Anthropic Is Force-Logging Out Claude Users and Deleting Saved Cards After Infostealers Replayed Live Sessions
Help Net Security / BleepingComputer·high signal
Anthropic emailed affected users starting August 30 that six commodity infostealer families (Vidar, LummaC2, StealC, RedLine and Acreed on Windows, Atomic Stealer on macOS) lifted authenticated Claude session cookies off infected machines and replayed them to burn paid usage. Because the theft is of already-authenticated cookies, it bypasses 2FA and SSO entirely, with no password ever needed. Anthropic's remediation is to invalidate sessions, strip saved payment methods, and refund unauthorized charges; the tell for builders is usage limits that appeared to refill and then drain while you were not using Claude.