The trouble began on August 4, when de Swardt noticed his token usage climbing despite zero activity. After disabling all integrated tasks and cloud execution, the consumption continued to rise. Anthropic eventually confirmed his session key had been compromised, allowing a third party to mint unauthorized OAuth tokens. The company suggested the breach stemmed from external infostealer malware, which targets saved browser sessions to bypass standard login security.
De Swardt is not an isolated case. A surge of similar reports has emerged on Reddit and GitHub, with users describing sudden account upgrades and rapid depletion of daily limits. While Anthropic has proactively identified some breaches by invalidating sessions and issuing refunds, the support process remains opaque. The company currently lacks granular, itemized usage logs, making it nearly impossible for subscribers to verify exactly which prompts or processes are consuming their quotas.

Comments (0)
No comments yet. Be the first!