Stolen Session Keys Drain Anthropic Subscribers’ Tokens

Grant De Swardt noticed the problem the way most users do: the numbers did not add up. The independent AI consultant in East Sussex, England, was not using his Claude Max 20x account on the day he opened his dashboard, yet his token usage kept climbing. He had been idle. The meter was not.

The next day he disconnected every integration tied to his Claude account and stopped using the service entirely. Token consumption kept rising anyway. It was only after he pressed Anthropic that the company told him what had happened. Leaked Claude session keys had been used to mint unauthorized Claude Code OAuth tokens. In plain terms, someone had taken over his account access and was quietly spending his tokens.

De Swardt took the story to Reddit, where his post drew about 80 comments. It did not take long to learn he was not alone. Other users said their balances had drained the same way, and at least two posted emails from Anthropic in which the company itself flagged unusual token activity and warned them their accounts were being drained. The theft, in other words, was known to the platform even as users discovered it on their own.

The Reddit thread De Swardt started has become a small gathering point for people comparing notes. Several described the same signature: idle accounts, rising token counts, and support replies that confirmed abuse only after repeated requests. The pattern suggests the thefts were not a single isolated credential leak but a recurring method, though Anthropic has not confirmed how many accounts were affected or when the leak began.

The mechanics of the abuse are straightforward but hard for a subscriber to spot. A session key that leaks lets an attacker create their own OAuth token with the victim’s credentials. The attacker then uses Claude Code, Anthropic’s coding agent, on the victim’s meter. Support staff at Anthropic can see total usage, according to De Swardt’s account, but not an itemized breakdown of where the tokens went. A theft can sit unnoticed for months.

That visibility gap is what has frustrated users. Subscription plans cap usage by token volume, and a drained account means a customer who cannot work until the next billing cycle. Anthropic’s support, in the cases described, could confirm the abuse had happened but not who had done it or what work they had run. For developers who bill clients by the hour, the interruption is the cost on top of the stolen tokens.

When asked how users should detect that their accounts are being misused, Anthropic declined to comment. The company’s silence on that question, after acknowledging the root cause to individual customers, has done little to reassure a developer community that has embraced Claude Code as a daily tool. Security researchers have long warned that API keys and session tokens are the softest part of the AI software supply chain, and this incident offers a concrete case study.

Security researchers have spent years warning that API keys and session tokens are the weakest point in the AI software supply chain. Keys get pasted into configuration files, committed to public repositories, and shared in chat messages. Once one leaks, automated tools can test it within minutes. Anthropic’s acknowledgment that session keys were the vector fits a well-known pattern, even if the specific breach has not been publicly detailed.

The episode points to a broader friction in how AI subscriptions work. These are not static accounts that hold a document or two. They are metered compute services, and a stolen credential is indistinguishable from a busy customer for as long as the bills stay within plan limits. That makes abuse slow to surface and easy to miss.

Claude Code arrived early last year as Anthropic’s answer to coding agents such as Cursor and GitHub Copilot, and it caught on quickly among developers who run it from the command line and pay for tokens as they go. Its pricing is metered, which is precisely what makes a stolen credential so damaging: the attacker’s usage looks identical to the customer’s own, and the bill lands on the customer’s subscription limit.

For Anthropic, the stakes are commercial as well as technical. The company is in the middle of preparing for an initial public offering, and trust in its platform is part of the story it tells enterprise buyers. An attack that drains paying customers while support can only offer a shrug is the kind of small incident that accumulates into a reputation problem, one support ticket at a time.

De Swardt’s post has already outlived its original purpose. What began as one user’s confusion has become a public record of a vulnerability that Anthropic has not fully explained, measured in tokens that keep disappearing from accounts whose owners are not using them.

For subscribers, the immediate lesson is narrow and dull: rotate credentials, avoid long-lived session keys, and watch the usage meter even on days when no work is being done. The burden should not rest entirely on users, and Anthropic’s refusal to explain how customers can catch abuse suggests the platform has not built the tools to make that easy. Until it does, the dashboard will keep telling some customers a story they have to figure out on their own.

Related Posts

  • October 1, 2026
  • 16 views
A Bad Prompt Exposes 95,000 Customer Emails at Bee Cheng Hiang

Bee Cheng Hiang, the Singapore company that has sold bak kwa, or barbecued pork jerky, for close to a century, decided in April to try something new. An employee asked…

  • October 1, 2026
  • 17 views
Google’s New Gemini Model Opens to Cyber Defenders First

Google introduced a new flagship artificial-intelligence model on Tuesday, but most people cannot use it yet. Gemini 4 Argon, the company’s first new frontier model since Gemini 3 last November,…