IA4 MIN

Malware is stealing Claude sessions and can get in without asking for a password

Anthropic is revoking sessions, removing saved payment methods and refunding unauthorised charges. Here is how to spot access and stop reinfection.

Claude interface open in a web browser
Image: BleepingComputer
01

The warning sign is a limit draining by itself

If your Claude limit appears to refill and then disappears while you are away, the problem may be inside your computer. Anthropic has warned users that a threat actor is using information-stealing malware to copy active sessions and consume their allowance. The company is signing affected accounts out, removing saved payment methods and refunding charges it identifies as unauthorised.

Anthropic's email, reported by BleepingComputer, draws an important boundary. Claude did not install the malware and the infection is not related to the assistant. General-purpose stealers arrive through downloads or malicious apps, then collect passwords, cookies and credentials from many services. A Claude session is one item in that haul.

Anthropic has linked the Windows cases to Vidar, LummaC2, StealC, RedLine and Acreed. A smaller number of Macs carried Atomic Stealer, also known as AMOS. One affected user acknowledged downloading a pirated game. Not every unofficial download is infected, but cracked software remains a common route for this class of malware.

Anthropic email warning a user that their Claude session was stolen
Image: BleepingComputer · affected user
02

Why two-factor authentication may not stop a copied session

A session cookie tells a service that this browser has already completed login. If malware copies that cookie and the attacker can reuse it, Claude may see an authenticated session. There is no new password or two-factor prompt to complete. Two-factor authentication remains essential for fresh logins, but the attacker has stolen something created after that check.

Changing a password does not disinfect the computer either. It may revoke some access, but an active infostealer can simply copy the next session when you sign in again. Anthropic's warning says it plainly: ending the stolen session stops that access, not the malware.

That is why an open session should be treated as a credential rather than a harmless browser tab. The threat differs from the time shared Claude chats appeared in Google results, but both cases reward checking what remains open or public.

03

What to do if you see an unfamiliar session

Open Claude on a device you believe is clean, select your profile and go to Settings > Account > Active sessions. Anthropic shows the browser, operating system, approximate location and recent activity. Terminate anything unfamiliar. You can also use Log out of all devices from the web app to revoke everything at once.

Do not judge a session by its city alone. Mobile networks, VPNs and internet providers can shift an approximate location. Compare it with the browser, operating system and activity time. If that combination matches none of your devices, revoke it first and investigate afterwards. Keeping a suspicious session alive is riskier than signing in again.

Next, scan and clean the infected computer, remove the app or extension that introduced the stealer and change credentials from a clean device. Check email, password managers and other services used in the same browser. Information stealers rarely collect just one account.

  • Revoke unfamiliar sessions or sign out everywhere from Claude on the web.
  • Do not sign in again until the infected computer is clean.
  • Change reused passwords and enable two-factor authentication where available.
  • Review usage, saved payment methods and card transactions.
  • Contact Anthropic support about charges or usage you do not recognise.
Illustration of several open Claude sessions with one session ready to be revoked
Image: Original illustration · INSERT FUTURE
04

What Anthropic is doing

The investigation remains open. Anthropic is revoking compromised sessions, removing saved cards to prevent purchases and refunding charges it can attribute to unauthorised access. It has not disclosed how many accounts were affected or how long the stolen sessions were used.

This attack is not a reason to abandon Claude. It is a reason to stop treating a password as the whole security boundary. Our guide to asking an AI to change code through a separate GitHub branch applies the same principle at work: limit access to something valuable and keep a clear way to revoke it.

00

The conversation starts here

Sign in with a supporter account to comment. Sign in

Nobody has commented yet. Want to go first?

KEEP READING

You may also like

FRONT PAGE