Some paying subscribers using Anthropic’s Claude service report that their quotas are rapidly being depleted because of activity they did not carry out. Independent AI consultant Grant De Swardt, based in East Sussex, saw token usage increase on August 4 even though he was not working under his $200-per-month Claude Max 20x subscription. Consumption continued despite his shutting down connected systems the following day. According to Anthropic’s investigation, a compromised Claude session key was used to create unauthorized Claude Code OAuth tokens. Swardt said usage rose from 45% to 55% during the period he observed, while scheduled tasks had been stopped and Dispatch and cloud execution had been disabled.
Anthropic did not provide a list in response to a request for a detailed usage breakdown, but acknowledged the unusual activity. It temporarily suspended the paid account and invalidated the sessions and server-side Claude Code tokens; it issued a partial refund of £44.49 for the remaining period. The AI agents Swardt had developed for SMEs were affected by the suspension of daily administrative tasks, web design and software development processes. The company said the account may have been used by an apparently unauthorized third party; it could not determine how access had been obtained. The absence of detailed transaction logs is making it difficult to identify the source of the quota consumption.
Why it matters
The incident shows that subscription quotas in AI services are linked not only to the user’s own activity but also to account security. This has direct implications for service continuity and cost control at SMEs that use AI agents connected to Claude for daily administrative tasks, web design and software development. Although Anthropic’s invalidation of the sessions and server-side tokens was a step aimed at limiting the damage, the inability to determine how access was obtained leaves the nature of the security breach unclear. The lack of detailed transaction logs also makes it difficult for users to independently audit which operations generated the quota consumption; therefore, access to logs and accountability mechanisms remain open questions in similar cases.
Background
Claude is not a new name in the FikirPilot archive: we have published 5 reports mentioning the name in the last 90 days; the latest was dated September 1, 2026.