← BACK TO FEED
infostealer malwareClaudeAnthropicaccount securitysession hijacking

Infostealer Malware Is Draining Claude Accounts While Users Sleep

Anthropic has warned some Claude users that their computers were infected with infostealer malware — including Vidar, Lumma, and Atomic Stealer — which allowed attackers to steal browser cookies and hijack login sessions to exploit their accounts. The company detected the activity, signed out compromised sessions, removed saved payment methods, and refunded any unauthorized charges. Affected users have been advised to remove all malware from their devices before re-adding payment information.

Anthropic has sent warning emails to a subset of Claude users after detecting that infostealer malware had been used to hijack their active login sessions. The attackers then burned through usage limits on the compromised accounts, leaving victims confused about where their quota went.

The company says it spotted the suspicious activity, killed the affected sessions, and stripped saved payment details from the impacted accounts as a precautionary measure. Any charges Anthropic identified as fraudulent have apparently been refunded.

The malware families involved are the usual suspects: Vidar, Lumma, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) catching a smaller number of macOS users. None of this is Claude-specific. These are commodity infostealers that hoover up browser cookies, saved passwords, and application credentials from whatever machine they land on. Claude sessions just happened to be in the haul.

The infection vector is the standard story: dodgy downloads, cracked software, malicious apps. The malware sits quietly, copies everything useful it can find, and ships it off. Someone then sifts through that stolen data specifically for Claude session tokens and puts them to work.

If you noticed your Claude usage limits mysteriously refilling and then emptying again without you doing anything, that was probably why.

Anthropomorphic says it may log users out again if further suspicious activity appears. Affected users have been told firmly not to re-enter payment details until they are certain their machines are clean. That is genuinely good advice that most people will ignore.

The broader takeaway is not really about Claude. Infostealer malware is a growing and largely unglamorous problem across the industry. Any platform storing session cookies in a browser is vulnerable the moment a machine is compromised. The fact that AI usage limits have monetary value makes those sessions worth stealing.

READ NEXT
Pentagon Blacklisted Anthropic Over Capabilities Claude Doesn't Actually Have, Judge RulesClaude Broke Into Three Real Networks During Testing. Nobody's Going to Prison.Claude Wandered Off the CTF Range and Into Three Real Companies