> Back to All Posts

Claude Session Hijacking: Malware Drains Paid AI Accounts

Claude Session Hijacking

Anthropic has started emailing Claude users with an unwelcome message. Malware sitting on their own computers stole active login sessions. Attackers then used those sessions to sign in and drain the usage that victims had paid for. This wave of Claude session hijacking did not begin with a flaw in the AI platform, because it began on the victim’s own desktop with a commodity infostealer.

How Claude session hijacking actually works

The attack chain is short, and that is exactly why it works. First, an infostealer lands on a Windows or Mac machine through a sketchy download or a fake app. It then sweeps up everything valuable stored locally, including browser passwords, saved credentials, login cookies and the session tokens that keep you signed in. Those tokens are the part that matters here.

A bad actor later sorted through that stolen haul and picked out the Claude sessions. Anthropic put it plainly: the session was one item among many, and someone has now started using it. So this round of Claude session hijacking runs as a second-stage operation on data that criminals already held.

Why your password and 2FA never got involved

A session token represents a browser that has already logged in. Because of that, an attacker who imports the token never sees the password prompt. Two-factor authentication stays quiet too, since the account never registers a fresh login attempt.

This is why Claude session hijacking succeeds against people who did everything right. But a strong password, an authenticator app and zero reused credentials will not block a stolen cookie. The security check already happened, and the attacker inherited the result.

The infostealers behind the stolen Claude sessions

Anthropic named several malware families in its ongoing investigation. On Windows, it identified Vidar, LummaC2, StealC, RedLine and Acreed. On macOS, Atomic Stealer, also known as AMOS, hit a smaller group of users.

None of these tools target AI accounts by design. Instead, they grab whatever sits on the disk, and resale value decides what gets used later. The infection route in one confirmed case was depressingly familiar. The affected user had downloaded a pirated game.

Why AI accounts landed on the target list

Stolen accounts carry a market price, and that price decides what criminals bother to use. A hijacked streaming login sells for pocket change. A Claude account with an active subscription is worth far more, since the buyer gets instant access to a paid model with no card to enter and no email trail to leave.

That demand explains the sorting behaviour behind this campaign. Infostealer crews collect millions of records, then resell them to people who specialise in monetising one platform. The specialists behind this Claude session hijacking campaign chose Claude, but the same playbook fits any AI service with a paid tier.

What Anthropic is doing for affected accounts

Anthropic’s response arrived in two parts. The company is signing affected users out of Claude, which kills the stolen sessions, and it is also stripping saved payment methods so intruders cannot rack up purchases. Anthropic says it will refund charges it identifies as unauthorized.

One warning in that email deserves repeating. Signing a user out stops the current session, but it does nothing to the malware itself. If the infection stays on the machine, the next login hands the attacker a fresh token.

How to spot a hijacked Claude account

Claude session hijacking leaves a distinctive fingerprint. Usage limits that refill and then drain while you sit nowhere near the keyboard point straight at someone else. Unexpected charges and unfamiliar entries in your account history tell the same story.

Anthropic asked affected users to take three steps. Change your credentials, revoke every other active session, and remove the malware before you log back in. Order matters here, because a fresh login on an infected machine simply hands over a fresh token.

A password change alone achieves nothing while the stealer still runs in the background. So run a full scan with reputable security software, or rebuild the machine if the infection looks stubborn. Only then should you sign back in and restore your payment details.

Where a VPN fits into this picture

A VPN cannot remove an infostealer that already reached your hard drive. It encrypts your traffic and hides your IP address, though it never scans your files. Anyone selling a VPN as malware removal is overselling the product.

Against Claude session hijacking, a VPN plays a supporting role instead. NordVPN’s Threat Protection and Surfshark’s CleanWeb both filter known malicious domains and warn you away from risky downloads before anything reaches your disk. Since pirated software and fake app pages remain the main delivery channel for these stealers, that filter carries real weight. Pair it with proper antivirus coverage, because the two tools handle different halves of the problem.

Final Thoughts

Claude session hijacking puts a fresh label on a very old problem. Cookie theft has also drained bank accounts, gaming libraries and social profiles for years, and AI subscriptions have joined the list. In short, attackers follow value, and paid AI access now carries a price.

The practical response is unglamorous but effective. Keep pirated software off your machine, and scan properly when something feels wrong. Treat a sudden drop in your usage limits as a security event rather than a billing glitch. The token sitting in your browser deserves the same care as the password behind it.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.