Agents AI

News
ai

Anthropic Warns Infostealer Malware Is Hijacking Claude Sessions to Drain Usage

Anthropic is signing out affected Claude accounts, removing saved payment methods and refunding unauthorized charges after infostealer malware on users' own PCs was found stealing active Claude login sessions.

AgentsAI NewsroomAugust 31, 20263 min read

Anthropic has begun notifying some Claude users that infostealer malware running on their own computers stole active, already-authenticated Claude login sessions, letting attackers access those accounts and burn through the victims' usage without needing a password or two-factor code. The company said it is signing affected users out of Claude everywhere, removing any saved payment methods, and refunding charges it identifies as unauthorized.

How the attack works

Anthropic said it "recently became aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage." Infostealers such as Vidar, LummaC2, StealC, RedLine and Acreed — all of which target Windows systems — along with Atomic Stealer (AMOS) on a smaller number of Mac systems, are designed to scrape browsers for stored passwords, cookies and other locally saved credentials. Because a stolen session cookie is already authenticated, an attacker who copies it can act as the logged-in user without ever seeing a password or being challenged for 2FA. Anthropic said the clearest sign of compromise is a usage limit that appears to refill and then drain on its own while the account owner isn't using Claude.

What Anthropic is doing, and what it isn't

The company's remediation is limited to account-level containment: forcing a global sign-out to invalidate the stolen session, stripping stored payment methods so a hijacked account can't be used to run up charges, and refunding usage it determines was unauthorized. Anthropic was explicit that the malware itself has nothing to do with Claude — it said it has "no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude." The infections originate from unrelated malicious downloads or apps on victims' devices, with Claude simply one of the accounts the stolen browser data happened to unlock.

Why it matters

The incident is a reminder that as AI accounts increasingly carry paid usage credits, saved billing details and, for developer-facing tools, API access, they have become as attractive a target for commodity infostealers as banking and email logins already are. It also illustrates a security gap generic to session-based web authentication rather than one specific to Anthropic: any service relying on long-lived browser sessions is exposed to the same class of attack once a user's device is compromised, making device-level hygiene — not just account passwords — part of protecting AI-tool access going forward.

AI-assisted reporting, overseen by the AgentsAI team. Spotted an error? Let us know.