Skip to content
Anthropic warns: attackers are hijacking active Claude sessions and using up other people's limits

Anthropic warns: attackers are hijacking active Claude sessions and using up other people's limits

Mezha.Ua August 31, 2026

Anthropic has warned some Claude users attacks using infostealers that hijack active chatbot sessions and consume AI limits on behalf of the owners, Bleeping Computer reports .

" We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage ," Anthropic said in an email to one user.

" We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage ," Anthropic said in an email to one user.

Infostealer is a malware designed to covertly collect and steal sensitive data from a victim's device. Primarily passwords, cookies, or other browser data, but in the case of Anthropic, the attackers targeted already authorized sessions on Claude.

A sign of an attack, according to the company, may be the strange behavior of Claude limits: they can quickly recover and then run out at a time when the user is not actually using the service.

Anthropic has now begun forcibly logging affected users out of Claude to prevent further theft, removing saved payment methods, and issuing refunds to account holders if unauthorized charges are confirmed.

Anthropic has detected several types of malware, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on a small number of Mac computers.

" We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude ," the company said. " Your Claude session was likely one of the many things it collected ."

" We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude ," the company said. " Your Claude session was likely one of the many things it collected ."

One user who shared an email from the company confirmed that he had pre-loaded a pirated game and that this may explain why his system was compromised.

Anthropic urged victims to take basic security measures, including changing their credentials, canceling other sessions, and removing the malware from their PCs.

Read also: Court overturns 'blacklist' against Anthropic, which the Pentagon had penalised for its stance on AI-powered weapons

Sony and Warner have accused Anthropic of unlawfully using "tens of thousands" of musical works

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)