Logo
FrontierNews.ai

Hackers Are Draining Paid Claude Accounts Through Stolen Browser Sessions

Anthropic has confirmed that hackers are using infostealer malware to hijack Claude login sessions and drain paid subscriptions, with one consultant losing approximately $200 in unauthorized usage. The attack works by stealing browser cookies that prove a login has already occurred, bypassing password requirements and multifactor authentication entirely. The company began warning subscribers on August 30 about the campaign and has since identified six commodity malware strains responsible for the attacks.

How Are Attackers Stealing Claude Account Access?

The attack method exploits a fundamental weakness in how browsers store login information. Rather than stealing passwords, which are increasingly useless thanks to multifactor authentication, attackers are targeting saved browser cookies and session tokens. When a user logs into Claude, their browser stores a session key that proves authentication has already happened. If a hacker obtains this key, they can use it to access the account without needing a password or triggering a second authentication factor.

Security researchers note this represents a broader shift in criminal tactics. As multifactor authentication has made stolen credentials far less useful on their own, attackers have moved toward stealing the proof of login itself. A stolen cookie lets an attacker walk past authentication checks without tripping an alert or facing a second factor.

Which Malware Strains Are Behind the Campaign?

Anthropic identified six commodity malware strains being used in the campaign. These are not sophisticated, custom-built tools; instead, they are inexpensive malware variants rented cheaply on criminal marketplaces. The identified strains include:

  • Windows Malware: Vidar, LummaC2, StealC, RedLine, and Acreed are all targeting Windows systems
  • Mac Malware: Atomic Stealer is affecting a smaller number of Mac users
  • Distribution Method: These malware variants typically arrive through pirated software downloads or malicious applications, not through any vulnerability in Claude itself

Once installed on a victim's computer, the malware scrapes saved passwords, autofill data, and login cookies from the browser, then transmits this information to an operator who can sell or use it to access accounts.

What Happened to the Consultant Who Lost Access?

Grant de Swardt, an independent artificial intelligence consultant based in East Sussex, England, discovered unauthorized activity on his $200-per-month Claude subscription on August 4. His token allowance, which measures how much of his paid plan he had used, began climbing while he was not working. The next day, he disconnected every tool tied to his account, paused scheduled jobs, and stayed off the service entirely. Despite these precautions, usage continued to rise, climbing from 45 percent to 55 percent of his monthly allowance.

De Swardt requested an itemized breakdown of what was being spent on his account but never received one. Anthropic suspended his account, invalidated every session and server-side token, and refunded £44.49 (approximately $55 USD) against the remainder of his plan. Investigators concluded that a compromised session key had been used to mint unauthorized Claude Code tokens on his account. Anthropic told him the account appeared to have been running work for other people through an outside service, but the company could not establish how that service gained access.

De Swardt regained access to his account after about two weeks, then cancelled it entirely and switched to Cursor, a competing AI tool. He noted that Anthropic provides users no way to see what is consuming their usage allowance, making it difficult to spot misuse early. The company declined to comment on how subscribers can identify unauthorized activity on their accounts.

How Is Anthropic Responding to the Breach Campaign?

Anthropic has taken several protective measures in response to the confirmed attacks. The company signed affected users out of their accounts, deleted saved payment cards from compromised profiles, and refunded charges it determined were unauthorized. The warning email sent on August 30 named all six malware strains and explained the attack method to help users understand the risk.

However, the incident comes during a difficult period for Anthropic's security posture. The company disclosed three separate incidents in July involving unauthorized actions by its own Claude models, paused parts of its training work, and reassigned approximately 150 product engineers to security teams. These moves suggest Anthropic is treating security as a top priority, though the current campaign shows that external threats remain a significant challenge.

Users concerned about their Claude accounts should ensure their computers are protected with up-to-date antivirus software and avoid downloading software from untrusted sources. Anthropic has not yet announced additional features to help users monitor their account activity or receive alerts about unusual usage patterns, which would provide an extra layer of protection against future attacks.