Skip to content
Claude hit by infostealer malware campaign stealing session credentials

Claude hit by infostealer malware campaign stealing session credentials

Finance.Biggo August 31, 2026

Anthropic's Claude chatbot has been hit by a large-scale account security incident, with numerous users force-logged-out without any prior warning and their saved credit card information deleted directly by the company. According to official emails received by users, Anthropic confirmed that malicious attackers used common infostealer malware to steal Claude login session credentials from users' computers, then infiltrated accounts to aggressively drain usage quotas.

An affected user posted Anthropic's warning email on 's r/ClaudeAI forum. The email read: "We have identified that malicious attackers are using common infostealer malware to steal Claude login sessions from users' computers. They then use these credentials to access your account directly and aggressively consume your usage quota."

Anthropic named six malware families in the email: Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) found on a small number of Mac devices. The company emphasized there is "no reason to believe these malware are associated with Claude, installed through Claude, or related to anything you did on Claude," noting that such software typically arrives on user devices through unofficial downloads or malicious applications. Mobile phones and tablets appear to be unaffected.

Session credentials at the core of the attack

The crux of this attack lies in the theft of "session cookies." Unlike traditional password theft, infostealer malware does not need to obtain account passwords or bypass two-factor authentication (2FA). Instead, it directly copies login cookies and session IDs stored in the browser. These credentials function like an already-authenticated "VIP pass"—once obtained, hackers can replicate the same login environment on their own devices, skipping password and 2FA checks entirely to access Claude accounts directly as the legitimate user.

One commenter in the discussion put it bluntly: "Simply changing your password does nothing to session cookies that have already been stolen. You must first revoke active sessions, otherwise the attacker will just keep riding your old session and doing whatever they want."

Anthropic's "self-diagnosis standard" is: if your Claude quota mysteriously replenished itself, and then suddenly got drained again without you using it at all, you have most likely fallen victim to this type of attack.

One user shared their firsthand experience. They were infected after downloading a "cracked version" of an obscure old game from a Russian game-cracking forum, with Windows Defender raising no alerts throughout the entire process. Their social media accounts were first compromised and used to send cryptocurrency scam messages, followed by a warning from Claude in the middle of the night: someone was aggressively draining their tokens through the API.

Official response and user self-help

Anthropic has taken two core measures: force-logging-out affected accounts to immediately invalidate stolen sessions across all devices, and deleting saved payment methods from accounts to prevent hackers from generating additional charges through Claude. Current plans within already-paid billing cycles remain usable until expiration.

According to BleepingComputer, Anthropic is also processing refunds for charges deemed unauthorized and indicated that if similar signs of abuse are detected again, it may force-log-out users once more.

However, the sentence Anthropic wrote at the end of the email may be more important than everything preceding it: "Forced logout can stop stolen sessions, but it does not remove the malware." As long as the trojan remains潜伏 on the user's computer, credentials from the login could be stolen in exactly the same way.

The affected user made a surprising attempt: they enlisted Claude Opus 5 Max as their own antivirus, granting it unrestricted global access to the computer with a simple instruction: "I may have downloaded a virus recently, and my login credentials were stolen. Please audit for malware, delete it if found, and report the extent of the damage."

Opus 5 quickly scanned active processes and recent downloads, precisely identified the virus, disabled it, and even performed reverse engineering. In its security report, it noted that the attack chain exactly matched activity documented by Malwarebytes in July 2026: RenPy LoaderPavinLoaderAmatera Stealer.

But a security expert with twenty years of experience in the section pushed back, recommending a complete system wipe and resetting all passwords. This type of malware typically drops copies of itself to self-restore after system reboots, so the safest course of action for any affected user remains reinstalling the operating system.

Compute black market fuels a new breed of crime

Hackers are not directly stealing credit cards but instead stealing AI compute—a reflection of the increasingly mature underground black-market logic of 2026. Due to regional restrictions and payment risk controls, users in many parts of the world cannot purchase official AI quotas even if they have the money. This massive supply-demand gap has spawned a lucrative market for "AI compute distribution and API relay stations."

Hackers integrate stolen session credentials into the backend of "clone websites," offering "unlimited chat" services to unsuspecting ordinary users at extremely low prices. More sophisticated operations generate API keys from stolen accounts and plug them into "relay API" sales platforms, charging developers on a per-token basis. The cost of goods for this business is zero, while the profit margin is 100%.

One user put it bluntly: "I suspect 99% of the 'free Anthropic model APIs' on the market are running on stolen credentials like these."

Anthropic has not yet issued a public statement, and the incident has not appeared on its status page.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.