Anthropic is warning some Claude users that infostealer malware copied their active login sessions and let an attacker consume account usage without signing in again. A telltale pattern is a usage limit that refills and then drains while the owner is not using Claude. This is an endpoint-malware incident, not evidence that Anthropic’s infrastructure was breached [1].
A stolen authenticated session can be useful even when the attacker does not know the password and cannot complete a new two-factor authentication challenge. Signing the account out stops the copied session, but it does not remove the infostealer. Logging in again on the same infected computer can expose the replacement session.
What Anthropic found
The warning, reported from emails sent to affected users, says attackers selected Claude sessions from data already collected by common infostealers. Anthropic named Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on a smaller number of Macs. These families can collect browser passwords, login cookies, and credentials for other applications, so Claude may be only one exposed account [1].
Anthropic said it was revoking compromised sessions, removing saved payment methods, and refunding charges it identified as unauthorized. The company also stressed that it had no reason to believe the malware came from Claude. Downloads, unofficial software, pirated games, fake installers, and other malicious applications remain more plausible infection paths.
Does unexplained Claude usage prove malware?
No. Claude usage can also come from a browser, desktop or mobile app, Claude Code authorization, an organization account, or another legitimate session that was left open. Start with the account evidence and treat an official Anthropic infostealer notice or an unfamiliar active session as the stronger compromise signal.
| What you see | What to do |
|---|---|
| Usage is higher than expected, but there is no security notice or unknown session | Compare active browsers and devices, Claude Code authorizations, and legitimate work before assuming malware. |
| Anthropic sent an infostealer warning | Use a clean device to log out all sessions, then isolate and scan every computer used with Claude. |
| An unfamiliar active session or payment activity appears | Terminate the session, secure the Google or email login path, review payment records, and contact Anthropic support. |
| Usage drains again after a new login | Stop signing in on the suspected device. Remove the malware first; consider a clean reinstall when trust cannot be restored. |
Revoke Claude access from a clean device
- On a phone or computer you trust, open Claude in a web browser and go to Settings → Account → Active sessions. Review the device, browser, approximate location, and last-updated time. Terminate anything unfamiliar [2].
- Use the web account’s Log Out control to sign out across browsers, mobile devices, and desktop applications. Anthropic notes that this all-session option is not available from the mobile apps [3].
- If you use Claude Code, open Settings → Claude Code and remove authorizations you do not recognize or no longer need [3].
- Secure the identity used to enter Claude. For Google sign-in, review Google devices, recovery methods, and third-party access. For email-link sign-in, change the email password, revoke email sessions, and inspect forwarding rules.
- Review saved payment methods and recent charges. Preserve the Anthropic notice and screenshots of unfamiliar sessions or charges before contacting official support.
A password change and 2FA are still important, but they solve a different part of the incident. They make a new login harder; they do not disinfect a computer, and they should not be assumed to revoke every already authenticated session unless the service confirms that action.
Clean the device before signing in again
Disconnect the suspected Windows PC or Mac from the network, but do not wipe browser data before preserving the notice, suspicious download name, install time, and security-tool findings. Then run a full scan with a trusted security product and remove detections. Reboot and scan again before creating a fresh Claude session.
An infostealer may leave more than the visible payload behind. A loader, startup item, scheduled task, service, browser extension, login item, or security-tool exclusion can recreate the threat after the first detection is removed. Gridinsoft Anti-Malware can check a Windows device for these leftovers after the initial containment.
If a token stealer ran here, logging back in can hand the attacker your new Discord session, email cookie, Steam token, or wallet access. Scan this Windows PC first, then reset passwords from a clean device.
Scan the device before signing in againIf the device held browser passwords, session cookies, developer tokens, crypto wallets, SSH keys, or cloud credentials, expand the recovery beyond Claude. The infostealer response guide explains why cleanup and account recovery are separate jobs. Use the account recovery checklist for email and social accounts, and rotate exposed AI API keys independently of Claude consumer sessions.
What not to do
- Do not blame every fast usage drop on malware; first rule out your own clients and authorizations.
- Do not keep signing in from the suspected computer while testing whether the drain continues.
- Do not rely on a password change alone when a valid session and endpoint malware are involved.
- Do not publish or share session cookies, authorization tokens, local credential files, or malware samples while asking for help.
Users who installed a fake Claude tool or pasted an unofficial installation command should also review the fake Claude Code stealer warning. That campaign is a separate infection path, but the same recovery rule applies: clean the endpoint before trusting the next login.
References
- Mayank Parmar. “Anthropic warns infostealer malware is hijacking Claude sessions to drain usage.” BleepingComputer, August 30, 2026. Report and reproduced Anthropic notice.
- Anthropic. “Managing your active sessions.” Anthropic Help Center, March 16, 2026; accessed August 31, 2026. Session management instructions.
- Anthropic. “How do I log out of all active sessions?” Anthropic Help Center, updated August 2026; accessed August 31, 2026. Logout and Claude Code authorization instructions.

