Anthropic has alerted users of its AI platform, Claude, about a serious security threat involving infostealer malware. This malware has been found to hijack active login sessions, allowing attackers to access user accounts and deplete usage. According to a report by Bleeping Computers, the malware steals authenticated browser sessions from compromised devices, enabling attackers to circumvent both passwords and two-factor authentication.
In response, Anthropic is proactively signing out affected users from Claude, revoking saved payment methods, and issuing refunds for any unauthorized charges. The company emphasizes the importance of securing personal devices to prevent such breaches.
What Anthropic is telling users to do
In the case shared on Reddit, the affected user confirmed they had downloaded a pirated game shortly before the compromise, offering a likely explanation for how the malware ended up on their system in the first place.
In an email sent to affected accounts, Anthropic said it recently became aware of a bad actor using common infostealer malware to steal Claude login sessions directly from people’s computers, then using those stolen sessions to access accounts and burn through the victims’ usage. Anthropic said its investigation is still ongoing, but that affected computers were most likely already infected with general-purpose infostealer malware unrelated to Claude itself. This type of malware typically spreads through downloads or malicious apps, and once installed, harvests information stored locally on a device — including browser passwords, login cookies, and credentials tied to a wide range of other apps and services, according to Anthropic. Anthropic said it has identified several specific malware families involved in these attacks, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems, along with Atomic Stealer (AMOS) affecting a small number of Mac users.
The email, which was shared publicly on Reddit by one affected user, also gave people a way to recognise the symptom: if a Claude account’s usage limits appeared to refill and then mysteriously drain while the account wasn’t actively being used, that pattern was likely the cause. The mechanics of the attack make it particularly hard to notice. Infostealer malware can copy an already-authenticated browser session, meaning an attacker doesn’t need to go through a normal password or two-factor authentication login process to gain access — they simply reuse a session that’s already been verified. The company was explicit on this point, stating it has no reason to believe the malware is connected to Claude, was installed through Claude, or relates to anything the user did within the Claude platform. A user’s Claude session was likely just one of many pieces of data swept up in that broader collection process, with attackers only recently beginning to specifically extract and exploit the Claude sessions from what they’d already gathered. For accounts identified as compromised, Anthropic is taking several protective steps: signing affected users out of Claude, revoking the stolen sessions, removing any saved payment methods from the account, and refunding charges it identifies as unauthorized. However, the company was clear that this response only addresses the symptom, not the underlying cause. Anthropic warned that signing a user out stops the stolen session from being used, but it doesn’t remove the malware itself — meaning if the infection is still present on a user’s device, their very next login session could be stolen through the exact same method. Anthropic has urged affected users to take basic follow-up security steps beyond what the company can do on its end, including changing their account credentials, revoking any other active sessions tied to their accounts, and thoroughly removing the malware from their infected computers before logging back in. Get the latest technology news and updates. Download the TOI App.


Pingback: AI giant Anthropic has confirmed that it paused some AI training: The wider industry
Pingback: Anthropic has launched two new AI models, Claude Fable 5.1: The wider industry impact