Anthropic Warns: Malware Hijacks Claude Sessions to Drain Credits

Anthropic Warns: Malware Hijacks Claude Sessions to Drain Credits

N
News Editor
2026-09-01 06:11:25
Anthropic has alerted Claude users that attackers are using infostealer malware to steal login sessions, bypassing multi-factor authentication to drain paid credits. The company forced logouts, refunded unauthorized charges, and urged users to remove malware, emphasizing the issue stems from user-side infections, not Claude itself.

Anthropic is warning Claude users about a wave of attacks where criminals exploit common infostealer malware to steal login sessions from infected computers, then use those sessions to access accounts and drain paid credits. According to security publication Help Net Security, Anthropic has been proactively contacting affected users since August 30.

Session Theft, Not Password Theft, Bypasses MFA

The key to this attack is that attackers are not stealing passwords but login sessions. These general-purpose malware programs running locally on victims' machines capture browser-stored cookies and session IDs. Since these cookies represent an "already authenticated" state, attackers can replay them to be treated as logged-in users, bypassing multi-factor authentication and accessing accounts without the user's knowledge.

Anthropic said the malware identified in this wave includes Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on some Macs. These malware typically enter computers through unofficial downloads or malicious apps, copying browser-stored passwords, login cookies, and other local credentials.

Anthropic Force-Logs Out Users, Issues Refunds, Urges Malware Removal

In response, Anthropic has force-logged out affected users to invalidate stolen sessions, removed stored payment methods from accounts, and refunded charges it determined to be unauthorized. The company also urged affected users to take basic security measures, including changing credentials, revoking sessions on other devices, and removing the malware from their computers.

Anthropic specifically clarified that the malware does not originate from Claude. "We have no reason to believe that this malware is related to Claude, installed through Claude, or related to any of your actions on Claude," the company said. In other words, the problem is that users' computers have been infected, not that the Claude platform itself has been compromised.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.