Anthropic has issued a warning to some users of its Claude AI service, indicating that their accounts have been compromised by infostealer malware. The company reports that these malicious programs have stolen active Claude login sessions from users' computers, enabling attackers to access accounts and consume their allocated usage.
In response, Anthropic is taking several steps for affected users, including signing them out of Claude, removing any saved payment methods, and refunding charges identified as unauthorized. The company communicated to affected users that if their usage limits appeared to refill and then deplete without their interaction, this was the likely cause.
The infostealer malware operates by copying already authenticated browser sessions, which means attackers can bypass the standard password and two-factor authentication processes. Anthropic's ongoing investigation suggests that the compromised computers were already infected with general-purpose infostealer malware. The company emphasized that there is no indication the malware is related to Claude itself, was installed through Claude, or connected to any user activity within the service.
According to Anthropic, this type of malware typically infiltrates systems through downloads or malicious applications. Once installed, it steals locally stored information, including browser passwords, login cookies, and credentials for various applications. Claude sessions were likely among the many pieces of data collected, which attackers are now reportedly exploiting. One user who received the warning confirmed their system was compromised after downloading a pirated game.
Anthropic has identified several specific malware families involved in these attacks. On Windows systems, these include Vidar, LummaC2, StealC, RedLine, and Acreed. A smaller number of Mac users were affected by Atomic Stealer (AMOS).
While Anthropic is revoking compromised sessions and removing payment methods to prevent further unauthorized purchases, the company stressed that signing users out of Claude does not eliminate the malware from their computers. If the malware remains, subsequent login sessions could be stolen in the same manner.
Affected users are advised to implement basic security measures. These include changing credentials for their accounts, revoking other active sessions, and thoroughly removing the malware from their personal computers to prevent future compromises.






