Security1 distinct publisher2 min readPublished
Anthropic is signing affected users out, stripping saved payment methods and issuing refunds after someone began pulling Claude cookies out of ordinary stealer logs and spending other people's quota.
The Watch · Security desk

build
Anthropic asks court to give dataset identifiers source-code-level confidentiality protection1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
build
Perf work stopped being a specialist queue item, and slow endpoints became a choice1 distinct publisher
security
Washington names industrial-scale distillation, then hands the detection bill to abuse teams1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
The only tell Anthropic gave users is a billing curve: limits that refill and then drain while nobody is at the keyboard [4]. Session replay leaves that shape. A cookie sitting in a browser profile is a bearer token, and the password check and the second factor already cleared on the victim's own machine before the theft, so replaying the cookie skips both [5].
Cookie theft is old tradecraft, but the resale value of what gets stolen has shifted. Anthropic's read is that stealer operators collected everything and that a bad actor "has now started picking the Claude sessions out of what it collected and using them" [9]. That is a triage decision inside a log market. The same dump that gets sorted for banking and gaming credentials is now being sorted for metered AI capacity, and the account carries both a quota worth reselling and a card on file, which is why the company pulled saved payment methods rather than only killing the cookies [2].
The toolset here is entirely commodity malware. Anthropic names Vidar, LummaC2, StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs [6]: six families, five of them on one platform [14]. The company also says it has no reason to believe the malware is related to Claude or was installed through it [7].
The gaps in Anthropic's disclosure matter for scoping the exposure. The record here is Anthropic's own notification email, published by a recipient [16]. There is no number of affected accounts in it and no dates for when sessions were taken or replayed. It also does not say whether the intruder read conversation history or uploaded files; the impacts it addresses are usage, payment instruments and refunds [15]. Anthropic says the investigation is ongoing and that the affected machines were likely already infected with general-purpose stealers before any of this [11].
Order of operations is the operational part. Anthropic tells affected users to change credentials, revoke other sessions and clean the machine [13], and its own caveat explains why sequence decides the outcome: re-authenticating on a dirty endpoint mints a fresh cookie for the same thief [12]. For anyone running these subscriptions inside a company, the identity design has to assume the endpoint is the front door, which puts the weight on short session lifetimes and on a revocation path a helpdesk can trigger without waiting on a vendor ticket.
Ranked by verification strength, evidence, and original report placement.
Anthropic is warning some Claude users that infostealer malware on their PCs stole active Claude login sessions, allowing attackers to access the accounts and consume their usage.
Anthropic is signing affected users out of Claude, removing saved payment methods to prevent unauthorized purchases, and refunding charges it identifies as unauthorized.
The warning was delivered in an email Anthropic sent to an affected user who shared it on Reddit; the same email is being sent to other compromised account holders.
Anthropic told users: "If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause."
Anthropic said: "Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them."
Infostealers can copy an already authenticated browser session, which means the attacker may not need to go through the normal password and 2FA login process again.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor email, one newsroom
The substance is strong where it is quoted and weak where it is checked. Anthropic's email is reproduced at length, names six stealer families and describes the replay mechanism precisely, and the recipient volunteered the pirated-game detail that explains their own infection. But every line traces back to that single email as posted to Reddit, relayed by one outlet twice; no telemetry, malware report or second victim account appears anywhere in the reporting.
Live abuse, unstated scale
The abuse is not hypothetical — sessions are being replayed now, and Anthropic has already reached for account-level levers: forced sign-outs, saved cards removed, refunds processed. What cannot be measured is size. No account count, no time window, no distinction between consumer and managed tenants, and 'a small number of Macs' is the closest thing to a number in the whole account.
Framing tracks the email, volume does not
Slightly overstated, and the overstatement is structural rather than rhetorical. The prose is disciplined — 'Anthropic said', 'likely', 'investigation is ongoing' — but the same piece published twice makes a single unverified vendor notice look like a developing story, and the unbounded scope invites readers to fill in a number nobody has given. Pushing the other way, the genuinely underplayed part is the economics: stolen AI quota now being harvested out of ordinary stealer logs is a bigger idea than the account-recovery advice around it.
Vendor framing plus a sponsor slot
Two incentives sit in plain view. Anthropic's notice takes care to state three times over that the malware has nothing to do with Claude — true, most likely, and also exactly what a vendor wants on the record when its customers' sessions are being spent by strangers. And BleepingComputer's copy closes on a pitch for a commercial defence-testing report about credential abuse, the very theme of the story above it. Neither undermines the facts; both shape which facts got emphasis.
Enough to act on, not to size
Confident about mechanism, unconfident about magnitude. A defender can act today on what is here — assume cookie theft defeats your 2FA, rotate, clean the host — because that part is internally consistent and matches how these stealer families are known to work. Anything requiring a number, a date, or a statement about what else a replayed session could reach should wait for a second source, and so far there is no second source.