Anthropic, the company behind the Claude assistant, has warned some users about information-stealing malware (an “infostealer”) that hijacks their login sessions. The attackers’ goal is not to read your chats but to take over accounts and burn through their AI usage quota, which can lead to extra charges.
What happened
According to an alert email shared by a Reddit user, a threat actor is “using a common infostealer to steal Claude login sessions from users’ computers, then using those sessions to access Claude accounts and exhaust their usage limits.” A tell-tale sign, Anthropic notes, is usage limits that appear to refill and then drain while you are not using Claude.
Which malware, and which devices
The campaign relies on well-known infostealer families: Vidar, Lumma, StealC and RedLine on Windows, plus Atomic Stealer on a “small number of Macs.” There is currently no evidence that phones or tablets are affected. These tools quietly harvest saved credentials, browser data, financial details and crypto wallets, and AI-platform sessions are now on that target list too.
What Anthropic did
Anthropic logged out affected users and deleted their stored payment information as a precaution, and says it is refunding usage charges that appear to be unauthorized. The company stresses it has “no reason to believe this malware is related to Claude” or was installed through it, the infection comes from the user’s own device.
How people got infected
In most reported cases the source was pirated software. The original Reddit poster acknowledged the likely culprit was a cracked game. This matches a long-standing pattern: downloading pirated, illegal or license-bypassed software puts your privacy, security and devices at risk.
What to do right now
- Remove any recent, suspicious or pirated software from your computer.
- Run a full malware scan of your system to find and remove any infostealer.
- Sign back in to Claude and re-enter your payment details (affected users were logged out).
- Review your billing, and contact Claude support if you see unusual charges that were not refunded.
- Consider changing your password and enabling multi-factor authentication after your device is clean.
The takeaway
AI accounts are now a target for the same credential-theft malware that has long chased banking logins and crypto wallets. Keeping your device clean, and avoiding pirated software, is the first line of defense for your Claude account.
Source
Reporting: ZDNET, 7 September 2026. This is an informational summary, not security advice tailored to your situation.