Skip to content

Product1 publisher3 min readPublished

Anthropic suspended a consultant's Claude account for two weeks to stop a token thief

Grant de Swardt watched his Claude Max 20x allowance climb on a day he did no work. He asked Anthropic for an itemized usage log, and what he got was a two-week suspension and a partial refund of £44.49.

The Product Desk · Product desk

What happened

  • Grant de Swardt logged an interval in which his Claude Max 20x usage rose from 45% to 55% while he did no work, with scheduled Cowork tasks paused or completed and cloud execution disabled.
  • He asked Anthropic for an itemized list of what was consuming his allowance, and the company agreed something was off but did not produce one.
  • Two other users posted emails in which Anthropic warned that a bad actor was using common infostealer malware to steal Claude login sessions from computers and consume the accounts' usage.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint With support able to report only total usage, a subscriber's sole detection method is noticing the meter move on a day they know they did nothing, which fails against a thief who draws slowly.
  • cost The only containment Anthropic applied also took the customer offline, so a sole proprietor whose client work runs through agents paid two weeks of downtime against £44.49 back.
  • exposure Any machine holding a saved Claude login session is now a billing credential, and malware picked up from an unrelated download turns one seat into capacity resold to strangers.
  • contradiction Anthropic's own monitoring was good enough to warn some users unprompted, yet it sent de Swardt no warning and could not say how his account was reached, which makes the absent customer-side log look like a decision about disclosure rather than a limit on what the company can see.

The percentage on the usage screen is the entire artifact a Claude subscriber gets. It moves, and it does not say who moved it. De Swardt's cleanest measurement took his Max 20x meter from 45% to 55% on a day when scheduled Cowork tasks were paused or already finished and cloud execution was switched off [3]. That is ten points of a monthly allowance [1] spent by a party he could not name, on an account whose support tooling reports totals rather than line items [9].

Anthropic's account describes the mechanism in detail but does not explain how the credential was obtained. A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens [7], and to Anthropic the account looked as though an outside service had been running other people's activity through it, with no finding on how that service obtained access [8]. De Swardt says he found no evidence his own machine was compromised, and he never received the malware warning Anthropic sent to other affected users [15]. Those warnings describe common infostealer malware lifting Claude login sessions off people's computers and using them to consume the accounts' usage [13]. Anthropic signed those users out and invalidated their authorizations, issued some refunds, and said the malware had not come from Claude itself [14].

Fast theft is easy to notice. One Reddit user's account went from 0% to 49% in twelve minutes after a couple of prompts and a web search [11], roughly four points of allowance a minute [2]. Another burned its maximum three days running while the owner was not using it at all [12]. Anybody glancing at the meter would catch that. The case the missing log actually covers is the patient thief taking a slice a day inside a busy consultancy's normal variance, which per TechCrunch could continue for months before anyone thought to ask [9].

The containment lever and the outage are the same action. Anthropic suspended the paid account and invalidated every session and server-side Claude Code token [5], and the account came back about two weeks later [16]. De Swardt sets up agents for small and mid-size businesses, including ones that pull purchase-order data out of email into accounting software, and runs his own admin, website and coding work through agents as well [6]. The refund for the interrupted subscription was £44.49 [5], a defensible figure for unused time on a $200-a-month plan and unrelated to two weeks of a one-person business.

Then he left, and moved to Cursor for its multi-model support including cheaper open-source options, saying the alternatives were "not that much different or better" [17]. Substitution was cheap for him because he rated the capability as equivalent, so the thing that lost the account was the recovery path.

Anyone signing off on a metered agent tool faces two questions, both about the credential rather than the model. First, whether you can attribute spend to a specific session, key or machine from your own side of the account without opening a ticket. Second, whether you can revoke one compromised credential without suspending the whole account. If both answers are yes, a stolen cookie costs an afternoon. Claude subscribers currently sit with the first answer as no [9], which leaves a percentage as the only evidence in a dispute. When both answers are no, incident response looks identical to downtime; two weeks is what that measured out to here [16]. Teams that have already filled in those two boxes will spend an incident arguing about scope. The others will spend it asking support for a list that does not exist [4].

What to watch

  • Whether Anthropic adds per-session or per-key usage itemization to the account screen, visible without contacting support.
  • Whether refunds for usage consumed by stolen sessions stay case-by-case or become a stated policy.
  • Whether Cursor, the tool de Swardt moved to, can attribute spend per credential when the same session theft happens there.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories