
If you use Claude and noticed your usage limits mysteriously draining without any activity on your end, here’s why: attackers used infostealer malware to steal browser session cookies from users’ machines and then quietly used those hijacked sessions to run up API usage on someone else’s dime. Anthropic has now warned affected customers directly, signing them out of compromised sessions and stripping saved payment methods from their accounts as a precaution.
The malware families involved are not new or exotic. Vidar, Lumma, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a small number of macOS machines, are all well-documented infostealers that have been circulating for years. They typically arrive through unofficial software downloads or malicious apps, then silently copy saved passwords, browser cookies, and credentials stored locally. Anthropic was quick to point out that none of this malware targets Claude specifically. That’s true, but it doesn’t make the situation less serious for the people affected.
What happened here follows a familiar pattern in credential theft. Attackers cast a wide net with infostealer campaigns, collect enormous batches of stolen session data, and then sift through it for anything valuable. Claude accounts with active subscriptions and stored payment methods clearly made the cut. The attacker would have had full session access, meaning no password needed, just a stolen cookie dropped into a browser.
Anthropic’s response included several concrete steps:
- Logging out all identified compromised sessions
- Removing saved payment methods from affected accounts
- Issuing refunds for charges identified as unauthorized
- Warning users they may be logged out again if further misuse is detected
The refunds are a reasonable gesture. But the removal of payment data cuts both ways. Yes, it stops unauthorized charges. It also means affected users have to re-enter their payment information, which creates its own risk if those users haven’t yet cleaned their machines. Anthropic addressed this directly, telling victims to only add a payment method back after confirming all malware has been removed. That’s solid advice. Whether every user will actually follow that process carefully is a different question.
This incident fits into a broader and growing problem. As AI platforms become more financially valuable, with paid tiers, API credits, and enterprise accounts, they become more attractive targets for exactly this kind of credential harvesting. The attackers didn’t need to break Anthropic’s infrastructure at all. They went after the weakest point: user devices running consumer-grade security. So even if Anthropic’s own systems are well-protected, its users’ machines may not be.
The bigger takeaway is that any platform handling recurring payments and session-based authentication is now a target worth pursuing through infostealer campaigns. Anthropic handled the response reasonably well. But users should treat this as a reminder that browser-stored credentials are a persistent liability, not a safe convenience.