Hackers are stealing Claude tokens from subscribers
2:10 PM PDT · September 8, 2026
On August 4, Grant De Swardt, an independent AI consultant in East Sussex, U.K., noticed something strange going on with his Claude Max 20x account. He hadn’t been working that day, yet his token usage was climbing.
The next day, he disabled everything he had attached to Claude and did not work with it. Token consumption again increased. “In the clearest controlled interval, it increased from 45% to 55% while I performed no work, scheduled Cowork tasks were paused or completed, Dispatch/cloud execution was disabled, and there was no corresponding active local Claude Code task,” De Swardt told TechCrunch.
What was eating up his token allowance? He had no idea, so he contacted Anthropic and asked for an itemized list. Anthropic didn’t provide one, but it agreed something was off. It suspended his paid account, invalidated all of his sessions and server-side Claude Code tokens, and issued him a partial refund of £44.49 for the remaining time on his $200-per-month subscription.
The suspension wreaked havok on his business, he told TechCrunch. His job is to help small and mid-size businesses set up agents — a sort of forward-deployed engineer for hire — for tasks like automatically loading purchase-order data from emails into the accounting software.
As a sole proprietor, he relies on agents throughout his whole business, too: daily admin tasks, website design, coding. “Like everything is just running through AI these days,” he said.
After investigating, Anthropic told De Swardt it found the culprit: A compromised Claude session key was used to mint unauthorized Claude Code OAuth tokens. The company told him the account “appeared to have been used by an unauthorized-looking third-party service to handle activity for other people, but they could not determine how it obtained access,” he told TechCrunch. “They say the evidence is consistent either with credentials/session data being taken without my knowledge, or with the account having been connected to an outside service.”
In other words, a hacker was able to obtain access to De Swardt’s account and was covertly siphoning off his tokens. Because account support tracks total usage but not itemized usage, even upon request, this kind of theft could have gone on for months undetected.
He posted his experience on Reddit and after 80 comments, he discovered he was not alone. One person claimed that their account “was auto-upgraded without my consent, my credit card got charged, and the usage shot from 0% to 100% automatically without me even touching it.” Another saw usage go from 0 to 49% in 12 minutes, when all they had used it for was a couple of prompts and a web search.
One Claude user said their account burned through its max tokens every day for three days without them using it at all; this person then created a GitHub report about it. Like with the Reddit post, other users shared similar experiences there, too.
Two of them posted emails from Anthropic where the company had — to its credit — identified and warned them that their tokens were being stolen.
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage,” the email read. Infostealers are a type of malware that installs itself on a user’s computer and steals saved passwords, session data, and login credentials.
When Anthropic saw suspicious activity, it signed the users out, invalidated existing authorizations, issued some refunds, and warned them that they may have malware.
The company also said the malware didn’t come from using Claude itself. Such malware can be picked up from many sources online, from downloading infected software to clicking on infected ads.
Anthropic did not send De Swardt one of those emails. He insists he found no evidence that his computer was compromised and says he still has no way of determining how hackers gained access.
De Swardt’s Claude account was reinstated after about two weeks. But the difficulty of getting speedy help for the matter, plus the lack of an itemized usage, soured him on Claude. He cancelled his subscription in favor of Cursor and its ability to use multiple models, including more affordable open source options.
In his experience, these other models work as well as Claude. “It’s not that much different or better,” he said, adding that he can’t see going back “without [Anthropic] actually having resolved the issue in any way.”
He says Anthropic still lacks tools that allow users to see what’s consuming their tokens. “I don’t think there’s any way that these people can protect themselves.”
When asked for information on how users can identify misuse, Anthropic declined to comment.
OpenAI fought dirty on career-making math problem, says NYU mathematician
10:32 AM PDT · September 8, 2026
NYU mathematics professor Tristan Buckmaster announced three proofs on Tuesday with a preliminary finding on one of the major unsolved problems in theoretical mathematics. The findings, made in collaboration with Anthropic mathematician Levent Alpöge and using both Codex and Claude AI models, are significant in themselves — but they’re also accompanied by an unusual controversy surrounding OpenAI’s attempts to solve the same problem.
“There is another part of this story,” Buckmaster wrote in his statement announcing the proofs, “and one that, honestly, I very much wish I did not have to be concerned with.” According to the statement, a parallel effort by OpenAI built on their work before it became public, leading to a tangle of academic rivalries and conflicting claims.
Shortly after the Buckmaster’s statement, OpenAI published a full proof of the Navier–Stokes existence and smoothness problem, which Buckmaster’s findings had taken steps towards. According to OpenAI, the proof was discovered by an unreleased next-generation model, which has tackled a range of different unsolved problems over the past week. All told, the week-long effort consumed 300 billion output tokens — $22.5 million worth of compute, if charged at current Astra rates.
The Navier-Stokes existence and smoothness problem is one of the seven Millennium Prize problems — a set of major unsolved math problems, each carrying a $1 million bounty from Clay Mathematics Institute for the first person or group to provide a solution. The Navier-Stokes equations are widely used in fluid mechanics but poorly understood in theoretical terms. A solution would represent a significant advance in the collective understanding of mathematical physics.
While Buckmaster and Alpöge were finalizing their own results, they learned that “information about our progress had been passed to OpenAI.” When they contacted OpenAI, they were told that OpenAI had already achieved a full proof of the central problem. But when they asked follow-up questions about when OpenAI had begun its research into the problem and how much human input was involved, the answers became more evasive.
“It emerged that an entire team had been working on the problem,” Buckmaster said, “and that an insane amount of compute had been used…. Eventually, it was agreed that [the first prompt] had been sent in the past few days, after information about our work had reached OpenAI.”
If true, that would suggest the OpenAI team had become convinced that Buckmaster and Alpöge’s approach was the right one, and decided to use its material advantage in computing resources to reach a formal proof first.
OpenAI’s post confirms much of this timeline, specifically saying that the latest effort began on September 1, inspired by rumors that two Millennium Prize problem had been solved. Additionally, the post confirms the ongoing conversations with Buckmaster and Alpöge.
Although the problem is widely pursued among mathematicians, the specific tactic taken by Buckmaster and his collaborator is far less common. As a result, Buckmaster found it suspicious that OpenAI ended up taking the same approach at the same time.
“The route to the Clay problem through a smooth force, options c and d in Fefferman’s statement of the problem, is the route Luis and Diego opened and the one Levent and I had quietly chosen to attack,” Buckmaster wrote. “Almost nobody else I know of was working on it,” he continued. “It is not the direction one arrives at in a few days by giving a model the problem statement.”
While Alpöge is employed by Anthropic, he was not conducting this research on the company’s behalf. As a result, the duo used a mix of models, relying primarily on OpenAI’s Codex in their work. Even so, Alpöge’s affiliation with a rival lab seems to have been a sore point for OpenAI, and Buckmaster alleges that Bubeck asked him to remove Alpöge’s credit as part of a proposed compromise.
When Buckmaster pushed to make the dispute public, he says that Bubeck replied: “Why would you ruin your career?” Buckmaster says that when he pushed back, Bubeck followed up with: “If you don’t want me to be nice, then I don’t have to be nice.”
Buckmaster also raised concerns that, because he used Codex extensively in assembling the project, information from his work could have informed OpenAI’s own efforts to solve the problem. OpenAI reserves the right to train models on Codex interactions, although users are able to opt-out. If the OpenAI team used a model trained on Buckmaster’s own Codex interactions, it’s plausible that it could have regurgitated his work when faced with a similar problem.
In its own post, OpenAI downplayed the possibility that regurgitation could have been involved. “We (the researchers and the agents) did not see any of their work through any means until they released it publicly — in particular, no specific user data was accessed in order to solve this problem,” the post reads. “While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models. However, our proofs differ significantly and even the precise results proved are different in the Euler case (forced vs unforced).”
Regardless, the issue is likely to reignite the ongoing debate about AI’s role in mathematical research, and OpenAI’s specific incentives. For his part, Buckmaster seems to believe the best answer is to get as much information about the research out into the public eye.
Update 2:35p.m. ET: Incorporated details from OpenAI’s release of the Navier-Stokes result.




