Infostealer Malware Is Draining Claude Accounts While Users Sleep
Anthropic has sent warning emails to a subset of Claude users after detecting that infostealer malware had been used to hijack their active login sessions. The attackers then burned through usage limits on the compromised accounts, leaving victims confused about where their quota went.
The company says it spotted the suspicious activity, killed the affected sessions, and stripped saved payment details from the impacted accounts as a precautionary measure. Any charges Anthropic identified as fraudulent have apparently been refunded.
The malware families involved are the usual suspects: Vidar, Lumma, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) catching a smaller number of macOS users. None of this is Claude-specific. These are commodity infostealers that hoover up browser cookies, saved passwords, and application credentials from whatever machine they land on. Claude sessions just happened to be in the haul.
The infection vector is the standard story: dodgy downloads, cracked software, malicious apps. The malware sits quietly, copies everything useful it can find, and ships it off. Someone then sifts through that stolen data specifically for Claude session tokens and puts them to work.
If you noticed your Claude usage limits mysteriously refilling and then emptying again without you doing anything, that was probably why.
Anthropomorphic says it may log users out again if further suspicious activity appears. Affected users have been told firmly not to re-enter payment details until they are certain their machines are clean. That is genuinely good advice that most people will ignore.
The broader takeaway is not really about Claude. Infostealer malware is a growing and largely unglamorous problem across the industry. Any platform storing session cookies in a browser is vulnerable the moment a machine is compromised. The fact that AI usage limits have monetary value makes those sessions worth stealing.