According to recent information shared by users on Reddit, Anthropic recently initiated emergency security protocols. The company began sending urgent security warnings to selected Claude users. Furthermore, Anthropic forcibly deleted linked payment methods and terminated active login sessions for these accounts. The company detected malicious actors actively utilizing info-stealing malware to extract active Claude sessions directly from victim computers. Attackers subsequently exploit these stolen sessions to access accounts, deplete Claude usage quotas, and even generate fraudulent charges.
The Threat of Stolen Session Credentials
Anthropic’s internal investigation revealed a disturbing trend. The affected computers had previously suffered infection by generic info-stealing malware. This insidious software meticulously harvests saved passwords, authentication cookies, active Session IDs, and various other application credentials stored within web browsers. Currently, active Claude login sessions have become a highly prioritized target for these attackers.
Bypassing Multi-Factor Authentication
Because the attackers acquire a fully authenticated, valid session token, they bypass standard security measures. They do not need to re-enter the account password or navigate Multi-Factor Authentication (MFA) prompts. Consequently, even if a user logs into Claude using a secure Google account fortified with MFA, the attacker can still seamlessly hijack the existing session if the browser token is compromised.
Users should remain vigilant regarding their usage quotas. If a user notices their Claude quota suddenly exhausting rapidly despite inactivity, account compromise is highly probable. Users must immediately install reputable antivirus software and conduct a comprehensive system scan. This precaution is especially critical for individuals who recently downloaded software activation tools or pirated games.
Multiple Malware Families Identified
Within their notification emails, Anthropic specifically identified several malware families targeting the Windows platform. These dangerous threats include Vidar, Lumma/LummaC2, StealC, RedLine, and Acreed. Additionally, they noted a smaller number of Mac devices compromised by the Atomic Stealer malware. However, the Windows platform unequivocally remains the primary battlefield for these credential theft operations.
No Breach of Claude Infrastructure
Anthropic explicitly emphasized a crucial point. These malware infections do not originate from the Claude application itself. Furthermore, absolutely no evidence suggests any breach of Claude’s internal infrastructure. Users typically acquire these malicious programs from unofficial software repositories, cracked software distributions, or disguised malicious applications. Ultimately, the Claude session token represents merely one specific target among many credentials stolen during the infection.
Immediate Remediation and Account Recovery
Anthropic implemented decisive action regarding accounts exhibiting anomalous activity. They forcibly terminated all associated sessions, rendering the stolen tokens immediately invalid. Simultaneously, Anthropic unlinked any payment methods previously attached to these compromised accounts. This proactive measure effectively prevents attackers from incurring further unauthorized charges. Anthropic also pledged to proactively refund any confirmed fraudulent consumption occurring during the unauthorized access period.
Crucial Post-Infection Steps
However, simply terminating the Claude session does not eradicate the underlying Trojan virus from the infected computer. If the malware persists on the system, it will relentlessly steal new credentials the next time the user logs in. Therefore, a comprehensive system scan using robust antivirus software is absolutely mandatory. Following the successful removal of the malware, users must urgently update their account email address, change their password, and immediately enable MFA to significantly enhance their overall security posture.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!