Anthropic cracks down on hijacked user accounts mining AI tokens
Rather than paying for their own Claude usage, crims are using malware to steal access to other people's accounts.
Aware of this issue, Anthropic has signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused.
According to an email shared by Reddit user WorriedAssociate7029, who sent a copy to The Register, Anthropic has been keeping an eye on a threat actor using infostealer malware to hijack Claude login details, session cookies, and other info needed to subvert multifactor authentication on user accounts.
Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves.
Fortunately for WorriedAssociate7029, Anthropic logged the user out of their account and deleted their stored payment method because it had detected evidence of attempted fraud.
“A few days ago, my social media accounts were hacked,” WorriedAssociate said, adding that they'd managed to track the malware down with the help of Claude Opus 5 Max and, they believe, cleaned the system.
“But last night I received this email from Anthropic warning me of an attempt to steal tokens via the API.” They explained that the attempt failed, apparently thanks to Anthropic spotting it, but they realized that meant that the cybercriminal behind the incident seemed to have hijacked Google account credentials, cookies, and session IDs as well, since that’s how they were signed into Claude.
After changing their password again and removing all active sessions, it appears they are now safe.
Who’s eating your cookies? Anthropic made clear in the email that the credential theft wave it’s identified has nothing to do with Claude itself, nor is it some sort of fancy, new-fangled, agentic AI malware that’s being used to create a base of accounts for bad actors to abuse.
This is just good old-fashioned infostealer malware being turned to a new purpose, the email explains.
“We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the email forwarded to us by WorriedAssociate and posted to Reddit stated.
“Your Claude session was likely one of the many things it collected.
It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them.” In this case, it’s well-known infostealing malware too: Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer have all been fingered by Anthropic as being used to steal Claude credentials, sessions, and cookies.
As for WorriedAssociate, they copped to making a noob mistake that led to their infection.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.