Update: Anthropic confirms Claude session theft, is refunding users

Infostealer malware lifts your logged-in cookie and drains your plan — no password, no 2FA needed. What Anthropic is doing, and how to lock your account down.

Nowline SEP 9 2:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • What Anthropic confirmed

    Anthropic says a bad actor is using common infostealer malware to lift Claude login sessions off people's machines and burn their usage — "not caused by using Claude," but picked up from infected software or malicious ads. One Max user watched his usage climb 45%→55% during a window where he ran nothing; another went 0%→100% in 30 minutes.

  • Why 2FA didn't save them

    The theft grabs your active session cookie straight from the browser — cryptographic proof of an already-completed login — so it sails past passwords and MFA entirely. This is device compromise, not a Claude breach: if your machine has an infostealer, your Claude session (and every other logged-in site) is exposed.

  • What Anthropic is doing

    Anthropic is signing out affected users, invalidating existing sessions and authorizations, and refunding the unused portion of drained plans. The gap: it still won't hand users itemized usage logs, so catching misuse yourself is hard — watch your usage percentage for jumps you didn't cause.

  • Lock it down now

    If you see unexplained usage, clean the host first: disconnect it, run a full malware scan, and confirm the infostealer is gone. Then "sign out of all devices" to kill stolen tokens, reset your password, re-check 2FA plus recovery email/phone, and audit browser-saved cards. Report drains to usersafety@anthropic.com.