Infostealer Malware Is Hijacking Claude Browser Sessions to Drain Usage Limits, Anthropic Warns
Five named Windows malware families and one macOS variant began appearing in Anthropic's session logs as unauthorized consumers of Claude usage limits. On August 30, 2026, Anthropic warned affected users that attackers had stolen active browser sessions from compromised computers and used them to exhaust subscription quotas without entering passwords or two-factor codes, per BleepingComputer.
What happened
Anthropic identified six infostealer variants behind the attacks: Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on a smaller number of Mac systems. These families are general-purpose tools built to harvest locally stored browser credentials, cookies, and session tokens. Attackers extract valid Claude session cookies from the stolen data and authenticate as the victim without triggering any login prompt.
The mechanism bypasses passwords and MFA entirely because it reuses an already-authenticated session rather than attempting a new login. Anthropic told affected users: "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause."
In response, Anthropic signed affected accounts out of Claude, removed saved payment methods from those accounts, and issued refunds for charges it identified as unauthorized.
Why it matters
Session-token theft is not a new technique, but this incident marks a public confirmation that AI subscription quotas now rank as a target worth harvesting. For any team running Claude on a shared or personal computer that may be compromised, a sudden unexplained usage drain is now an indicator of account takeover, not a billing anomaly.
Anthropic noted that the malware is not related to Claude, was not installed through Claude, and was not caused by anything the user did on the Claude platform itself. For operators doing incident response, that means the attack surface is the local browser and operating system. Teams should assess endpoint hygiene rather than assume a breach on the Claude side.
A practical gap remains: the default Claude account model has no hardware-key or passkey option. Stolen session cookies remain valid until Anthropic expires them on the backend. Rotating passwords does not help because the attacker reuses the cookie, not the password. Until passkey support arrives, the only reliable mitigation is keeping the endpoint clean in the first place.
Context
The six named infostealer families typically arrive through unofficial software downloads or malicious applications, per BleepingComputer. They have long targeted banking credentials, gaming accounts, and SaaS tokens. Claude accounts carry a concrete asset: prepaid usage capacity and linked payment methods, making them a logical addition to the infostealer target list.
Anthropic's response, covering proactive notification, forced session termination, and refunds, per Search Engine Journal, sets a response benchmark other AI platforms will be measured against when similar incidents surface. The same infostealer families are known to target a wide range of SaaS platforms, so ChatGPT and Gemini accounts face the same underlying exposure.
What to watch next
Watch for Anthropic to add hardware key or passkey support to Claude accounts. A passkey requires local hardware verification at each new login, so a stolen session cookie cannot produce a fresh authenticated session from an attacker's machine. Whether other AI platforms issue similar infostealer warnings in the near term is the next signal to track.
Sources
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage: BleepingComputer, August 30, 2026 (primary)
- Anthropic Warns Hackers Are Stealing Claude Sessions To Hijack Accounts: Search Engine Journal, August 30, 2026 (secondary)
