Claude Code · Anthropic · Claude · TechCrunch AI
Hackers are stealing Claude tokens from subscribers
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something strange going on with his Claude Max 20x account.
Key facts
- On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something strange going on with his Claude Max 20x account
- It suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued him a partial refund of £44.49 for the remaining time on his $200-per-month subscription
- In the clearest controlled interval, it increased from 45% to 55% while the reporter performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no
- After investigating, Anthropic told De Swardt it found the culprit: A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens
Summary
The next day, he disabled everything he had attached to Claude and did not work with it. What was eating up his token allowance? The suspension wreaked havok on his business, he told TechCrunch. As a sole proprietor, he relies on agents throughout his whole business, too: daily admin tasks, website design, coding.