-+ 0.00%
-+ 0.00%
-+ 0.00%

Recently, Grant De Swardt, an independent AI consultant in East Sussex, England, discovered an issue with his Claude Max 20x account. He didn't use the service that day, but his token usage continued to rise. The next day, he disconnected all the connections bound to Claude and did not operate Claude the whole time. However, token consumption continues to rise. After investigation, Anthropic told De Swardt that they had found the root of the problem: the leaked Claude session key was used to generate an unauthorized Claude Code OAuth token. Simply put, the hacker gained access to De Swardt's account and secretly consumed his tokens. The platform's customer service can only track total usage and cannot view item details. Even if users voluntarily apply, such theft incidents may remain hidden for months without being discovered. After his Reddit post garnered 80 comments, he discovered that he wasn't the only one who had experienced this incident. Two of the users posted emails from Anthropic. It is worth mentioning that the platform actively identifies risks and reminds them that tokens are being stolen. When asked how users can identify account abuse, Anthropic declined to comment.

Zhitongcaijing·09/09/2026 07:33:18
Listen to the news
Recently, Grant De Swardt, an independent AI consultant in East Sussex, England, discovered an issue with his Claude Max 20x account. He didn't use the service that day, but his token usage continued to rise. The next day, he disconnected all the connections bound to Claude and did not operate Claude the whole time. However, token consumption continues to rise. After investigation, Anthropic told De Swardt that they had found the root of the problem: the leaked Claude session key was used to generate an unauthorized Claude Code OAuth token. Simply put, the hacker gained access to De Swardt's account and secretly consumed his tokens. The platform's customer service can only track total usage and cannot view item details. Even if users voluntarily apply, such theft incidents may remain hidden for months without being discovered. After his Reddit post garnered 80 comments, he discovered that he wasn't the only one who had experienced this incident. Two of the users posted emails from Anthropic. It is worth mentioning that the platform actively identifies risks and reminds them that tokens are being stolen. When asked how users can identify account abuse, Anthropic declined to comment.