Unexplained Token Drain: A Security Wake-Up Call for Claude Users
In early August, Grant De Swardt, an AI consultant based in East Sussex, stumbled upon a troubling anomaly within his Claude Max 20x account. Despite remaining idle on August 4, De Swardt observed his token usage metrics steadily climbing, a clear indicator that his account resources were being siphoned off without his authorization.
The Mystery of Phantom Consumption
Determined to identify the source of the drain, De Swardt conducted a rigorous self-audit the following day. He systematically disconnected all integrations, halted active projects, and ensured no local Claude Code tasks were running. Even with his digital workspace completely dormant, the token consumption continued to surge. As he noted in an interview, his usage jumped by 10%-from 45% to 55%-during a period of total inactivity, confirming that the issue was not tied to his own workflows.
This phenomenon highlights a growing vulnerability in the AI-as-a-service landscape. Much like a compromised API key in a software development environment, unauthorized access to AI tokens can lead to significant financial and operational losses. Recent industry reports suggest that as AI agents become more integrated into business infrastructure, they are increasingly becoming targets for malicious actors looking to hijack computational power for unauthorized data processing or automated scraping.
Anthropic’s Response and Operational Fallout
When De Swardt reached out to Anthropic for an itemized breakdown of his usage, the company was unable to provide specific logs. However, they acknowledged the irregularity. In a move to mitigate further risk, Anthropic suspended his subscription, invalidated all active server-side tokens, and processed a partial refund of £44.49 for the unused portion of his $200 monthly plan.
For De Swardt, the impact was immediate and severe. His consultancy specializes in deploying AI agents for small and medium-sized enterprises-automating critical back-office functions such as extracting purchase order data from incoming emails and syncing it directly into accounting platforms. The sudden loss of access effectively paralyzed his ability to maintain these essential client services, illustrating how fragile business operations can become when they rely on centralized AI platforms without robust security oversight.
