Product1 distinct publisher3 min readPublished
The company told affected customers by email, with nothing on its status page, and the only symptom on the user's side was usage that refilled and drained on its own. Watching that burn is now the account holder's job.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
Anthropic's email to affected customers says the giveaway was a usage limit that appeared to refill and then drain while the owner had not opened Claude at all [4]. For one person on one account, that is a workable signal. Spread across a team's seats, the person who notices a curve like that is whoever owns the curve, and on most teams nobody owns it.
What got taken was a cookie. A session is proof that you already signed in, it sits on the machine, and whoever copies it never runs the login again, so the password prompt and the second factor are never reached [10]. Anthropic says the same malware also collects saved passwords and credentials belonging to other apps running locally, and the Claude session was one item among many that it picked up [11]. The email is public only because a recipient posted it in the r/ClaudeAI forum [2].
Both of Anthropic's steps sit on Anthropic's side of the boundary. The sign-out cancels the stolen session everywhere, which is why affected users had to log in again on all of their own devices [13]. The card deletion means Claude can no longer charge that payment method, while the plan already paid for runs to the end of the billing period [14]. The line in the email that matters most for anyone doing cleanup is the one about reach: "Signing you out stops the stolen sessions, but it doesn't remove the malware" [17]. One recipient pointed Claude Opus at his own machine to find and shut the malware down, and a commenter who said he had twenty years in security recommended wiping the system and resetting every password, because this class of malware routinely drops copies that restore it [18].
The named families say something about who is exposed. Anthropic lists five stealers on Windows plus Atomic Stealer on a small number of Macs, six families across two operating systems [6][7], and says the software typically arrives with an unofficial download or a malicious app rather than through Claude [8]. Phones and tablets do not appear to have been involved [9]. One affected user had installed a pirated game, and Windows Defender did not react [12]. The exposed surface is a personal laptop with a browser profile on it.
Login protects the spend, or so the comfortable account of AI account security goes. Here, the login was completed once by the legitimate user, then copied and spent by someone else [1].
Two axes are worth drawing over your own paid seats. First, where the first signal comes from: a vendor email, or your own usage and billing telemetry. Second, how far remediation reaches: the vendor can revoke a session and detach a card [3], and cannot touch the machine the cookie came from [17]. The bad cell is vendor-email detection paired with account-only remediation, which is where the affected accounts sat, and the only cell you can move yourself is the first one.
That leaves the money. BleepingComputer reports that Anthropic is also refunding charges it identifies as unauthorized [15]. The verb carrying the weight there is "identifies": a team with its own record of what was consumed and when has something to bring to that conversation, and a team without one accepts the vendor's arithmetic.
Ranked by verification strength, evidence, and original report placement.
Anthropic told affected customers in an email: "We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage."
The Anthropic email became public because an affected customer posted it in the r/ClaudeAI forum.
Anthropic signed affected users out and removed the payment method stored on their accounts; anyone who wants to carry on has to log back in and add a card again.
According to Anthropic, the giveaway was usage that appeared to refill and then drain while the owner had not opened Claude at all.
No public statement from Anthropic exists so far, and the incident does not appear on Anthropic's status page.
Anthropic names Vidar, Lumma (LummaC2), StealC, RedLine and Acreed on Windows, plus Atomic Stealer on a small number of Macs.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Commodity infostealers are now cashing out stolen Claude sessions1 distinct publisher
product
Claude has no MFA, so your inbox is the entire login1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
science
Claude's watermark is a compliance artefact, not a cheating detector1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One leaked email, one outlet
Trace any fact in this story back far enough and you arrive at the same place: a support email a Claude user pasted into r/ClaudeAI, which Notebookcheck then read out. The quoted wording is specific and internally consistent — named stealer families, the refill-then-drain tell, the two-step remediation — but Anthropic says none of it in public, the status page shows nothing, and the single detail from beyond that chain, the refunds, arrives as Notebookcheck citing BleepingComputer rather than as reporting anyone can inspect.
Concrete actions, undisclosed footprint
The response is not hypothetical: sessions were killed, stored cards were removed, and at least one account holder describes signing back in across his devices. What is entirely absent is size — no count of affected accounts, no start date for the abuse, no split between Windows machines and the 'small number of Macs'. We can see the shape of Anthropic's action and not its reach.
Headline verbs outrun a scope nobody published
'Wipes saved cards' is faithful to the email and still larger than what is known, because a notice sent to some customers reads, once aggregated, like a platform-wide event. Notebookcheck itself resists that drift — it flags the missing status-page entry and lets Anthropic's disclaimer about the malware's origin stand — so the overstatement is structural rather than editorial.
The email is doing two jobs at once
Anthropic's note is remediation and reputation management in the same breath: the assurance that there is 'no reason to believe this malware is related to Claude' may well be correct and is also the sentence a vendor most wants quoted. Detaching cards limits fraudulent spend the company would otherwise be refunding. On the publishing side, Notebookcheck threads readers to its own prior session-theft explainer and its ChatGPT piece — routine, but part of why those references are thin.
Plausible mechanics, unconfirmed event
The technical core is the least doubtful part: cookie replay skipping a second factor is well understood, and the families named are the ones that turn up in this kind of theft. What keeps the number mid-range is that one outlet is reading a private email aloud with the company on record nowhere, and the detail users most need — that an infected machine will keep surrendering fresh sessions — is Anthropic's own caveat rather than anything checked from outside.