Anthropic has started warning Claude users that infostealer malware on their computers may have stolen their active login sessions, letting attackers slip into their accounts and burn through their paid usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized, according to a report from BleepingComputer published on August 30.

The warning, sent by email to affected account holders, describes a bad actor using common, off-the-shelf infostealer malware to harvest Claude login sessions from infected PCs and then use those sessions to access Claude accounts and consume their usage allowances. For more context on this story, see our ongoing latest AI developments.

What Anthropic Told Affected Users

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in the email, which one affected user shared on Reddit and which BleepingComputer reviewed.

The company added a telltale symptom that victims may have noticed without understanding it: "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause."

Along with forcing sign-outs and pulling saved cards, Anthropic said its investigation is ongoing, but that the affected computers were most likely already infected with general-purpose infostealer malware before anything touched Claude.

"We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company stressed in the email.

How Session Theft Sidesteps Passwords and 2FA

The technical detail that makes this campaign effective is that infostealers do not need to crack a password or defeat two-factor authentication. As BleepingComputer notes, infostealer malware can copy an already-authenticated browser session, which means an attacker holding those session cookies can resume the login as if they were the victim — no password prompt, no 2FA challenge.

According to Anthropic's email, this class of malware typically arrives through downloads or malicious apps and collects whatever is stored locally: browser passwords, login cookies, and credentials belonging to other applications. "Your Claude session was likely one of the many things it collected," the company wrote. "It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them."

In the case that surfaced on Reddit, the affected user confirmed they had downloaded a pirated game, which BleepingComputer notes explains how the system got compromised in the first place.

Why AI Accounts Are Worth Stealing

The campaign highlights a shift in what criminals consider worth taking. A Claude account is not just an email address — an active session carries a usage allowance that refills on a schedule, and someone quietly siphoning that allowance gets model access for free while the victim pays or loses access themselves.

The symptom Anthropic described, usage limits that appear to refill and then drain inexplicably, suggests the attackers were letting sessions sit until quotas reset and then consuming them, rather than making noisy one-time thefts.

For Anthropic, the response leans on containment rather than claiming its own systems were breached. The company's position, as stated in the email, is that the compromise started on users' machines, not on Claude's infrastructure — and the remediation (forced sign-outs, removal of stored payment methods, refunds of unauthorized charges) is designed to cut hijacked sessions off from anything valuable they can reach.

What Users Can Do

The specifics of this incident point to a familiar defense: keep infostealers off the machine in the first place. Anthropic's email traces the infections to general-purpose malware delivered through downloads and malicious apps — in the documented case, pirated software.

Security teams have warned for years that cracked software and shady installers are among the most reliable delivery channels for infostealers, and this incident follows that pattern exactly. Once such malware has run with user privileges, it can read browser cookie stores, and from there an authenticated web session is simply another file to copy.

Users who see Claude usage behaving oddly — limits draining while idle, or refilling and vanishing — should sign out of all sessions, rotate credentials, and contact Anthropic support, which is already refunding unauthorized charges it identifies.

A Sign of What's Next for AI Account Security

As AI subscriptions become line items with real monetary value, the incentives shift. credential-harvesting malware has always followed value, from bank sessions to gaming accounts to streaming logins, and AI usage allowances are the newest prize with a clean resale logic: access that refills itself is worth more than a one-shot login.

Anthropic's handling — proactive sign-outs, payment-method removal, and refunds — sets an early benchmark for how AI vendors may be expected to respond when their accounts become targets of commodity malware. The company has not disclosed how many accounts were affected, and its investigation, per the email, remains ongoing.

---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →