ÉTAT HER

Login Sessions Hijacked by Info-Stealing Malware: What Really Drained Claude Usage

Malware on users' computers designed to steal information hijacked their Claude login sessions. In response, Anthropic emailed affected users last week, forcing account logouts, deleting saved credit cards, and issuing refunds.

Login Sessions Hijacked by Info-Stealing Malware: What Really Drained Claude Usage

If your Claude usage quota looked like it got refilled only to mysteriously get burned through again, an email Anthropic sent out last week has the answer: the problem wasn't your password or two-factor authentication—it was something in your browser called a session cookie that got stolen.

The email was first shared by a user on Reddit, and later reported by SecurityWeek. According to the letter, Anthropic has force-logged out all sessions on affected accounts, deleted saved credit cards, and refunded charges from the abnormal usage. The company also clarified that the root cause was info-stealing malware on users' own computers, not a breach of Anthropic's systems.

Anthropic has identified six malware families behind the incidents, including Vidar, Lumma, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on macOS. The company described the number of affected Mac users as "very small." None of these tools were designed specifically to target Claude—they're common generic info-stealers, typically bundled with malicious downloads. Once executed, they harvest passwords and cookies stored in the browser.

The key lies in what a session cookie actually does: once you log into Claude, your browser holds onto this credential so the system doesn't need to ask for your password every time you load the page. Once an attacker copies that cookie, they can simply pick up right where the victim's already-logged-in, already-2FA-verified session left off—no need to trigger a password prompt or two-step verification at all. That's exactly why the account password never leaked, yet the quota mysteriously got burned through.

Anthropic warns that a forced logout only cuts off the currently hijacked session—it doesn't remove the malware itself from the user's computer. The company's recommended order of operations: first remove the malware from your computer, then log back into Claude, set a new password for the linked email account and turn on two-factor authentication, and only after that re-add your payment method. Do the steps out of order, and the same malware could just intercept the new cookie generated by your fresh login.

The email didn't disclose the scale of affected accounts, and Anthropic has not yet responded to Engadget's request for comment.

Related

Anthropic Gives Users the Power to Rewrite What Claude Remembers Long-Term
Living

Anthropic Gives Users the Power to Rewrite What Claude Remembers Long-Term

With new granular controls rolled out by Anthropic, Claude users can now edit or delete memories by topic and decide whether sensitive information gets included at all.

What to know | Rugged Phone Hides an Action Cam: RugOne Xsnap 7 Pro's Camera Module Detaches with Magnets
Living

What to know | Rugged Phone Hides an Action Cam: RugOne Xsnap 7 Pro's Camera Module Detaches with Magnets

The key details: Ulefone's sub-brand RugOne unveiled the rugged Xsnap 7 Pro at IFA 2026, featuring a camera module on the back that can be fully detached and carried around as a waterproof action cam. Early-bird pre-orders open on Kickstarter September 7 at €799.

No Steering Wheel, No Problem: Tesla's Cybercab Now Officially Serving Riders in Austin
Living

No Steering Wheel, No Problem: Tesla's Cybercab Now Officially Serving Riders in Austin

Austin riders can now hail a ride via Tesla's Robotaxi app, though specifying a vehicle type isn't yet an option—among the 314-vehicle fleet, dominated by Model Ys, 45 are Cybercabs.

What to know | Boox Go 6 Gen II Review: The E-Reader That Runs Google Play, but the Battery Only Lasts Eight Days
Living

What to know | Boox Go 6 Gen II Review: The E-Reader That Runs Google Play, but the Battery Only Lasts Eight Days

The key details: The $200 Boox Go 6 (Gen II) runs Android, letting you install any reading app and use a stylus, but its battery life falls well short of Kindle and Kobo—and it's still stuck on Android 11, which has already lost security updates.

Samsung Devices Set to Gain Android's Scam Detection, With the Galaxy S26 Leading the Rollout
Living

Samsung Devices Set to Gain Android's Scam Detection, With the Galaxy S26 Leading the Rollout

Previously exclusive to Pixel phones, Google's AI-powered call scam detection is now confirmed to be coming to the Samsung Galaxy S26. Android's security toolkit also includes several often-overlooked features, such as updates, two-factor authentication, Find Hub, and anti-theft locks.

Can a Gimbal Fit in 9.6mm? Honor Robot Phone Pushes Physical Limits
Living

Can a Gimbal Fit in 9.6mm? Honor Robot Phone Pushes Physical Limits

To give the 200MP main camera three-axis stabilization, Honor developed its own 2.6-gram gimbal motor and hid it inside the phone's back cover. Available only in China as a limited run, this experimental device delivers a hands-on experience that sits between a standard phone and a dedicated gimbal camera.