Anime, manga, and games, with a take · A Yukimedia publication

← all stories other 1 sources · 1h ago ·

Anthropic Logs Out Claude Users Hit by Infostealer Malware

Anthropic's forced logout and refunds show that session hijacking bypasses login protections, pushing the burden onto users to avoid suspicious software.

Reporting from 1 source: GIGAZINE.

Anthropic Logs Out Claude Users Hit by Infostealer Malware

Anthropic confirmed infostealer malware hijacking Claude login sessions to drain usage. The company forcibly logged out affected users, removed their payment methods, and refunded unauthorized charges. The malware copies browser cookies and credentials, so two-factor authentication does not stop it. One Reddit user reported infection from pirated games.

Anthropic detected malware that hijacks users' Claude login sessions and drains their usage. The company responded by forcibly logging out affected users, removing their payment methods, and refunding charges for the unauthorized period.

The malware, a type of infostealer, copies browser cookies and credentials from locally running software. Since it takes over browsers already logged into Claude accounts, two-factor authentication at login cannot prevent the unauthorized use. One affected user on Reddit confirmed that two-factor authentication did not work.

Anthropic noted the malware is common and likely came from unofficial software, not through Claude itself. The same user reported being infected after installing pirated games, and the malware also hijacked their social media accounts to post cryptocurrency scams.

Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources