Claude Tokens: When Security Becomes a Game of Cat and Mouse
Imagine waking up one day to find that your AI resources are being drained without you even touching the computer. This is exactly what happened to Grant De Swardt, an AI consultant in the UK. He noticed that his account on Claude Max 20x was consuming tokens as if there were no tomorrow, even when he wasn't working. Something was clearly wrong.
De Swardt did what anyone would do: he shut everything down, paused tasks, and still saw token consumption rise. He contacted Anthropic, the company behind Claude, asking for a breakdown of usage. The response? No list, but an acknowledgment that something was strange. The result: account suspended, sessions invalidated, and a partial refund. However, this messed up his entire business, which relies on AI agents for day-to-day tasks.
The Mystery of Stolen Tokens
After an investigation, Anthropic discovered that De Swardt's Claude session key had been compromised. Someone was using his tokens for unauthorized activities. The company could not determine how this happened, but the scenario was clear: a hacker had access to De Swardt's account and was draining his resources.
The problem is that, without a detailed usage report, this type of theft can go unnoticed for months. De Swardt shared his experience on Reddit and found he was not alone. Other users reported similar situations, with accounts being automatically updated and unauthorized charges.
Anthropic, upon noticing suspicious activities, took measures such as logging out users and invalidating authorizations. But the question remains: how to protect users from infostealers, malware that steals login data and passwords? The company claims that the malware does not come from using Claude but can be acquired from various online sources.
The Search for Solutions and Alternatives
De Swardt had his account reactivated after two weeks, but the experience left him disillusioned. He canceled his Claude subscription and opted for other solutions, such as Cursor, which offers more accessible and open models. For him, these alternatives work just as well as Claude, without the risk of unpleasant surprises.
The detail is that Anthropic still does not offer tools for users to see what is consuming their tokens. Without this transparency, it is difficult to protect against abuse. When asked how users can identify misuse, Anthropic preferred not to comment.
De Swardt's story is a warning for everyone who relies on AI: the security of your resources is just as important as the technology itself. And while companies do not provide clear solutions, the cat-and-mouse game between hackers and users continues.





Comments (0)
Comments are moderated and if they violate our Terms and Conditions of use, the comment will be deleted. Persistence in violation will result in a ban of your account.