Your Claude usage limit refilled, then drained overnight while your laptop sat closed. If that happened to you this week, you’re not imagining things. Anthropic confirmed that infostealer malware sitting on some users’ computers stole active Claude login sessions and let attackers use those accounts without ever touching a password.
This isn’t a Claude hack. Nobody broke into Anthropic’s servers. The malware was already on the victims’ machines, quietly copying browser cookies, and Claude sessions were just one more thing it picked up along the way.
What Is The Claude Infostealer Hijack?
Infostealer malware already sitting on a user’s PC copied their active Claude browser session and handed it to an attacker, who then logged in as that user and burned through their usage without needing a password or 2FA code. Anthropic is signing affected users out, pulling saved payment methods, and refunding unauthorized charges.
The company sent emails to a batch of affected users last week. One of them posted the message on Reddit, and that’s how most people first heard about it.
We tested the described attack path against how session cookies normally work in Chrome and Firefox, and the mechanics check out. This is not a new trick — it’s an old one aimed at a newer target.
How Did Attackers Get Into Claude Accounts?
They didn’t guess passwords or brute-force logins. They stole the session cookie a browser stores after you log in, and that cookie alone is enough to open your account on a different machine.
The chain looks like this:
- Infection. A user downloads a pirated app, a cracked tool, or clicks a malicious ad — completely unrelated to Claude.
- Local theft. The infostealer scans the browser’s storage and copies saved passwords, autofill data, and active session cookies for every site logged in, Claude included.
- Exfiltration. That stolen data gets uploaded to the attacker’s server, usually bundled with cookies from dozens of other sites on the same machine.
- Session replay. The attacker loads the stolen Claude cookie into their own browser and is instantly logged in as the victim — no password, no 2FA prompt, because the session was already authenticated.
- Usage drain. From there, the account gets used for whatever the attacker wants, and the real owner’s usage limits take the hit.
Anthropic named five malware families behind this specific wave: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, with a smaller cluster of Mac users hit by Atomic Stealer (AMOS). None of these are new or Claude-specific. They’re general-purpose credential stealers that have been hitting gamers, crypto traders, and pirated-software users for years. Claude accounts are just the latest thing worth stealing.
Is This The Same As The Fake Claude Install Pages?
No, and mixing these up is the biggest mistake we’ve seen in early coverage. This week’s incident is about malware already on a victim’s PC stealing an existing Claude session. A separate, earlier campaign tricked people into installing malware disguised as Claude Code itself.
Back in March, researchers at Malwarebytes found cloned Claude Code install pages swapping the official one-line install command for a script that dropped an infostealer called Amatera. That attack relied on copy-pasting a fake terminal command. This week’s attack relies on malware that’s already there, from a completely different source, scavenging whatever sessions it finds. Same category of threat, different door into your machine.
Why Would Someone Steal Claude Usage Instead Of Money?
Because Claude usage is worth money without ever touching a bank account. A stolen session gives an attacker paid model access they didn’t pay for, and API-based sessions can be resold or run through automated scripts for hours before anyone notices. It’s a quieter payday than card fraud, and it’s harder to trace back to a single transaction.
Compare that to stolen crypto wallets, which get flagged the second a transfer moves. A drained Claude account just looks like heavy usage until the real owner checks their dashboard and finds the meter empty.
What Should You Do If You Think Your Claude Account Was Hijacked?
Change your Claude password, log out of every active session, run a full malware scan, and re-check your saved payment method — in that order, today, not this weekend. Anthropic is already force-logging-out confirmed victims, but that only kills the stolen copy of the session. It does nothing about the malware still sitting on your hard drive, which can just grab a fresh session the next time you log in.
Here’s the full cleanup, step by step:
- Run a real malware scan. Use Malwarebytes or Windows Defender’s full offline scan, not just a quick scan. Infostealers hide well.
- Change your Claude password from a clean device, ideally your phone, not the possibly infected computer.
- Revoke all active sessions in your Claude account settings so any lingering stolen cookie stops working.
- Check your payment methods. Remove and re-add your card if Anthropic hasn’t already done it for you.
- Change passwords everywhere else too. If one infostealer grabbed your Claude session, it almost certainly grabbed sessions and passwords for other sites on the same machine.
- Turn on 2FA, though be aware it won’t stop a stolen active session — it stops future login attempts that need a fresh password.
- Wipe or reinstall if the scan finds a rootkit-level infection. Some infostealer variants are stubborn enough that a clean OS install is genuinely faster than chasing them out.
Could This Happen Again On A Phone?
Anthropic said phones and tablets don’t appear to be involved in this specific wave, which lines up with how most infostealers are built — they’re Windows and macOS desktop malware, not mobile malware. That’s good news for now, but it’s not a guarantee. Mobile infostealers exist and are getting more capable, especially on Android where sideloaded apps can request the kind of storage access a stealer needs.
If you use Claude mainly through the mobile app and never log in through a desktop browser, your exposure to this particular wave is close to zero. If you also use Claude on a Windows laptop, that’s the machine to check first.
What Is Anthropic Doing About It?
Anthropic is force-logging-out confirmed victims, stripping saved payment methods from those accounts, and refunding usage it identifies as unauthorized, while its investigation into the scope of the campaign continues. The company has been explicit that this isn’t a breach of its own systems — it’s malware doing what malware does on infected personal computers, with Claude sessions caught in the crossfire.
That distinction matters for trust. A server-side breach means Anthropic’s infrastructure failed. A session-theft campaign means the failure happened on individual users’ machines, often long before anyone typed a single prompt into Claude.
The Bigger Pattern: AI Accounts Are Now Worth Stealing
A year ago, infostealer logs full of stolen credentials were mostly valuable for banking sites, email, and gaming accounts. Paid AI accounts have quietly joined that list, and Claude won’t be the last one hit. Any service where a subscription buys real compute time is now a target worth listing on the same dark web marketplaces that already sell stolen Netflix and Spotify logins.
That’s the part most coverage of this story is skipping. It’s not really a “Claude problem.” It’s what happens when infostealer malware, which has existed for over a decade, meets a new category of account that’s suddenly worth real money to resell.
FAQ SECTION:
Q1: What is the Claude infostealer malware hijack? A1: It’s an attack where malware already on a user’s computer stole their active Claude login session and let attackers access the account and use up its usage limits, without needing the account’s password.
Q2: Was Anthropic’s own system hacked? A2: No. Anthropic has said the malware isn’t related to Claude and wasn’t installed through Claude. It’s general-purpose infostealer malware that infected users’ personal computers separately, and their Claude sessions happened to be among the data it stole.
Q3: Which malware families are behind this? A3: Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows systems, plus Atomic Stealer (AMOS) affecting a smaller number of Mac users. All are established credential-stealing malware families, not new tools built for Claude specifically.
Q4: How do I know if my Claude account was affected? A4: The clearest sign is usage that refilled and then drained while you weren’t using Claude. Anthropic is emailing confirmed victims directly and force-logging them out, so check your inbox and your account’s active sessions list.
Q5: Does changing my password stop this attack? A5: It stops future logins, but not an already-stolen session that’s still active. You need to revoke all sessions in your account settings and remove the malware from your device, or the attacker can just steal a fresh session next time you log in.
Q6: Is 2FA useless against this kind of attack? A6: Not useless, just incomplete. 2FA protects the login step, but a stolen session cookie skips login entirely because it’s already authenticated. 2FA still matters for stopping new unauthorized logins once you’ve secured your account.