
Anthropic moved fast. The AI company began signing affected Claude subscribers out of their accounts last week. It yanked saved payment methods too. All to slam the door on attackers who had quietly stolen active login sessions.
The root cause traces back to ordinary infostealer malware. Nothing bespoke for Claude. The same families that have vacuumed credentials for years. Vidar. LummaC2. StealC. RedLine. Acreed on Windows systems. Atomic Stealer, also known as AMOS, on a handful of Macs. These tools don't target Claude directly.
They arrive through the usual vectors. Cracked games. Unofficial downloads. Dodgy apps. Once inside, they copy saved passwords, browser cookies, and local app credentials. The Claude session cookie becomes just one more prize in the haul. Attackers then replay that authenticated session. No password needed. No 2FA prompt. The system sees a legitimate logged-in user.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic explained in emails sent to impacted customers. The message, first shared on Reddit by user WorriedAssociate7029, was reported in detail by The Register.
Users noticed odd behavior first. Usage limits that refilled. Then drained rapidly. Even when they weren't prompting Claude at all. That pattern tipped off Anthropic's monitoring systems. The company responded by invalidating the stolen sessions. Removing stored cards. And issuing refunds for unauthorized charges.
But here's the catch. Signing out stops the immediate abuse. It does not clean the infected machine. "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," the email warned. Victims must scan and remove the infostealer first. Only afterward should they reset passwords, enable two-factor authentication on their email, and review other sessions.
Security researchers saw the same pattern play out across the industry. Help Net Security detailed how the malware copies the session cookie. Attackers replay it. The platform treats them as already authenticated. This bypasses every login hurdle.
The incident highlights a broader shift. AI computing power now carries real street value. Tokens aren't abstract. They're expensive resources that bad actors can consume at someone else's expense. Or bundle and resell. One Chinese-language report described attackers wrapping hundreds of stolen sessions into backend proxies. Then offering "unlimited chatting" for pennies to end users. All while the original account holders footed the bill. That coverage appeared on 36Kr.
Anthropic stressed the malware had no connection to its platform. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the email stated. "Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them."
One victim told The Register he got fooled by a cracked game. Classic entry point. He later used Claude itself to help analyze the malware on his system. After the company's alert, he changed passwords again and revoked all active sessions. The experience left him more appreciative of Anthropic's proactive steps than past refund disputes on Reddit.
This isn't the first time Claude has drawn large-scale abuse. Earlier this summer Anthropic accused operators linked to Alibaba of running the biggest known campaign to extract its model's capabilities. That operation allegedly used nearly 25,000 fraudulent accounts to generate more than 28.8 million exchanges. The company shared evidence with U.S. senators and called for punishment. Ars Technica broke down the letter and its claims.
Yet the latest wave feels different. It relies on commodity tools already loose in the wild. No need to create fake accounts or build custom infrastructure. Just harvest sessions from thousands of ordinary users who clicked the wrong link or downloaded the wrong file. The barrier to entry dropped. The incentive rose.
Security firm Huntress identified a related campaign called FakeAgent. Attackers hosted malicious pages that posed as Claude-related tools. At least 29 organizations fell victim in two days. Roughly 7,100 downloads occurred before Anthropic took the page down. Some payloads led to SectopRAT. Others dropped poisoned SKILL.md files that could persist through Claude's own agent features. Those findings appeared in reporting by CyberSecurity News.
The speed of Anthropic's response stands out. Account lockouts. Card removal. Refunds processed. Notifications sent. All within days of detecting the pattern. But the company also signaled it may act again if similar misuse appears. Users could face another forced logout.
For enterprise teams that rely on Claude for code generation, research, or agentic workflows, the implications sting. A single compromised developer laptop can drain shared subscription credits or rack up surprise bills. Teams that treat AI usage limits as mere convenience now face them as a security boundary.
Recommendations from Anthropic and the reporting outlets converge. Treat the machine first. Remove the malware completely. Then harden the accounts. Strong unique passwords. Proper 2FA. Session hygiene. Avoid unofficial software. The advice feels basic. Its repeated necessity reveals how often it gets ignored.
So the cycle continues. Malware authors update their stealers. Users download tempting cracks. AI companies detect the drain and cut the sessions. Each round exposes the same truth. The value of compute has moved from theoretical to transactional. And thieves noticed first.
Additional coverage today from SecurityWeek and Notebookcheck confirmed the same email language and remediation steps. No new families of malware. No evidence of a Claude-specific exploit. Just opportunistic reuse of tools that have plagued browsers and password managers for years.
Anthropic's move buys time. It doesn't solve the underlying problem of session theft. Browser vendors, password managers, and endpoint security products all carry pieces of the defense. Until those layers tighten, AI platforms will keep playing whack-a-mole with stolen cookies. The tokens keep burning. The bills keep arriving. And users keep learning the hard way.