Anthropic Warns Claude Users of Stolen Sessions via Infostealer Malware
Artificial intelligence company **Anthropic** is notifying some users of its **Claude** AI assistant that their active login sessions have been compromised by infostealer malware. Attackers are leveraging these stolen sessions to access accounts and consume usage, prompting Anthropic to sign out affected users, remove payment methods, and refund unauthorized charges.

**Anthropic** has issued a warning to a segment of its **Claude** user base regarding a wave of account compromises. The company states that malicious actors are utilizing common infostealer malware to pilfer active **Claude** login sessions directly from users' computers.
Once obtained, these stolen sessions grant attackers direct access to accounts, allowing them to consume **Claude**'s usage limits without needing to re-authenticate with passwords or two-factor authentication.
"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," **Anthropic** stated in an email shared by an affected user on Reddit.
"If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," the company further warned.

**Anthropic** sending emails to affected users
Source: Reddit
### Infostealers Identified: Vidar, LummaC2, RedLine Among Others
**Anthropic**'s ongoing investigation suggests that the compromised computers were already infected with general-purpose infostealer malware. The company emphasizes that there's no evidence linking the malware to **Claude** itself or suggesting it was installed through the AI platform.
"We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," the company stressed.
These malware strains typically infiltrate systems via malicious downloads or apps, subsequently stealing locally stored data such as browser passwords, login cookies, and credentials for various applications.
"Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them," **Anthropic** explained.
Among the identified malware families are **Vidar**, **LummaC2**, **StealC**, **RedLine**, and **Acreed** on Windows systems. A smaller number of Mac users were affected by **Atomic Stealer** (**AMOS**).
### Remediation and User Action
In response to confirmed compromises, **Anthropic** is taking several steps: revoking compromised sessions, signing users out of **Claude**, and removing any saved payment methods to prevent unauthorized purchases.
However, **Anthropic** strongly cautions that revoking sessions does not remove the underlying malware. "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," the company warned. "If it's still on your computer, your next login session could be stolen the same way."
Affected users are urged to implement fundamental security measures, including changing credentials for all relevant accounts, revoking other active sessions, and, crucially, removing the infostealer malware from their compromised PCs.