Key Takeaways
- Hackers are stealing Claude AI login sessions using general-purpose "infostealer malware" installed on users' computers.
- This malware bypasses traditional security measures like passwords and multi-factor authentication by stealing active browser cookies.
- Anthropic, Claude's developer, is proactively signing out compromised accounts, removing payment methods, and refunding unauthorized charges.
- Users must clean their infected devices of malware, strengthen account security, and be vigilant against suspicious downloads to prevent future attacks.
The digital landscape is constantly shifting, and with the rise of powerful AI tools, new security challenges are emerging. A recent incident involving Anthropic's popular AI assistant, Claude, highlights a concerning trend: hackers are actively targeting AI users to steal valuable "tokens" and gain unauthorized access to premium services. This isn't a direct breach of Anthropic's systems, but rather a sophisticated attack leveraging general-purpose malware on users' own devices. The company has since issued a warning, urging subscribers to take immediate action to protect their accounts.
The Discovery: Unexplained Token Consumption
The alarm was first raised when a Claude user noticed a peculiar issue: their account was consuming tokens even though they weren't actively using the AI. This kind of unexplained usage is often the first sign of unauthorized access, and in the world of AI, where every interaction can cost "tokens" (which translate to real money), it's a critical red flag. The user's observation quickly led to a broader investigation, revealing a more widespread issue.
Anthropic, the San Francisco-based AI research and development company behind Claude, confirmed that hackers were indeed compromising user accounts. Their investigation pointed not to a vulnerability within Claude's own infrastructure, but to "infostealer malware" secretly operating on users' personal computers.
How the Hackers Are Operating: The Infostealer Threat
Infostealer malware is a malicious software designed to secretly collect sensitive information from an infected computer and send it back to the attackers. In this particular campaign, the malware isn't trying to guess passwords or exploit weaknesses in Anthropic's platform directly. Instead, it's stealing active browser cookies and session IDs.
Think of it this way: when you log into a website, your browser often saves a "cookie" that acts as a digital key, keeping you logged in for a certain period. This means you don't have to enter your password every time you visit the site. The infostealer malware steals these keys. Once an attacker has these session cookies, they can effectively "replay" your authenticated session, gaining access to your Claude account without needing your password or even bypassing multi-factor authentication (MFA). This makes the attack particularly insidious, as traditional security layers are circumvented.
Anthropic's investigation has identified several common infostealer malware strains involved, including Vidar, Lumma (LummaC2), StealC, RedLine, and Acreed on Windows systems. For macOS users, Atomic Stealer (AMOS) has been observed. Crucially, Anthropic clarified that this malware is general-purpose and not specific to Claude; it typically spreads through unofficial software downloads or malicious applications.
Anthropic's Swift Response and User Warnings
Upon detecting the unauthorized activity, Anthropic took immediate steps to protect its users. The company has been proactively signing out affected accounts from all active sessions, revoking the stolen tokens, and removing any saved payment methods on file. Furthermore, Anthropic is issuing refunds for any unauthorized charges identified as a result of the theft.
In communications sent to affected users, Anthropic stressed the importance of addressing the root cause: the malware on the user's device. "Signing you out of Claude stops the stolen sessions, but it doesn't remove the malware," the company warned. This means that if the malware remains on a user's computer, any subsequent login session could also be compromised. Users are strongly advised to clean their devices of the malware before logging back into Claude and re-adding payment details.
Understanding Claude and Its Value
Claude is Anthropic's flagship family of large language models (LLMs) and a powerful AI chatbot. Developed by a team of former OpenAI researchers, including siblings Dario and Daniela Amodei, Anthropic was founded in 2021 with a strong emphasis on AI safety and responsible development. Claude models, such as Opus 4.7, Sonnet 4.6, and Haiku 4.5, are known for their advanced reasoning capabilities, long-context processing, and design to provide cautious and ethical responses.
For individuals and businesses, Claude offers a range of subscription plans, each providing access to different levels of usage and features. These include a Free tier, Claude Pro ($20/month or $17/month annually), Claude Max (offering 5x or 20x Pro usage capacity at $100-$200/month), and Team plans (Standard at $25/seat/month, Premium at $125/seat/month, with a five-seat minimum). Enterprise-level custom pricing is also available. These paid tiers grant users increased access to the AI's capabilities, including features like Claude Code for developers, research modes, and integrations with productivity suites. The "tokens" that hackers are stealing represent this valuable usage capacity, making them a direct financial target for cybercriminals.
Broader Implications for AI Security
This incident with Claude is more than just an isolated event; it underscores a growing and evolving threat landscape for AI services. As AI tools become more integrated into daily work and personal lives, the accounts associated with them become increasingly attractive targets for hackers. Stolen AI tokens, premium access, or even the ability to misuse powerful AI models can be financially lucrative for cybercriminals, either through direct resale or by using the AI for other malicious activities, such as generating phishing emails or creating malicious code.
The use of infostealer malware to bypass MFA is particularly worrying. While MFA is generally considered a strong defense, attacks that steal active session cookies demonstrate that even this layer can be circumvented if the user's device itself is compromised. This highlights the critical need for comprehensive endpoint security.
Furthermore, AI itself is now being leveraged by hackers to make their attacks more sophisticated. AI-powered phishing attacks, for example, can generate highly personalized and grammatically flawless messages, making them much harder to detect than traditional scams. This means users can no longer rely solely on spotting typos or awkward phrasing as indicators of a scam.
Protecting Your AI Accounts and Digital Footprint
Given the increasing sophistication of cyber threats targeting AI accounts, users must adopt robust security practices. Here are key recommendations:
- Implement Strong, Unique Passwords: Even though session hijacking can bypass passwords, strong and unique passwords for all accounts remain a fundamental defense. Use a mix of letters, numbers, and symbols, and aim for passwords longer than 15 characters. Never reuse passwords across different services.
- Enable Multi-Factor Authentication (MFA) Everywhere: While session stealing can bypass some MFA implementations, it still adds a crucial layer of security. Ensure MFA is enabled on your Claude account and all other critical online services, including email. Authenticator apps or hardware tokens are generally more secure than SMS-based MFA.
- Keep Software and Operating Systems Updated: Regular updates often include security patches that fix vulnerabilities attackers could exploit. Ensure your operating system, web browser, and all applications are always up to date.
- Use Reputable Antivirus/Anti-Malware Software: Install and maintain a high-quality antivirus or anti-malware solution on all your devices. Regularly scan your system for threats. This is critical for detecting and removing infostealer malware.
- Be Wary of Suspicious Downloads and Links: Infostealer malware often comes bundled with unofficial software, pirated content, or malicious apps. Exercise extreme caution when downloading anything from untrusted sources. Be suspicious of unexpected emails, messages, or pop-ups, and avoid clicking on unfamiliar links.
- Consider a Password Manager: A password manager can help you create and store strong, unique passwords for all your accounts, reducing the risk of credential stuffing attacks and making it easier to follow best practices.
- Monitor Account Activity: Regularly check your AI service usage logs and billing statements for any unusual activity. Unexplained token consumption, as initially reported by the Claude user, is a clear sign that something is wrong.
Industry Reaction and The Path Forward
The incident serves as a stark reminder that as AI capabilities advance, so too must cybersecurity defenses. Companies like Anthropic are actively working to secure their platforms and inform users, but the responsibility also falls on individual users to protect their own devices and digital hygiene. The increasing value of AI resources means that these types of attacks are likely to become more common and sophisticated.
The AI industry, already grappling with ethical considerations and safety guidelines, now faces an amplified need for robust security frameworks. This includes not only securing the AI models themselves but also the access points and user accounts that interact with them. As AI continues to integrate into critical systems, incidents like the Claude token theft will drive further innovation in cybersecurity, pushing for more resilient authentication methods and advanced threat detection capabilities.
Conclusion
The theft of Claude tokens by infostealer malware is a clear signal that AI users need to elevate their cybersecurity vigilance. While Anthropic has responded swiftly to mitigate the impact for affected users, the underlying threat on personal devices remains. By understanding how these attacks work and implementing strong security practices, users can better protect their valuable AI resources and contribute to a safer digital environment for everyone.
Frequently Asked Questions
What exactly is "infostealer malware" and how does it steal Claude tokens?
Infostealer malware is malicious software designed to secretly extract sensitive data from an infected computer. In the case of Claude tokens, this malware steals active browser cookies and session IDs. These are small pieces of data that keep you logged into websites. By stealing them, hackers can bypass your password and multi-factor authentication (MFA) to access your Claude account, making it seem like a legitimate login session.
Is the Claude AI platform itself vulnerable to this attack?
No, Anthropic has stated that there is no evidence of a breach within their own infrastructure or any new, AI-specific malware. The infostealer malware is general-purpose and originates from the user's own computer, often downloaded through unofficial sources or malicious apps, not through Claude itself.
What steps has Anthropic taken to protect users, and what should affected users do?
Anthropic is proactively signing out compromised sessions, revoking stolen tokens, removing saved payment methods, and refunding unauthorized charges. Affected users must clean their infected devices of the malware using reputable antivirus software. After cleaning their device, they should reset their email and Claude passwords, enable strong multi-factor authentication, and only then re-add payment information.
How can I protect my AI accounts from similar attacks in the future?
To protect your AI accounts, use strong and unique passwords for all services, enable multi-factor authentication wherever possible, keep your operating system and software updated, use reputable antivirus/anti-malware software, and be extremely cautious about suspicious downloads or links. Regularly monitor your account for any unusual activity or unexpected token consumption.



