Infostealer Malware Used to Hijack Claude Sessions and Drain Usage Limits
Attackers bypassed MFA by stealing session cookies to consume subscriber token allowances across Claude's interfaces.
Attackers are using common infostealer malware to hijack Claude login sessions and drain the usage limits of paying subscribers. The campaign targets active session cookies on users' computers, allowing bad actors to bypass passwords and multi-factor authentication (MFA) entirely.
According to reports from TechCrunch and Engadget, the attackers utilized a variety of known infostealer tools, including Vidar, Lumma, StealC, RedLine, Acreed, and AMOS. Once these tools compromised a user's machine, the hackers replayed stolen session cookies to gain unauthorized access to accounts. This access allowed them to consume usage limits across multiple interfaces, including claude.ai, Claude Desktop, and Claude Code.
The Mechanics of the Attack
Unlike a traditional breach of a company's central servers, this attack does not stem from a vulnerability within Claude's own infrastructure. Instead, it leverages a post-authentication vulnerability: the session cookie. By stealing the token that tells a website a user is already logged in, attackers can step directly into an active session without needing a password or a second-factor code.
Anthropic confirmed the activity in emails to users, stating that "bad actors" were using common malware to steal login sessions from computers to access accounts and consume usage. The issue gained visibility after users noticed their token allowances disappearing rapidly while they were inactive, leading to wider discussions on GitHub and Reddit.
Industry Implications
This incident underscores a growing risk for high-value AI subscriptions. As professional users rely more heavily on LLM token allowances for their workflows, these quotas become a target for theft and resale. The attack also highlights a critical transparency gap; the current lack of itemized, real-time token usage tracking makes it difficult for subscribers to detect theft as it happens.
For the broader industry, the breach serves as a reminder that session-based authentication remains a weak point. Even with robust MFA in place, the local storage of session keys on a compromised device provides a direct path for attackers to bypass perimeter security.
Anthropic's Response
In response to the hijackings, Anthropic has taken several remedial steps to secure affected accounts. The company forced sign-outs of compromised sessions to invalidate the stolen cookies and removed saved payment cards from affected accounts to prevent further fraudulent activity. Additionally, Anthropic has issued refunds for fraudulent charges incurred during the attacks.
Users are encouraged to scan their systems for infostealer malware and monitor their account activity. While Anthropic has invalidated the known compromised sessions, the persistence of infostealer malware on a user's device means new sessions could be compromised immediately after a user logs back in.