Particle.news

Anthropic Revokes Claude Sessions After Malware Steals Authenticated Browser Cookies

Anthropic says revoking those sessions prevents attackers from replaying stolen cookies to run up paid usage while its investigation and refunds continue.

Overview

  • Anthropic began notifying affected Claude users on Aug. 29–31 after its systems detected accounts refilling and then draining in ways consistent with session replay from infected devices.
  • The company signed compromised users out of Claude, removed saved payment methods from those accounts, and issued refunds for charges it identified as unauthorized.
  • Anthropic traced the hijacks to common infostealer families that harvest browser cookies and credentials, naming Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer (AMOS) on a small number of Macs.
  • Evidence in at least one reported case links an infection to a pirated-game download and Anthropic stressed the malware originated on user devices rather than through Claude itself.
  • Anthropic urges victims to fully remove malware, change email and saved passwords, revoke other active sessions, and only re-add payment methods after cleaning devices because server-side fixes do not disinfect endpoints.