Anthropic has confirmed that hackers are hijacking Claude login sessions with infostealer malware and draining paid usage, including from one consultant's $200-a-month account.
Key Points:
- Anthropic began warning subscribers on Aug. 30 that stolen browser sessions were letting attackers consume paid usage without a password or a second factor.
- The company named six commodity malware strains behind the campaign, five on Windows and one affecting a smaller number of Macs.
- One consultant lost about two weeks of account access and says he still cannot get an itemized log of what was spent.
Claude Sessions Hijacked Through Stolen Browser Cookies
TechCrunch reported the case of Grant de Swardt, an independent AI consultant in East Sussex, England, who watched his token allowance climb on Aug. 4 while he was not working. The next day he disconnected every tool tied to the account, paused his scheduled jobs and stayed off the service entirely. Usage rose anyway, climbing from 45% to 55%.
He asked Anthropic for an itemized breakdown and never received one. The company suspended his account, invalidated every session and server-side token, and refunded £44.49 against the remainder of the plan.
Investigators later concluded that a compromised session key had been used to mint unauthorized Claude Code tokens on his account. Anthropic told him the account looked as though an outside service had been running work on it for other people, but could not establish how that service got in. He took it to Reddit and drew about 80 comments, several from users describing the same drain.
Also Read: XRP Price Eyes $1.46 With Whale Accumulation Back In September
Anthropic Names Vidar, LummaC2 And Four More Stealers
Anthropic began emailing a wider group of customers on Aug. 30, naming Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs. All six are commodity stealers rented cheaply on criminal marketplaces, and none of them is new.
The company said the malware has no link to Claude and usually arrives through pirated downloads or malicious apps. Once installed, it scrapes saved passwords, autofill data and login cookies off the machine, then ships them to an operator. Anthropic signed affected users out, deleted saved payment cards, and refunded charges it judged unauthorized on those accounts.
Session Theft Now Outruns Password Theft
Security researchers tie the campaign to a broader move away from password theft, because multifactor authentication has made stolen credentials far less useful on their own. A stolen cookie proves a login already happened, so an attacker walks past those checks without tripping an alert or facing a second factor.
De Swardt got his account back after about two weeks, then cancelled it for Cursor. He says Anthropic still gives users no way to see what is consuming an allowance, and the company declined to comment on how subscribers can spot misuse. The episode closes a rough stretch for a firm that disclosed three incidents in July involving unauthorized actions by its own models, paused parts of its training work and moved about 150 product engineers onto security teams.
Read Next: Bitget Adds Blockchain Lessons To UNICEF Program Reaching 642,000+





