Anthropic is warning Claude users that malware on their computers stole active login sessions. Attackers used those stolen sessions to enter accounts and burn through usage limits. Anthropic is signing affected users out, deleting saved payment methods and refunding charges it judges unauthorised. It says usage that refilled and then drained while the user was away is the likely sign. The malware is ordinary credential-stealing software, not linked to Claude or installed through it. It usually arrives via downloads or malicious apps and copies browser passwords, cookies and other credentials. A copied session can bypass the normal password and two-factor login. Anthropic named Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a few Macs. It warns that signing out does not remove the malware, so a new session could be stolen. Users are urged to change credentials, revoke other sessions and clean their machines.
What changed
Stolen Claude sessions were letting attackers use accounts undetected.
What it unlocks
Recognising drained usage limits as a sign of a hijacked login session.
Sources