Anthropic is warning some Claude users that infostealer malware already present on their computers stole active Claude login sessions, letting attackers log into accounts and burn through usage limits, according to an email Anthropic sent to affected users and shared on Reddit. The company said it is signing out affected accounts, removing saved payment methods, and refunding charges it identifies as unauthorized.
The incident illustrates how session-cookie theft, not password compromise, is increasingly the entry point attackers use against cloud and AI accounts, since a stolen authenticated browser session can skip login and two-factor checks entirely.
Key takeaways
- Anthropic says infostealer malware on victims' PCs and Macs stole active Claude login sessions.
- A stolen session lets an attacker bypass normal password and 2FA login because the browser session is already authenticated.
- Anthropic identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer (AMOS) on a small number of Macs.
- Anthropic is signing out affected users, removing saved payment methods, and refunding unauthorized charges.
- Anthropic stresses the malware is unrelated to Claude and typically arrives through unrelated downloads, such as pirated software.
Affected
What did Anthropic tell affected Claude users?
Anthropic Claude infostealer session hijacking is the pattern Anthropic described in an email sent to compromised account holders: a bad actor used common infostealer malware to steal Claude login sessions from people's computers, then used those sessions to access accounts and consume usage. Anthropic told users that if their usage limits appeared to refill and then drain while they were not using Claude, this was the likely cause.
The company said its investigation is ongoing but that affected computers were likely already infected with general-purpose infostealer malware unrelated to Claude. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," Anthropic wrote, according to the email shared on Reddit and reported by BleepingComputer.
Why session theft bypasses passwords and 2FA
Infostealer malware harvests data stored locally on an infected machine, including browser passwords, login cookies, and credentials for other applications. Because a Claude session is stored as an already-authenticated browser session, a stolen copy of it lets an attacker skip the normal password and two-factor login flow altogether. Anthropic said the malware likely collected the victim's Claude session as one of many items during the initial infection, and that a threat actor later began picking Claude sessions specifically out of that stolen data to use them.
In the case shared publicly, the affected Redditor confirmed downloading a pirated game shortly before the compromise, a common infection vector for infostealers that has nothing to do with Claude's own security.
Which malware families is Anthropic linking to the attacks?
- Vidar
- LummaC2
- StealC
- RedLine
- Acreed (Windows)
- Atomic Stealer / AMOS, identified on a small number of Macs
Anthropic said it has identified these malware families among the infections tied to the session theft. All are established, general-purpose credential and cookie stealers already tracked across the broader threat landscape, not tools built to target Claude specifically.
How is Anthropic responding?
Anthropic said it is signing affected users out of Claude, which revokes the stolen sessions, removing saved payment methods to block unauthorized purchases, and refunding charges it identifies as unauthorized. The company was explicit about the limits of this response: "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," it warned, adding that if the malware remains on a victim's computer, the next login session could be stolen the same way.
What should affected users do now?
- Remove the infostealer malware from the affected PC or Mac using a reputable security scan before logging back into Claude.
- Change Claude account credentials and any other passwords stored in the same browser.
- Revoke other active sessions across Claude and other services that shared the infected browser.
- Avoid installing pirated software or unverified apps, a common infection route Anthropic cited in the case it addressed.
Why this matters beyond Claude
The incident is a reminder that AI subscription accounts carry real monetary value attackers can quietly siphon through usage-based billing, not just data theft. Because infostealers operate independently of the service they eventually target, IT teams should treat any AI or SaaS account tied to a compromised endpoint as at risk, regardless of whether that endpoint ever ran the vendor's own software. Session-cookie theft has become a preferred technique precisely because it sidesteps password resets and MFA enforcement that organizations rely on as their primary defense.
Timeline
Impact & actions
Infostealer-hijacked Claude sessions let attackers consume victims' usage allotments and rack up charges without ever triggering a password or 2FA prompt.
Security: The underlying infostealer infections predate and are unrelated to Claude, meaning session theft is a symptom of broader endpoint compromise via malware like Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer.
Privacy: Infostealers that harvested Claude sessions typically also collect saved browser passwords and other app credentials from the same infected machine.
Recommended actions · Medium urgency
- 1Run a full malware scan and remove any infostealer found before logging back into Claude
- 2Change the Claude account password and revoke other active sessions after cleaning the device
- 3Avoid pirated software and unverified downloads, the most common infostealer delivery route cited in this case
- 4Review Claude billing history for unauthorized charges and confirm any refunds from Anthropic
Technical details
- Exploitation
- Exploited in the wild
- Attack vector
- Local infostealer malware on a victim's Windows PC or Mac harvests browser data, including already-authenticated Claude session cookies, which an attacker then reuses to log into Claude accounts without a password or 2FA.
Mitigations
- Anthropic revokes compromised Claude sessions and removes saved payment methods on affected accounts
- Run reputable anti-malware software to detect and remove infostealers such as Vidar, LummaC2, StealC, RedLine, Acreed, or Atomic Stealer
Response
Vendor
Customer guidance
Anthropic advises affected users that signing them out stops the stolen session but does not remove the malware, and urges changing credentials, revoking other sessions, and cleaning the infected computer before logging back in.
FAQ
How did attackers hijack Claude accounts without a password?
Infostealer malware already on victims' computers copied active, authenticated Claude browser sessions, letting attackers reuse the login directly and skip the password and 2FA process entirely.
What malware is Anthropic linking to the Claude session theft?
Anthropic identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows machines, plus Atomic Stealer (AMOS) on a small number of Macs.
Is the infostealer malware related to Claude or delivered through it?
No. Anthropic said it has no reason to believe the malware is related to Claude, installed through Claude, or tied to anything the user did with Claude; infections typically come from unrelated downloads like pirated software.
What is Anthropic doing for affected users?
Anthropic is signing affected accounts out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.
How would a user know their Claude account was hijacked this way?
Anthropic said a telltale sign is usage limits appearing to refill and then drain even when the account owner was not using Claude.
What should someone do if their Claude session was stolen?
Anthropic recommends removing the infostealer from the infected computer, changing the Claude password, and revoking other active sessions before logging back in.
The bottom line
Anthropic emailed affected Claude users to explain that pre-existing infostealer malware stole authenticated login sessions, letting attackers access accounts and drain usage without passwords or 2FA.
What happens next
What to do






