Someone Might Be Using Your Claude Account — And Anthropic Wasn’t Hacked
TL;DR: Attackers are using ordinary malware to steal Claude login sessions off people’s computers, then spending those accounts’ paid usage. If your limits looked like they refilled and drained while you weren’t using Claude, that is the signature of a Claude account hacked this way. Two things almost every headline gets wrong: Anthropic wasn’t breached — the malware is on the user’s own machine — and signing out doesn’t fix it, because if the malware is still there the next session gets stolen too.
What happened
Anthropic has emailed affected Claude users to say a “bad actor” is stealing login sessions. The company’s own wording, published in full by Malwarebytes:
“We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people’s computers, then using those login sessions to access Claude accounts and consume their usage.”
And the tell, in Anthropic’s words: “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”
TechCrunch reported one case in detail. Grant De Swardt, an AI consultant in East Sussex, watched his Claude Max 20x usage climb from 45% to 55% during a stretch when he did no work at all and had every integration switched off. Anthropic suspended the account, invalidated the sessions, and refunded £44.49 of his $200-a-month subscription. He cancelled anyway.
Per SecurityWeek, the malware families involved are the usual suspects — Vidar, Lumma, StealC, RedLine and Acreed on Windows, and Atomic Stealer on a small number of Macs. None of them are aimed at Claude. They scrape everything: saved passwords, browser cookies, credentials for other apps. Someone then went through the haul, picked out the Claude sessions, and started spending them.
Why a Claude account hacked this way beats two-factor authentication
This is the part worth understanding properly, because it’s counter-intuitive and it applies far beyond Claude.
The attackers didn’t guess a password. They didn’t intercept a code. They stole the session cookie — the small file your browser keeps that says this person already logged in successfully.
Presenting that cookie means never facing the login screen. So two-factor authentication doesn’t come into it. Your 2FA worked perfectly, once, when you logged in. The thief simply walked in behind you carrying the receipt.
Which is why “I have 2FA on” is not an answer to this, and why the fix isn’t a stronger password.
The bit almost everyone gets wrong
Two corrections, and they matter more than the story itself.
First: a Claude account hacked like this does not mean Anthropic was breached. The malware lives on individual users’ computers, arriving the way it always does — dodgy downloads, cracked software, a malicious app. Anthropic told affected users it has no reason to believe the malware was “related to Claude, installed through Claude, or related to anything you did with Claude”. Switching to a different AI tool would protect you from precisely nothing, because the problem isn’t the tool.
Second: being signed out is not being fixed. Anthropic signed out the stolen sessions and removed saved payment cards so accounts couldn’t be charged. Both sensible. Neither touches the malware still sitting on the computer — so the next session you create can be stolen the same way. SecurityWeek’s write-up is blunt about the order of operations: clean the machine first, re-add your card second.
There’s a third detail that turns this from annoying into expensive. Paid Claude plans can carry usage credits with auto-reload — buy more automatically when the balance runs low. As Malwarebytes points out, someone spending your account can burn the included allowance, then the credits, and then trigger fresh purchases on your behalf.
Why it matters if you don’t code
You are the group least likely to spot this, and it isn’t your fault.
A Claude account hacked this way announces itself very quietly. A developer glancing at a usage graph tends to know roughly what they ran yesterday. If you’re building with AI as a means to an end, usage is a number that goes up for reasons you don’t especially track — and “my limit filled up faster than expected” reads as I must have used it a lot, not someone else is on my account.
Three practical consequences:
- The symptom is boring. Not a scary login alert. Just usage that drains when you aren’t working. Easy to shrug off.
- The money is real. With auto-reload on, this stops being “my limit is gone” and becomes a charge on your card.
- Anthropic can’t show you the detail. TechCrunch notes the company doesn’t offer itemised usage tracking, so you can’t audit line by line what was spent and when. You’re left comparing a percentage against your memory.
The wider lesson has nothing to do with Claude. Every AI subscription you hold is now a thing worth stealing — not for your data, but because paid capacity is valuable in itself. It’s the same shift we’ve written about from the money side: what your subscription actually buys and what a tool’s costs really are. Now it’s worth someone else’s while to take it.
What to do about a Claude account hacked this way
Not panic-worthy, but worth twenty minutes today.
- Check your usage while you’re idle. Look now, don’t touch Claude for a few hours, look again. If it moved, that’s your answer.
- Assume the computer, not the account. If something’s wrong, the malware is on your machine. Run a full scan with reputable, up-to-date anti-malware — not just the built-in quick check.
- Clean first, re-add your card second. Putting the payment method back on an infected machine simply restocks the shelf.
- Turn off auto-reload unless you genuinely need it. This is the difference between losing an allowance and losing money. Check any AI subscription you have, not just Claude.
- Sign out everywhere, then log in fresh — after the clean-up, not before. And if usage still moves while Claude sits idle, Anthropic points people at `usersafety@anthropic.com`.
One thing not to do: don’t switch AI tools over this. It would cost you time and fix nothing.
Who should care (and who shouldn’t)
- On a paid Claude plan, especially Max: the group with something to lose to a Claude account hacked this way. Do the idle check today.
- With auto-reload or usage credits enabled: the most exposed, because the loss is monetary rather than notional. Check that setting first.
- On the free tier: far less appealing to a thief, but the malware question stands on its own — if you have an infostealer, Claude is the least of it.
- Using Cursor, Replit or Lovable: not this incident, same principle. Session cookies are session cookies.
- Who installs nothing unofficial and runs current anti-malware: you were already doing the thing this article recommends.
Our take
We’d hold two thoughts at once about a Claude account hacked this way, and resist collapsing them into a simpler story.
Anthropic comes out of this reasonably well. It detected the misuse, told affected users in plain language, killed the sessions, pulled saved cards so nobody could be charged further, refunded what it identified as unauthorised, and said clearly that the malware had nothing to do with Claude. That is a better response than “we take security seriously”.
The gap is what it leaves the user holding. Without itemised usage history, a person who suspects something can’t check it themselves — they compare a percentage to their memory and hope. And the remedy Anthropic can apply, signing you out, addresses the symptom on their side while the cause sits untouched on yours. De Swardt cancelled his subscription over exactly that, which strikes us as an overreaction to the incident and a fair reaction to the lack of tools.
The durable point is the one to take away: your AI subscription is now a target in its own right. Not your files, not your data — the paid capacity, which is worth money and can be resold or used to power other people’s work. Anyone shipping things with AI should file that alongside their other passwords-and-payments hygiene, and stop treating “it’s just a chatbot login” as a low-value credential. It isn’t one any more.
Not sure which AI tool is the right fit for what you’re building? Take the 60-second Vibe Coding Tool Finder quiz →
FAQ
Was Claude or Anthropic hacked?
No. The compromise happened on individual users’ own computers, via general-purpose infostealer malware such as Vidar, Lumma, StealC, RedLine, Acreed or Atomic Stealer. Anthropic told affected users it has no reason to believe the malware was related to Claude, installed through Claude, or caused by anything they did with Claude.
How do I know if my Claude account is hacked?
The signature is usage that changes while you aren’t using Claude. Check your usage figure, leave Claude alone for a few hours, then check again. Anthropic’s own guidance is that limits appearing to refill and then drain during periods you weren’t working is the likely sign of a stolen session.
Does two-factor authentication protect me from this?
Not from this specific attack. The malware steals your browser session cookie, which proves you have already logged in successfully — so the attacker never sees a login screen or a 2FA prompt. Keep 2FA on regardless; the defence that matters here is removing the malware from your computer.
