Anthropic has confirmed that hackers are actively stealing session tokens from Claude subscribers to hijack accounts and drain high-value AI credits. The campaign utilizes “infostealer” malware to harvest browser cookies, allowing attackers to bypass traditional security measures like passwords and multi-factor authentication (MFA).
The attack does not rely on a server-side breach of Anthropic’s systems. Instead, it targets individual users by deploying malware that captures session IDs from local browser files. Because these stolen tokens represent a session that is already logged in, the attackers can access the account without needing to provide credentials or solve an MFA prompt.
How Infostealers Bypass MFA
The campaign involves several well-known families of malware. For Windows users, security researchers have identified the use of Vidar, Lumma, StealC, RedLine, and Acreed. For macOS users, the primary threat is Atomic Stealer (AMOS). These tools are designed to search a victim’s machine for sensitive data, specifically targeting browser cookies related to high-value services.

Once the malware successfully exfiltrates a session token, the attackers can impersonate the user on Anthropic’s platform. This is particularly lucrative for hackers because many Claude subscribers pay for high-tier access. Reports indicate that users on the $200-per-month Claude Max 20x plan and those using “Claude Code,” a command-line tool for developers, are being specifically targeted. In one documented instance, an AI consultant noted a 10% spike in usage on his premium account during a period when he was not using the service.
Anthropic’s Response and Mitigation
Anthropic has acknowledged the issue and is taking steps to protect affected users. The company has begun forcing sign-outs for sessions identified as suspicious and is invalidating OAuth tokens associated with Claude Code. In some cases, Anthropic has also issued partial refunds.
According to research from Malwarebytes, this trend of “token-burning” is becoming a significant concern for AI providers, as stolen credits are often used to power third-party “wrapper” services or massive automated data-scraping operations.
A Transparency Gap in Usage Logs
While Anthropic is working to mitigate the attacks, the incident has highlighted a limitation in the platform’s current dashboard. While users can see their total credit balance or usage percentage, the system currently lacks the capability to provide itemized usage logs. This makes it difficult for subscribers to verify exactly when or how their credits were consumed, often leaving them to rely on sudden, unexpected drops in their quota as the only indicator of a compromise.
Subscribers who suspect their account has been accessed without authorization should clear their browser cookies immediately, which effectively kills any active sessions. Users are also encouraged to run a full system scan using reputable security software to ensure no residual malware remains on their hardware. As a broader precaution, security experts suggest avoiding the “Remember Me” or “Stay Logged In” features on sensitive accounts, as these persist the very session tokens that infostealers seek to harvest.
