AI
2026-08-31
Some Claude users got a strange email from Anthropic this week. Malware on their computer had stolen their login session. Someone then used that session to drain their account. Anthropic says infostealer malware grabbed active Claude sessions straight off people's machines. Whoever took them logged in as those users and burned through their paid usage.
A stolen session is more dangerous than a stolen password. It skips login entirely. No email, no code, no prompt needed. The malware just copies a browser cookie. That cookie says the device is already signed in. It hands that cookie straight to an attacker. The same trick works on any website, not just Claude. Security researchers have watched infostealers grow more popular. One infected computer becomes a master key. It can unlock dozens of accounts at once. Anthropic hasn't said how many customers were hit. It also hasn't named which malware family did it.
Will Anthropic explain how the malware got in? Right now the fix is reactive. Sign people out. Refund the usage. Move on. The bigger question is different. Will AI companies start treating account security like banks do? That means device checks and session limits by default. Or will this keep happening, one drained account at a time?
This story is written by AI from the sources above, checked against them before publishing. If something here still reads wrong, tell us and we'll correct it.