Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage
Anthropic is signing out affected Claude accounts, removing saved payment methods and refunding unauthorized charges after infostealer malware on users' own PCs was found stealing active Claude login sessions.
Anthropic has begun notifying some Claude users that infostealer malware running on their own computers stole active, already-authenticated Claude login sessions, letting attackers access those accounts and burn through the victims' usage without needing a password or two-factor code. The company said it is signing affected users out of Claude everywhere, removing any saved payment methods, and refunding charges it identifies as unauthorized.
How the attack works
Anthropic said it "recently became aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Infostealers such as Vidar, LummaC2, StealC, RedLine and Acreed — all of which target Windows systems — along with Atomic Stealer (AMOS) on a smaller number of Mac systems, are designed to scrape browsers for stored passwords, cookies and other locally saved credentials. Because a stolen session cookie is already authenticated, an attacker who copies it can act as the logged-in user without ever seeing a password or being challenged for 2FA. Anthropic said the clearest sign of compromise is a usage limit that appears to refill and then drain on its own while the account owner isn't using Claude.
What Anthropic is doing, and what it isn't
The company's remediation is limited to account-level containment: forcing a global sign-out to invalidate the stolen session, stripping stored payment methods so a hijacked account can't be used to run up charges, and refunding usage it determines was unauthorized. Anthropic was explicit that the malware itself has nothing to do with Claude — it said it has "no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude." The infections originate from unrelated malicious downloads or apps on victims' devices, with Claude simply one of the accounts the stolen browser data happened to unlock.
Why it matters
The incident is a reminder that as AI accounts increasingly carry paid usage credits, saved billing details and, for developer-facing tools, API access, they have become as attractive a target for commodity infostealers as banking and email logins already are. It also illustrates a security gap generic to session-based web authentication rather than one specific to Anthropic: any service relying on long-lived browser sessions is exposed to the same class of attack once a user's device is compromised, making device-level hygiene — not just account passwords — part of protecting AI-tool access going forward.
Sources
AI-assisted reporting, overseen by the AgentsAI team. Spotted an error? Let us know.
Related agents
More ai news
TCS Unit HyperVault to Invest Up to $7.4B in 1GW AI Data Center Campus in India
Tata Consultancy Services' infrastructure arm HyperVault will invest up to $7.4 billion with partners to build a 1-gigawatt AI data center campus in Hyderabad, one of India's largest bets yet on domestic AI compute capacity.
Mistral Raises €3B in Samsung-Led Round, Becomes Europe's Best-Funded AI Startup
French AI lab Mistral raised €3 billion in a Series D round led by Samsung Electronics, pushing its post-money valuation above €21 billion and marking the largest equity round ever completed by a European technology company.
Sanders and Casar Introduce Bill to Ban 'Artificial Superintelligence' Outright
Sen. Bernie Sanders and Rep. Greg Casar introduced the Ban Artificial Superintelligence Act on September 3, which would permanently prohibit superintelligent AI systems, pause frontier development pending federal safety rules, and impose prison terms and a 'corporate death penalty' for violations.
Anthropic Says Claude Produced the First Machine-Checked Proof of Fermat's Last Theorem
Working largely autonomously for 11 days on the open Prove2Me platform, Claude generated a 13-million-line Lean formalization of Fermat's Last Theorem, which mathematician Kevin Buzzard called an 'extraordinary autoformalization achievement.'