Confirmed

Anthropic confirmed infostealers harvested local session cookies to drain paid quotas.

AI Safety

Anthropic blocks malware siphoning paid Claude accounts

Intruders stole browser session cookies to bypass security checks and burn paid computer power without hacking central systems.

Published
NRB — News Republic Brigade

Other links

Anthropic

In a nutshell

Computer malware operators compromised paid Claude subscribers by extracting active login passes from local browser databases, bypassing two-factor defenses to drain paid processing allowances and auto-reload credits without touching Anthropic's central systems. Anthropic stopped immediate exploitation by voiding open connections, removing saved payment methods, and reimbursing fraudulent charges. Long-term defense hinges on adopting hardware-tied security credentials across web platforms, while victims must eradicate local malware before updating passwords to avoid instant repeat theft.

Highlights

  • Anthropic initiated forced logouts and customer warnings on August 30, 2026, after spotting automated exploitation.
  • Attackers replayed stolen session cookies to bypass two-factor authentication and passwords entirely.
  • Intruders targeted automated billing systems to siphon compute capacity for cyberattacks and heavy model workloads.
  • Anthropic deleted saved payment methods from hijacked accounts and refunded unauthorized balance top-ups.
  • Security researchers cautioned that resetting account credentials before cleaning local devices allows malware to steal new sessions instantly.

From the Editor’s Diary

When authentication relies on local software files rather than physical hardware chips, account security is only as dependable as the endpoint device holding the key.

Who's involved

  • Anthropic

    San Francisco developer of the Claude AI system

    goal → Block platform exploitation, shield subscriber balances, and safeguard commercial standing

  • Cybercriminals / Infostealer Operators

    Financially motivated hackers deploying commodity information-stealing programs

    goal → Harness paid computer processing without paying artificial intelligence operating expenses

  • Affected Claude Subscribers

    Paying subscribers infected through compromised web downloads or illicit programs

    goal → Clear host infections, block recurring card charges, and recover subscription control

In short

TL;DR: Criminals infected subscriber devices to hijack active Claude sessions and consume paid artificial intelligence power without triggering passwords or two-factor security prompts. Anthropic intervened by revoking hijacked tokens, wiping saved billing methods, and issuing refunds.

Q: How did hackers access paid accounts without breaking Anthropic's servers?

- Intruders deployed common computer malware to steal browser cookie files stored locally on victim machines.

How it unfolded

01

Anthropic Issues Security Notifications to Infected Claude Users

2026-08-29 – 2026-08-29

Anthropic identified abnormal automated workloads across its network on August 30, 2026, prompting immediate account resets and warning dispatches to affected subscribers. Technicians notified users that malicious software installed on their computers had extracted browser session tokens to consume paid compute budgets.

1 source
02

Public Disclosure and Security Advisory Warnings

2026-08-30 – 2026-09-01

Account holders posted Anthropic's breach notifications to the discussion website Reddit, alerting independent cybersecurity analysts to the ongoing theft campaign. Technical inquiries showed that established software variants—including LummaC2, Vidar, StealC, RedLine, Acreed, and Atomic Stealer—were extracting database files from desktop browsers, enabling outsiders to exhaust auto-renew billing limits without alerting security tools.

3 sources

Where things stand

Anthropic halted immediate financial losses by voiding active digital passes, deleting customer payment profiles, and refunding unauthorized credit top-ups. The core vulnerability persists because web browsers continue to handle authentication credentials through standard cookie structures on personal devices.

Permanent protection depends on wider industry rollout of Device Bound Session Credentials, which tie web logins directly to a computer's physical security chip. In the meantime, analysts caution that users who update passwords before cleaning their operating systems will have their replacement passes stolen immediately.

Sources

  • Gblockincident writeup · 2026-09-01