OLKERIAI News
← All AI news
OLKERI · AI NEWS
Society & CultureGlobal2 September 20262 min read

By Olkeri.space

Anthropic says infostealer malware is draining Claude accounts

Commodity malware on users' own machines is lifting authenticated Claude sessions and burning paid usage — a theft that sidesteps two-factor authentication entirely, because the stolen token proves the login already happened.

Read this story in: Deutsch · Français · Español

Anthropic has warned that attackers are using commodity infostealer malware to lift active Claude login sessions from users' own computers and replay them to consume paid usage, according to reporting by BleepingComputer. The company named Vidar, LummaC2, StealC, RedLine and Acreed on Windows, along with Atomic Stealer on a small number of Macs.

The mechanism is worth being precise about, because it determines which defences work. These tools do not steal passwords. They steal the session cookie issued after a successful login — a token asserting that authentication has already happened. Two-factor authentication and single sign-on are therefore not so much bypassed as rendered irrelevant: the attacker never reaches a login screen. Rotating a password does nothing to a session already minted.

Anthropic says it has signed out affected sessions, removed stored payment methods to stop further unauthorised charges, and refunded confirmed fraudulent transactions. It has also stated the limitation plainly, which is to its credit: none of that removes malware from an infected machine, so a session created at the next login can be taken the same way.

What is new here is not the technique, which is years old, but the target. Infostealers have historically monetised banking credentials, crypto wallets and gaming accounts. An AI subscription now joins that list, because metered compute is a fungible resource with a resale market — a hijacked account is a way to run your workload on someone else's bill. That places AI accounts in roughly the same risk class as cloud credentials, and very few consumers treat them that way.

The uncomfortable part for every provider is that the compromise happens outside their perimeter. A vendor can shorten session lifetimes, bind tokens to a device, or alert on implausible travel, and several of those would help. None of them fix an infected laptop, and the industry has no better answer to that today.