anthropic's support tracks how much you used in total, but not what you used it on. No line items, even if you ask. So a stranger can spend your allowance for weeks and the only thing you'd see is a number climbing faster than it should.
You get a bill with a total and no line items — and you're told to figure out the rest.
That's the real story here, and it goes far past one company. AI subscriptions are becoming a fixed monthly cost like rent or a phone plan, and people are wiring them into work they get paid for. De Swardt sets up agents for small businesses — pulling purchase-order data out of emails into accounting software — and runs his own admin, web design and coding through them. "Like everything is just running through AI these days," he said. When his account was suspended for roughly two weeks, that wasn't an inconvenience. That was the business stopping.
Anyone who pays monthly for an AI tool and just watches the usage bar — freelancers, students on a plan they can barely afford, people who bought a subscription to write code or do their side gig. If someone drains it by Tuesday, you either stop working or pay again. It also hits people building small businesses on top of these tools: De Swardt's clients weren't hacked, but his account being frozen for two weeks froze their work too. And it should worry anyone who keeps ten browser tabs logged in forever — the thing being stolen here isn't a password, it's the fact that you never log out.
Two things to watch, and the source names both. De Swardt says Anthropic still lacks tools that let users see what's consuming their tokens — so the test is whether itemized usage ever appears. And when TechCrunch asked Anthropic how users can identify misuse, the company declined to comment. No timeline was given for either. Anthropic did send warning emails to some affected users; it did not send one to De Swardt.
He didn't wait for a fix. He cancelled and moved to Cursor, which lets him run several models including cheaper open-source ones — and he says they work about as well. "It's not that much different or better." The theft cost Anthropic £44.49 in refund. Losing a customer who thinks the product is replaceable costs rather more.
Sources: TechCrunch, "Hackers are stealing Claude tokens from subscribers" by Julie Bort, September 8, 2026.
Взломщики через обычный вирус-инфостилер угоняют сессии Claude и втихую сжигают чужие оплаченные лимиты — а у подписчика нет ни детализации расходов, ни способа это заметить.
Written by THE TELL’s AI newsroom. how we work · corrections