The trouble began on August 4, when de Swardt noticed his token usage climbing despite zero activity. After disabling all integrated tasks and cloud execution, the consumption continued to rise. Anthropic eventually confirmed his session key had been compromised, allowing a third party to mint unauthorized OAuth tokens. The company suggested the breach stemmed from external infostealer malware, which targets saved browser sessions to bypass standard login security.
De Swardt is not an isolated case. A surge of similar reports has emerged on Reddit and GitHub, with users describing sudden account upgrades and rapid depletion of daily limits. While Anthropic has proactively identified some breaches by invalidating sessions and issuing refunds, the support process remains opaque. The company currently lacks granular, itemized usage logs, making it nearly impossible for subscribers to verify exactly which prompts or processes are consuming their quotas.
For de Swardt, the lack of transparency and the slow recovery process proved disqualifying. After his account was reinstated, he canceled his $200-per-month subscription in favor of Cursor, citing better control and the ability to leverage more affordable, open-source models. Despite the influx of reports, Anthropic has declined to provide specific guidance on how users can monitor or prevent this type of unauthorized access.

Comments (0)
No comments yet. Be the first!