Malware is stealing Claude login sessions and draining paid usage — a cheap lesson for anyone budgeting AI tool spend
Anthropic has warned that infostealer malware — including Vidar, LummaC2, StealC, RedLine, and Atomic Stealer on Mac — is lifting active Claude session cookies from infected machines and using them to consume victims' paid usage, bypassing MFA entirely because the stolen session is already authenticated.
2 September 2026
Anthropic is warning some Claude users that infostealer malware on their own machines has stolen active login sessions and used them to run up usage on the victims’ account. The mechanism is simple and effective: general-purpose infostealers like Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer on a small number of Macs, extract browser cookies and session tokens from an infected device. Because a session cookie represents a state that’s already authenticated, multi-factor authentication never gets a chance to block anything — the attacker just walks in with your open session. Anthropic’s advice for spotting it: if your usage allowance looked like it refilled and then drained while you weren’t actively working, that’s the signature.
Anthropic’s response has been to forcibly sign out affected accounts, revoke the stolen tokens, delete stored payment cards, and refund unauthorised charges — but as the company itself notes, that stops the immediate session theft without removing the malware from the machine it came from. The next login is exposed the same way until the underlying infection is cleaned up.
Why this is a commissioning question, not just an IT one
This isn’t a Claude-specific flaw — it’s a general infostealer problem that happens to have a very visible symptom on a metered AI coding tool, because usage draining shows up as a bill. If your delivery team runs Claude Code, Cursor, or any other session-authenticated AI tool on developer laptops without solid endpoint hygiene, the exposure is the same: someone else spending against your account, and potentially reading whatever that session has access to in the meantime.
So what
If you’re paying for a team’s AI coding tool usage, it’s worth asking whether their machines run current endpoint protection and whether they’d notice an unexplained usage spike before it hit an invoice. It’s a small operational check, but infostealers are opportunistic and don’t care whether the account they hijack belongs to a solo developer or an agency billing a client. See our AI-assisted development approach, or get in touch if you want a second pair of eyes on how your delivery team’s tooling is secured.