If your usage limit refills and then drains while you never touched Claude — this might be exactly why. Anthropic is currently warning affected users by email: an attacker is using common infostealer malware to steal active Claude logins from infected computers, then signing into other people’s accounts. Not to read data, but simply to burn through their usage.
The trick behind it is uncomfortably clever. Infostealers scrape locally stored data — browser passwords, login cookies, credentials from other apps. That haul includes the authenticated Claude session. And because an already logged-in browser session gets copied wholesale, the attacker never has to beat a password or a two-factor prompt. They’re just in.
Anthropic’s response is clear. Affected users get signed out of Claude, saved payment methods are removed, and charges the company identifies as unauthorized get refunded. The investigation is still running. But one thing is already settled: the origin isn’t Claude. “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the company writes. In one shared case, a user got infected through a pirated game.
The forensic trail turns up familiar names. On Windows there’s Vidar, LummaC2, StealC, RedLine and Acreed; on a smaller number of Macs, Atomic Stealer (AMOS). All standard, general-purpose malware, nothing AI-specific — Claude was just one of many things it grabbed, and someone is now deliberately picking the Claude sessions out of that stolen pile.
One point Anthropic makes plainly, and it matters: signing you out stops the stolen sessions, but it doesn’t remove the malware. If the infostealer is still sitting on your machine, your next session can get lifted the same way. Hence the advice: change your credentials, revoke other sessions, and clean the malware off properly.
For me this is less a Claude story than a good old hygiene reminder. Session cookies are worth real money the moment there’s a subscription or a balance behind the login — and AI accounts are a fresh, worthwhile target. The defense is unglamorous: no shady downloads, no cracked games, two-factor on, and a machine you can actually trust. That Anthropic proactively emails people and refunds charges here, instead of quietly sitting on it, is something I’ll give them credit for.
Sources: r/ClaudeAI