← Back to Tech & Science

Anthropic Warns of Malware Hijacking User Sessions to Drain AI Credits

Tech & ScienceAI-Generated & Algorithmically Scored··1 UPDATE

AI-generated from multiple sources. Verify before acting on this reporting.

Update

SAN FRANCISCO — Anthropic has received additional corroborating reports confirming the scope of the infostealer malware campaign targeting Claude user sessions. These new accounts reinforce earlier findings that malicious software is actively capturing authentication tokens to bypass password protections and drain paid usage credits. The influx of verified incidents suggests the attack vector remains active across multiple user environments, with attackers continuing to exploit compromised credentials for unauthorized access. While the specific mechanics of the token theft remain consistent with initial alerts, the volume of new reports indicates a broader impact than previously understood. Anthropic continues to advise users to monitor account activity and rotate session tokens immediately upon detecting any anomalies. The company has not yet identified a single point of origin for the malware distribution but is working to mitigate further unauthorized consumption of AI resources.

Original Report —

SAN FRANCISCO — Anthropic issued an urgent alert on Aug. 30, warning that infostealer malware is actively hijacking user login sessions for its Claude artificial intelligence platform, leading to unauthorized consumption of paid usage credits. The security firm stated that malicious software installed on personal computers is capturing active authentication tokens, allowing attackers to bypass standard password protections and access victim accounts directly.

The attack vector relies on the theft of session cookies rather than credential stuffing or phishing. Once the malware infiltrates a user's device, it extracts the digital keys required to maintain an active login state. Attackers then utilize these stolen sessions to execute commands through the Claude interface, rapidly depleting the account holder's allocated tokens or subscription limits. Because the hijacked session appears legitimate to the system, the unauthorized activity is often indistinguishable from normal user behavior until significant usage has been consumed.

Anthropic emphasized that this threat targets the endpoint devices of users rather than the company's servers. The malware operates silently in the background, waiting for a user to log in before exfiltrating the necessary data to grant remote access. This method allows bad actors to bypass multi-factor authentication measures, as the stolen session token has already passed all security checks.

The incident highlights a growing trend in cybercrime where attackers target high-value AI services to monetize stolen compute resources. Unlike traditional data theft, which focuses on personal information or financial records, this campaign aims to drain the economic value stored within user accounts. The cost of such attacks falls directly on the victims, who may face unexpected charges or find their service limits exhausted before they can react.

Anthropic has advised users to immediately revoke all active sessions and change their passwords if they suspect their device is compromised. The company recommends scanning systems for known infostealer variants and enabling additional security layers where available. However, the effectiveness of these measures depends on whether the malware has already exfiltrated tokens before detection.

Security experts note that while session hijacking is a known technique, its application against generative AI platforms represents an evolving threat landscape. The speed at which attackers can consume resources makes real-time detection difficult for both users and service providers. It remains unclear how widespread the infection is or whether specific variants of the malware are being distributed through targeted campaigns or broader supply chain compromises. As the investigation continues, Anthropic is monitoring for new patterns in unauthorized usage to identify and block compromised sessions more effectively.

Discussion

0 / 2000