Editorial illustration for Anthropic: Hackers Stole Claude Tokens Via Compromised Session Key
Hackers Stole Claude API Tokens Via Session Key
Grant de Swardt's token usage on Claude kept climbing on August 4 even though he wasn't touching the account. The East Sussex AI consultant runs a one-man operation building agents for small businesses, tasks like pulling purchase-order data out of emails and into accounting software, and he wasn't running any of it that day. So he shut everything down.
Cowork tasks paused, Dispatch and cloud execution disabled, no local Claude Code session active. The usage numbers kept moving anyway.
De Swardt asked Anthropic for an itemized breakdown of what was burning through his $200-a-month Max 20x plan. The company couldn't produce one, but it didn't dismiss him either. Anthropic suspended his account, killed every active session and server-side token tied to it, and sent him a partial refund of £44.49. For a sole proprietor who told TechCrunch his entire business runs on AI agents, from daily admin to coding to website work, losing account access for even a short stretch wasn't a minor inconvenience.
Anthropic later came back with an explanation for what had drained his tokens without his knowledge.
After investigating, Anthropic told de Swardt it found the culprit: A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens.
Why this matters
A stolen session key minting unauthorized OAuth tokens means someone found a way to impersonate a paying user well enough that Anthropic's own systems couldn't tell the difference until de Swardt flagged the anomaly himself. That's the part worth sitting with. He caught this because he tracks his token usage closely enough to notice a 10-point jump on a day he did no work.
Most subscribers don't watch their dashboards that carefully, and Anthropic's explanation, an "unauthorized-looking third-party service" handling "activity for other people," raises more questions than it answers. Whose activity? How many accounts?
For developers building on Claude Code, and founders paying for Max-tier plans, this is a reminder that OAuth tokens tied to session keys are only as secure as the weakest link in that chain, and right now Anthropic hasn't said where that link broke. Until there's a fuller account of scope and root cause, treat unexplained usage spikes as a signal worth escalating, not an error to shrug off.
Common Questions Answered
How did hackers gain access to Grant de Swardt's Claude tokens?
According to Anthropic's investigation, hackers obtained a compromised Claude session key that was then used to mint unauthorized Claude Code OAuth tokens. This allowed the attackers to impersonate de Swardt's account well enough that Anthropic's systems initially could not detect the fraudulent activity.
What warning signs alerted Grant de Swardt to the unauthorized token usage?
De Swardt noticed his token usage on Claude kept climbing on August 4 despite having shut down all his operations, including paused cowork tasks, disabled Dispatch and cloud execution, and no active local Claude Code sessions. The suspicious 10-point token jump on a day he performed no work prompted him to investigate and ultimately report the issue to Anthropic.
Why is the unauthorized minting of OAuth tokens a significant security concern?
The ability to mint unauthorized OAuth tokens using a compromised session key means attackers could impersonate legitimate paying users so convincingly that Anthropic's own security systems failed to detect the anomaly automatically. Most subscribers do not monitor their token usage dashboards closely enough to catch such breaches, leaving them vulnerable to undetected unauthorized access and charges.
What type of work was Grant de Swardt performing with Claude before the security breach?
De Swardt, an East Sussex AI consultant running a one-man operation, was building AI agents for small businesses to perform tasks such as extracting purchase-order data from emails and importing it into accounting software. He had various automated systems running through Claude's Dispatch and cloud execution features to serve his clients.
Further Reading
- Anthropic: Attackers Using Infostealers to Hijack Claude Sessions - Security Boulevard
- Anthropic cracks down on hijacked user accounts mining AI tokens - The Register
- Anthropic warns infostealer malware is draining Claude sessions - AI Weekly
- Anthropic warns infostealer malware is draining Claude sessions - AI Weekly
- Anthropic Claude Infostealer Attacks Expose Token - CyPro