Notebookcheck Logo

Claude sessions stolen: Anthropic signs users out and wipes cards

Laptop screen showing an Authentication Failed error after a failed login.
ⓘ Markus Spiske / Pexels
Anyone affected has to log back into Claude and add a payment method again.
Anthropic has been signing Claude users out and removing the payment method saved on their accounts. In an email to affected customers the company explains why. Infostealer malware copied their Claude login sessions from their PCs, and a bad actor used them to burn through paid usage. No password or two-factor code was needed.

If your Claude usage limit refilled and then drained while you were not using Claude, somebody else was probably inside your account. Anthropic has signed affected users out and removed the payment method stored on their accounts. Anyone who wants to carry on has to log back in and add a card again.

Anthropic gave its reason in an email to affected customers, which one of them posted in the r/ClaudeAI forum. "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," that message says. According to the company, the giveaway was usage that appeared to refill and then drain while the owner had not opened Claude at all. No public statement exists so far, and the incident does not appear on Anthropic's status page.

The malware copies a login you already completed

An infostealer is malware built to collect credentials quietly and ship them to whoever planted it. It locks nothing and demands no ransom, it reads along. According to Anthropic it copies saved passwords, login cookies in browsers and credentials belonging to other apps running locally. That Claude session was one item among many that it picked up.

Anthropic names Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs. It stresses that there is "no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude", and says the software typically arrives with an unofficial download or a malicious app. Phones and tablets do not appear to have been involved.

Why two-factor authentication did not help

A session is proof that you already signed in. It sits on your machine as a cookie, and whoever copies it never has to run the login again. Password and second factor get skipped because nothing asks for them at that point. We have covered how this attack works in detail, and a similar question came up around ChatGPT a few days ago.

One affected Reddit user had downloaded a pirated game. Windows Defender did not react. Game copies from dubious sources are built for exactly this, and a free Steam title robbed its players the same way.

Signing out is not enough

Anthropic describes two steps, and the sign-out is the first of them. It cancels the stolen session everywhere, which is why affected users had to log in again on all of their own devices. A removed payment method can no longer be charged through Claude, while the current plan runs until the end of the billing period already paid for. BleepingComputer reports that Anthropic is also refunding charges it identifies as unauthorized, and the company says it may sign users out again if it sees similar signs of misuse.

One sentence at the end of the email matters more than the rest. "Signing you out stops the stolen sessions, but it doesn't remove the malware," Anthropic writes, and as long as it is still on the machine the next login can be taken the same way.

The user let Claude clean up, security pros disagree

That customer then pointed Claude Opus at his own machine to find the malware and shut it down. In the comments a security professional with twenty years of experience pushed back and recommended wiping the system and resetting every password. Malware of this kind routinely drops copies that restore it. Anyone affected is safer reinstalling.

Google LogoAdd as a preferred source on Google
Mail Logo

No comments for this article

Got questions or something to add to our article? Even without registering you can post in the comments!
No comments for this article / reply

static version load dynamic
Loading Comments
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > News > News Archive > Newsarchive 2026 08 > Claude sessions stolen: Anthropic signs users out and wipes cards
Steffen Zahn, 2026-08-31 (Update: 2026-08-31)