Anthropic is notifying affected users that infostealer malware infecting their personal computers has stolen active Claude login sessions, which attackers are then using to access accounts and consume usage. The company is proactively signing out compromised accounts, stripping saved payment methods, and refunding charges it identifies as unauthorized.
In an email sent to affected users and shared publicly on Reddit, Anthropic said it “recently became aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.” The company noted that users whose usage limits appeared to refill and then drain without their own activity were likely affected.
Because infostealers can capture an already authenticated browser session, attackers may be able to reuse a hijacked session without needing to pass through a password or two-factor authentication challenge again.
Not a Claude-specific compromise
Anthropic stressed that the malware has no connection to Claude itself. “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the company said. Instead, investigators found that victims’ machines were already infected with general-purpose infostealers that typically spread through pirated software, malicious downloads, or fake apps, and that harvest browser passwords, login cookies, and credentials for numerous other services.
Anthropic said the Claude session data was just one of many items these tools collected, and that an attacker has since begun specifically extracting and reusing Claude sessions from stolen data logs. The company has tied the activity to several well-known infostealer families, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) affecting a small number of Mac systems. In one case reviewed by BleepingComputer, an affected user confirmed their infection stemmed from downloading a pirated game.
What Anthropic is doing, and what users should do
For affected accounts, Anthropic is revoking compromised sessions and removing saved payment methods to block unauthorized purchases. However, the company cautioned that this does not remove the underlying infection. “Signing you out of Claude stops the stolen sessions, but it doesn’t remove the malware,” Anthropic warned, adding that a still-infected machine could have its next session stolen the same way.
Anthropic is urging affected users to change their credentials, revoke other active sessions across services, and run a full malware cleanup on any infected device before logging back in.
