Stolen Claude Tokens Expose a New Security Challenge for the AI Subscription Economy

Unauthorized access to Claude sessions is raising questions about account security, usage transparency, and the growing financial dependence on AI-powered work.

TNN AI & Technology Desk author photo
Wednesday, September 9, 2026

The rapid expansion of artificial intelligence subscriptions is creating a new kind of digital dependency, where access to AI models has become an operational resource with direct economic value. A recent case involving unauthorized consumption of Claude tokens illustrates how this new environment is also creating security risks that extend beyond traditional account compromise.

The issue came to light after Grant De Swardt, an independent AI consultant based in East Sussex in the United Kingdom, noticed unexpected activity on his Claude Max 20x subscription. Despite not working with the platform on August 4, his available token allowance continued to decline.

The following day, De Swardt attempted to isolate the source of the activity. He disabled the services and tools connected to Claude and avoided using the platform himself. However, token consumption continued to increase.

During one of the clearest periods of observation, his usage reportedly rose from 45% to 55% despite the absence of active work. Scheduled Cowork tasks had been paused or completed, Dispatch and cloud execution were disabled, and there was no active local Claude Code task corresponding to the additional consumption.

The unexplained activity led De Swardt to contact Anthropic and request a detailed breakdown of what was using his tokens. According to his account, the company did not provide an itemized usage report, although it acknowledged that unusual activity had occurred.

Anthropic subsequently suspended the paid account, invalidated existing sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining portion of his subscription period. The Claude Max 20x plan was priced at approximately $200 per month.

For De Swardt, however, the incident was not simply an inconvenience involving a consumer software subscription. His professional work depends heavily on AI systems. As an independent consultant, he helps small and medium-sized businesses implement AI agents capable of performing operational tasks, including automatically transferring purchase-order information from emails into accounting software.

AI tools are also integrated into his own daily workflow, supporting administrative work, website design, coding, and other business activities. This level of dependence demonstrates how AI subscriptions are increasingly evolving from optional productivity products into essential components of professional infrastructure.

The investigation eventually pointed to unauthorized access to De Swardt's account. Anthropic informed him that a compromised Claude session key had been used to generate unauthorized Claude Code OAuth tokens.

According to the explanation provided to him, the account appeared to have been used by a suspicious third-party service to process activity for other individuals. However, the company was reportedly unable to determine exactly how that external party obtained access to the account.

The incident represents an emerging security challenge for the AI economy. In traditional subscription services, unauthorized access may expose personal information or enable fraudulent purchases. In AI platforms, however, stolen access can also allow attackers to consume a customer's computational resources.

Tokens have effectively become a digital economic asset. They determine how much a subscriber can interact with advanced AI models, generate code, execute tasks, and operate AI-powered workflows. Unauthorized token consumption can therefore directly reduce the value of a paid subscription while disrupting professional operations.

One of the central concerns highlighted by the incident is the limited visibility users may have into their own AI resource consumption. While account systems can track overall usage, the absence of detailed, itemized reporting can make it difficult for subscribers to identify exactly which service, application, task, or session is responsible for consuming their allocation.

Without that level of transparency, unauthorized activity may remain undetected for extended periods. A user may simply observe that their monthly or daily usage limit is disappearing without being able to determine whether the cause is legitimate automation, a configuration issue, a connected third-party service, or an attacker.

After sharing his experience publicly, De Swardt discovered that other Claude users had reported similar unexplained usage patterns.

One user claimed that their account had been upgraded without authorization, followed by a credit card charge and a rapid increase in usage from zero to full capacity despite little or no direct interaction with the platform.

Another user reportedly saw usage increase from zero to 49% within approximately 12 minutes after performing only limited activity involving a small number of prompts and a web search.

A separate Claude user said their account consumed its maximum token allocation for three consecutive days without active use. The user subsequently documented the issue through a public GitHub report, where other users also shared comparable experiences.

Some affected users posted communications from Anthropic indicating that the company had identified suspicious activity and believed tokens were being stolen.

According to those communications, a malicious actor was using common infostealer malware to obtain Claude login sessions from users' computers. The stolen session information could then be used to access Claude accounts and consume the available usage associated with those subscriptions.

Infostealer malware is designed to extract sensitive information from infected systems. Depending on the malware and the compromised environment, this information can include saved passwords, browser credentials, session cookies, authentication data, and other login-related information.

The security model surrounding AI subscriptions therefore increasingly overlaps with broader endpoint security. A user's account may be protected by the AI provider's authentication systems, but compromised credentials or session data on the user's own device can potentially create another path for unauthorized access.

Anthropic reportedly told affected users that the malware responsible for these incidents did not originate from using Claude itself. Such malicious software can be acquired through a wide range of online sources, including infected software downloads, malicious advertising, or other compromised digital environments.

When suspicious activity was detected in certain cases, Anthropic reportedly signed users out of their accounts, invalidated existing authorizations, provided refunds in some situations, and warned users about the possibility that their devices had been affected by malware.

De Swardt's situation remained more complex. He said he did not receive the same warning email and found no evidence that his own computer had been compromised. As a result, he remained uncertain about how the unauthorized party gained access to his Claude account.

This uncertainty exposes another important challenge in the design of AI platforms: security tools must not only detect suspicious behavior but also provide meaningful explanations that allow users to understand and respond to incidents.

For professional users, the difference between detecting an attack and understanding an attack can have significant economic consequences. Businesses increasingly rely on AI systems to automate operations, generate software, manage information, and support decision-making. When access is interrupted or usage limits are consumed unexpectedly, the result may be lost productivity, interrupted workflows, and additional costs.

De Swardt's account was restored after approximately two weeks. However, the experience, combined with difficulties obtaining fast support and detailed usage information, changed his view of the service.

He ultimately cancelled his Claude subscription and moved to Cursor, citing its ability to provide access to multiple AI models, including lower-cost open-source alternatives.

His decision also reflects a broader competitive dimension in the AI market. As more organizations and independent professionals integrate AI into their operations, the decision to remain with a particular provider is no longer based solely on model quality.

Transparency, security, customer support, pricing flexibility, interoperability, and the ability to move between models are becoming increasingly important parts of the product experience.

De Swardt said that, in his experience, alternative models could perform many of the same tasks as Claude and that he did not see enough differentiation to justify returning unless the underlying security and visibility concerns were properly addressed.

From a strategic perspective, the incident highlights how AI companies are now designing not only models but complete digital ecosystems.

The quality of the AI model remains central to the brand, but the surrounding architecture is becoming equally important. Authentication systems, session management, token monitoring, third-party integrations, usage dashboards, support mechanisms, and security alerts all contribute to the overall identity and perceived reliability of an AI platform.

This represents a significant shift in the design strategy of AI products. Early competition in generative AI focused heavily on model capability, benchmark performance, and the ability to produce increasingly sophisticated responses.

As AI becomes embedded in professional workflows, however, users are beginning to evaluate platforms in the same way they evaluate critical business infrastructure.

They expect clear visibility into resource consumption, rapid incident response, understandable security controls, and systems that can explain what is happening inside their accounts.

The economic implications are equally significant. Premium AI subscriptions can cost hundreds of dollars per month, while enterprise customers may spend substantially more to provide AI access across their organizations.

As token-based pricing and usage limits become more common, the unauthorized consumption of AI resources creates a direct financial exposure. The issue is no longer limited to data theft; attackers may also steal access to computational capacity that has already been purchased by another user.

This creates a new category of digital asset protection. In the AI economy, credentials can provide access not only to information but also to intelligence, automation capacity, computing resources, and expensive model usage.

For AI companies, the challenge will be to design systems capable of protecting these resources while maintaining the frictionless experience that users expect from modern software.

More aggressive authentication and security controls can reduce unauthorized access, but they may also complicate workflows for legitimate users. AI providers therefore face a product-design balancing act between security, usability, automation, and convenience.

The issue also raises questions about the role of third-party services. Modern AI users often connect their accounts to coding environments, automation tools, cloud services, agent frameworks, and other external platforms.

Every additional connection can improve productivity, but it may also expand the number of potential pathways through which credentials or session information could be exposed.

For that reason, the future security architecture of AI services may depend increasingly on detailed access controls, granular authorization systems, transparent session monitoring, and better visibility into how tokens are being consumed.

Users will likely expect dashboards that show not only how much of their allocation has been used but also where, when, and by which application or task that consumption occurred.

The Claude token theft reports demonstrate that the AI industry is entering a more mature stage in which trust infrastructure may become as important as model intelligence.

A powerful AI system can attract users, but long-term retention increasingly depends on whether customers believe their accounts, resources, workflows, and investments are protected.

For brands competing in the AI market, security is therefore becoming part of the product identity itself. A company's reputation will be shaped not only by what its models can do but also by how transparently it handles incidents, how quickly it responds to affected customers, and how effectively it allows users to understand what is happening within their accounts.

As AI continues to move deeper into business operations, token usage will increasingly resemble a metered business resource rather than a simple consumer feature.

The incidents reported by Claude users suggest that protecting that resource will require a new approach combining cybersecurity, product design, customer support, and transparent usage management.

The broader lesson for the AI industry is that intelligence alone is no longer enough. The next stage of competition may be defined by who can build the most trusted ecosystem around that intelligence.

Stolen Claude Tokens Expose a New Security Challenge for the AI Subscription Economy

News You Should See

2026 Nobel Medicine Prize Honors Scientists Behind Optogenetics Breakthrough

Oil Prices Edge Lower as Stronger Middle East Exports and G7 Reserves Ease Supply Concerns

Trump Offers U.S. Assistance to Russia After Death at Siberian Plague Research Institute

Trump Takes Economic Message to Nebraska as GOP Faces Rising Cost-of-Living Pressure

U.S. Appeals Court Weighs Trump Administration’s $2.6 Billion Harvard Funding Fight

U.S. Midterm Elections Begin With Resilient Jobs Market and Persistent Cost Pressures

Latest News

2026 Nobel Medicine Prize Honors Scientists Behind Optogenetics Breakthrough

The 2026 Nobel Prize in Physiology or Medicine honors Karl Deisseroth, Peter Hegemann and Georg Nagel for pioneering research behind optogenetics and its impact on neuroscience.

Oil Prices Edge Lower as Stronger Middle East Exports and G7 Reserves Ease Supply Concerns

Oil prices edged lower as stronger Middle Eastern exports and a planned G7 release of 100 million barrels eased immediate supply concerns, while Gulf security risks and the Strait of Hormuz kept markets alert.

Trump Offers U.S. Assistance to Russia After Death at Siberian Plague Research Institute

President Donald Trump said the United States would help Russia if needed after a laboratory worker died at a Siberian plague research institute, as Russian authorities imposed precautionary quarantine measures.

Trump Takes Economic Message to Nebraska as GOP Faces Rising Cost-of-Living Pressure

Trump’s Nebraska campaign stop highlights rising fuel and grocery costs, beef prices and growing economic pressure on Republicans ahead of the November midterm elections.

U.S. Appeals Court Weighs Trump Administration’s $2.6 Billion Harvard Funding Fight

A U.S. appeals court is reviewing the Trump administration’s effort to cut Harvard’s federal research funding, with more than $2.6 billion at stake.

U.S. Midterm Elections Begin With Resilient Jobs Market and Persistent Cost Pressures

The U.S. enters the 2026 midterm elections with unemployment at 4.2%, while higher living and energy costs create economic pressure for households and businesses.

US Services Growth Cools as Input Costs Reach Four-Year High

US services growth eased in September as input prices climbed to their highest level since July 2022, with fuel costs, supply-chain disruptions and strong demand increasing pressure on businesses.

Rising Treasury Yields Put Washington Under Growing Fiscal Pressure

Rising Treasury yields are increasing U.S. borrowing costs as Washington manages record debt, persistent inflation and strong economic demand, narrowing its policy options.

Dr. Ghada Ali Helps Coordinate EGP 16 Million Partnership for Cairo Bone Marrow Transplant Unit

A EGP 16 million corporate partnership will establish and equip a bone marrow transplant unit at Cairo’s Coptic Hospital, supporting access to specialized treatment for patients.