Anthropic Warns Hackers Are Stealing Claude Sessions To Hijack Accounts

Aug 31, 2026 05:45 AM - 1 day ago 7

Anthropic Claude has been signing users retired of their Claude sessions and removing costs methods for users whose computers person been compromised. A personification published the email they received from Anthropic that they had go alert that the customer was compromised by an infostealer malware.

Infostealer Malware

Infostealer malware is malicious package whose intent is to secretly bargain valuable accusation for illustration passwords and credentials from a machine aliases instrumentality and transmit it backmost to the criminals that planted the malware.

This is different from ransomware which announces its beingness by locking files and demanding a ransom for unlocking it. Infostealers are stealthy by creation truthful arsenic to person capable clip to cod valuable accusation that tin later beryllium utilized aliases sold by criminals.

Anthropic Noticed A Computer Was Compromised

A Redditor posted that they had received a announcement from Anthropic astir an effort to bargain tokens from their relationship via the API. The announcement advised them that Anthropic had go alert that they are a unfortunate of an infostealer malware. According to the Redditor, they tally Anthropic’s models connected their machine “exclusively successful permission-free mode.”

The Redditor posted immoderate of the email connection they had received:

“We precocious signed you retired of Claude and removed the costs method saved connected your account, truthful you’ll request to log backmost successful and re-add your card. We’re sorry for the disruption. Here’s what happened and what we’ve done astir it.

What happened

We person precocious go alert of a bad character that is utilizing communal infostealer malware to bargain Claude login sessions from people’s computers, past utilizing those login sessions to entree Claude accounts and devour their usage. Our systems detected this activity connected your account, and we’ve truthful removed your paper connected record and signed retired the sessions progressive to thief artifact further unauthorized access.

If your usage limits looked for illustration they refilled and past drained while you weren’t utilizing Claude, this was apt the cause.

How did this happen

Our investigation is ongoing. Our findings to day propose that a machine you usage pinch Claude is apt infected pinch infostealer malware, and whitethorn person been for immoderate time. Phones and tablets do not look to person been involved.

We person nary logic to judge that this malware is related to Claude, installed done Claude, aliases related to thing you did pinch Claude. It’s general-purpose malware that typically arrives pinch an unofficial download aliases a malicious app, and it softly copies saved passwords, login cookies successful browsers, and credentials for different apps moving locally. Your Claude convention was apt 1 of the galore things it collected. It appears that a bad character has now started picking the Claude sessions retired of what it collected and utilizing them.

The malware identified successful this run truthful acold see Vidar, Lumma (LummaC2), StealC, RedLine and Acreed connected Windows, and Atomic Stealer (AMOS) connected a mini number of Macs.

What we’ve done
Signed retired the sessions involved. Your Claude login convention is saved connected your computer, and the malware took a transcript of it. Signing you retired cancels that convention everywhere, truthful the stolen transcript stops working. This is why you had to log successful again crossed each your ain devices. Please statement that we mightiness motion you retired again if we spot akin signs of relationship misuse.
Removed your saved costs method, truthful it can’t beryllium charged done Claude. Your existent scheme continues for the billing play you’ve already paid for. To renew aft that, aliases to make immoderate purchase, you’ll request to adhd a costs method again successful Settings.”

Origin Of The Infostealer Malware

In consequence to a mobility the Redditor admitted that they had downloaded a pirated crippled and that contained a hidden Infostealer malware. The malware apparently stole login accusation from the computer. The harm wasn’t constricted to extracted passwords. The Redditor related that Chrome credentials, cookies, and convention IDs were stolen, information that could beryllium utilized to impersonate the personification online.

Two-Factor Authentication Failed

Quite apt the astir startling portion of this saga is the Redditors declare that two-factor authentication did not protect them. That’s astir apt because the convention ID and cookies whitethorn person enabled the criminals to impersonate the Redditor’s logged-in Chrome session.

The criminals did not person to conclusion two-factor authentication because they could conscionable usage the logged-in convention state.

Anthropic Opus’s Solution Terrified The User

Removing the infected package did not destruct the malware itself. The Redditor’s mentation suggests that the malware itself had burrowed heavy into their computer. The Redditor recounted that they deployed Claude straight into their computer, which proceeded to guidelines retired the malware.

They described the process:

“…I was already logged into Claude CLI. My presumption was that the microorganism was still coming and active. So utilizing Claude connected my machine wouldn’t alteration thing until the microorganism was deactivated.

…According to the report, Opus detected the virus, deactivated it, identified it, and past reverse-engineered it to measure the grade of the threat. It almost terrified me. It was for illustration watching a diabolical surgeon dissecting his prey.”

PC Antivirus Useless

Claude Opus described really the infostealer worked and provided instructions connected really to reset each of their login credentials.

They wrote:

“Apparently, the microorganism operated connected a timer system and sent a “batch” of login credentials to a distant server each fewer minutes.

In fact, if the hacker had acted quickly, he could person trim disconnected my entree to Claude (forcing maine to reset my machine arsenic a past edifice and slowing down my efforts to antagonistic him). Windows Defender was clueless”

Was The Problem Truly Solved?

One personification who identified themself arsenic a information master pinch 20 years of master acquisition red-teaming malware recommended wiping their full machine and starting anew pinch it because their acquisition is that these kinds of malware instal backup files for restoring themselves.

Their advice:

“I powerfully urge you swipe your strategy and reset your passwords.

Or you tin spot Claude who hallucinates.”

Featured Image by Shutterstock/Algi Febri Sugita

Category News AI Search
Add SEJ arsenic a preferred root connected Google
More