Anthropic warns Claude users that stolen browser sessions can bypass 2FA and drain account usage

Anthropic warns Claude users that stolen browser sessions can bypass 2FA and drain account usage

N
News Editor
2026-08-31 10:29:31
Anthropic has sent security warnings to some Claude users after detecting a pattern in which attackers steal active login sessions from malware-infected computers and use them to access accounts and consume usage limits. According to examples shared by users on Reddit, the issue is not password theft in the usual sense. Instead, attackers are taking browser cookies and session IDs tied to already authenticated sessions, which lets them impersonate users without re-entering a password or passing two-factor authentication again. One user said they signed in with Google and had 2FA enabled, but their browser session was still stolen. In its warning email, Anthropic listed several infostealers linked to this activity, including Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on Mac. The company said this is not a security flaw in Claude itself. Anthropic also said it has revoked suspicious sessions, removed saved payment methods from affected accounts, and addressed related unauthorized charges. The company warned that changing a password alone will not fix the problem if malware remains on the device.

Anthropic is sending security warnings to some Claude users after finding that attackers have been stealing active Claude login sessions from malware-infected computers and then using those sessions to access accounts and consume user quotas.

Users on Reddit have posted screenshots of warning emails from Anthropic. The company described the issue as session theft rather than a direct password compromise.

Attackers are taking authenticated browser sessions

According to one user, what was stolen was not the account password but an already authenticated browser session. That included browser cookies and the session ID.

With that login state in hand, an attacker can impersonate the user without entering the password again or completing 2FA. The user said they had signed in with Google and had two-factor authentication enabled, but their browser cookie and session ID were still taken.

Anthropic named multiple infostealers in its warning

In the email, Anthropic listed several infostealer families tied to this kind of activity: Vidar, LummaC2, StealC, RedLine and Acreed on Windows, along with Atomic Stealer, or AMOS, on Mac.

These malware strains are built to steal browser cookies, passwords and related data. Anthropic said the problem is not a security vulnerability in Claude itself.

Suspicious sessions were revoked and payment methods removed

The same user said in replies to other Reddit users that they had previously downloaded pirated software. Anthropic said in its email that it had revoked detected suspicious login sessions, removed saved payment methods from the account, and handled related unauthorized charges.

The company also warned that changing a password alone is not enough. If the malware remains on the computer, newly created login sessions can still be stolen again.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
900

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.