EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Anthropic Warning: Stolen logins are consuming paid Claude subscriptions

2026-09-10 06:37:38
Bookmark

Anthropic confirmed that hackers used information theft trojan to hijack Claude's login session and steal payment limits

Core points:

  • Anthropic began warning subscribers on August 30 that stolen browser sessions were allowing attackers to consume payment credits without requiring passwords or secondary verification.
  • The company pointed to six common malware variants behind the operation, five of which target Windows systems and one affects a small number of Mac devices.
  • One consultant lost access to his account for about two weeks and said he still has not obtained a detailed consumption detail log.

Hijacking Claude sessions with stolen browser cookies

According to TechCrunch, Grant de Swardt, an independent AI consultant in East Sussex, England, discovered that his token limit continued to climb during his off-work period on August 4. The next day, he disconnected all tools associated with the account, suspended scheduled tasks, and stopped using the service completely. However, usage is still rising, increasing from 45% to 55%.

He asked Anthropic for a detailed breakdown of expenses, but received no response. The company then suspended his account, invalidated all session and service-side tokens, and refunded £ 44.49 to offset fees for the remaining plan.

Investigators later concluded that a stolen session key was used to generate unauthorized Claude Code tokens on his account. Anthropic informed him that the account looked like an external service was running someone else's work for it, but could not determine how the service entered. He shared the experience on Reddit, prompting about 80 comments, with multiple users describing similar situations where quotas were exhausted.

Anthropic names Vidar, LummaC2 and four other theft tools

Anthropic began sending emails to a wider customer base on August 30, naming Vidar, LummaC2, StealC, RedLine and Areed on Windows platforms, as well as Atomic Stealer used on a small number of Mac devices. All six are universal theft tools that can be rented at low prices in the criminal market, and none of them are recent variants.

The company stated that the malware is not directly related to Claude himself and is usually spread through pirated downloads or malicious applications. Once installed, they scrape passwords, auto-fill data and login cookies saved on the machine and send them to the operator. Anthropic forced cancellation of affected users, deleted saved payment cards, and refunded fees in those accounts that were determined to be unauthorized.

Session theft now surpasses password theft

Security researchers linked the operation to a broader security trend that is gradually moving away from password theft to session theft. Because multi-factor authentication (MFA) greatly reduces the utility of stolen credentials obtained separately, and stolen cookies prove that login has been completed, attackers can bypass these checks without triggering alarms or facing secondary verification.

de Swardt restored account access after about two weeks, then canceled it and switched to Cursor. He said Anthropic still does not provide users with a way to check credit consumption, and the company declined to comment on how subscribers detect abuse. The incident came at a challenging time for the company-in July, three incidents involving unauthorized behavior by its own models were disclosed, some training was suspended, and about 150 product engineers were transferred to the safety team.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP