
Anthropic is charging people $200 a month for Claude Max, and someone else is spending those tokens. That’s the blunt reality facing a growing number of subscribers who’ve watched their usage climb without touching the product, received little useful help from support, and, in some cases, only found out about the theft because another user posted on Reddit.
Grant De Swardt, an independent AI consultant based in East Sussex, U.K., first noticed the problem on August 4. He hadn’t worked that day, but his token usage kept rising. He ran a controlled test the following day, pausing scheduled tasks and disabling cloud execution entirely. His usage still went from 45% to 55% with no work performed. He contacted Anthropic and asked for an itemized breakdown. According to TechCrunch, Anthropic didn’t provide one. Instead, it suspended his account, invalidated his sessions, and issued him a partial refund of £44.49.
The suspension hit hard. De Swardt runs a one-man operation helping small and mid-size businesses deploy AI agents for tasks like pulling purchase orders from emails into accounting software. He also relies on those same agents for his own daily work, from admin to coding to web design. Two weeks without his account meant two weeks of business disruption. When Anthropic finally explained what happened, it told him a compromised session key had been used to mint unauthorized OAuth tokens. The account had apparently been accessed by a third-party service that used it to handle activity for other people. Anthropic couldn’t tell him how that service got in.
After De Swardt posted on Reddit, 80 comments made clear this wasn’t an isolated incident. One user reported their account was auto-upgraded without consent and their card charged. Another saw usage jump from 0 to 49% in 12 minutes after doing almost nothing. A third burned through their full token allowance every day for three days without opening the app. A GitHub thread surfaced similar reports.
Anthropic did send some affected users a warning email describing the attack. The culprit is infostealer malware, software that quietly pulls saved passwords and session data from infected machines. When Anthropic spotted suspicious activity on those accounts, it signed users out and issued refunds. De Swardt never received that email. He says he found no evidence of malware on his computer and still has no clear answer on how the breach happened.
This matters beyond one consultant’s bad month. The absence of itemized usage data is a structural problem. Without it, this kind of theft can run for months before a user notices anything. And when asked how users can identify and stop misuse, Anthropic declined to comment. De Swardt has since cancelled his subscription and moved to Cursor. His conclusion is hard to argue with: ‘I don’t think there’s any way that these people can protect themselves.’