Overview
- Anthropic began notifying affected Claude users on Aug. 29–31 after its systems detected accounts refilling and then draining in ways consistent with session replay from infected devices.
- The company signed compromised users out of Claude, removed saved payment methods from those accounts, and issued refunds for charges it identified as unauthorized.
- Anthropic traced the hijacks to common infostealer families that harvest browser cookies and credentials, naming Vidar, LummaC2, StealC, RedLine, Acreed on Windows and Atomic Stealer (AMOS) on a small number of Macs.
- Evidence in at least one reported case links an infection to a pirated-game download and Anthropic stressed the malware originated on user devices rather than through Claude itself.
- Anthropic urges victims to fully remove malware, change email and saved passwords, revoke other active sessions, and only re-add payment methods after cleaning devices because server-side fixes do not disinfect endpoints.