Users report watching their paid Claude allowance shrink on days they never worked. Anthropic has confirmed that infostealer malware is lifting login sessions from people's computers and letting outsiders burn through their usage. No password is cracked and no MFA prompt is defeated, yet the account ends up in someone else's hands.

Stealing a Session Is Enough

The target here is not the password but the session. It is a small piece of data stored inside a browser or app to prove that a user is already signed in, and any party holding it is treated by the service as the authenticated account owner.

Once that session leaves the machine, the attacker needs neither a password nor a one-time code. Even with multi-factor authentication enabled, no fresh challenge is triggered. This is the kind of compromise that hardening authentication does little to stop.

Anthropic's position is that neither its infrastructure nor Claude itself was breached. What was compromised is the user's own computer, not Anthropic's servers. No evidence of password guessing or brute-force attempts has been reported.

The Malware Involved Is Nothing New

The tools lifting these sessions are conventional infostealers. On Windows, the families named include Vidar, LummaC2, StealC, RedLine and Acreed, all long-standing fixtures of the underground market. Atomic Stealer (AMOS) has turned up on a small number of Macs as well.

These programs sweep up saved passwords, cookies, session data and credentials and ship them out. The infection routes are equally familiar: tampered software downloads, malicious ads, and pages posing as distribution sites.

Anthropic says the malware did not arrive through the use of Claude. Rather than a novel AI-specific attack technique, this looks like AI subscription quotas being added to the shopping list of existing stealers. As monthly generative AI plans became a fixture of daily work, stolen sessions acquired resale value.

The Warning Sign Is Usage That Rises While You Do Nothing

Victims describe nearly identical symptoms: the usage gauge moves during hours of inactivity, the allowance drops by nearly half after only a few prompts, or the ceiling is hit several days in a row.

One well-documented case involves an independent AI consultant based in East Sussex in the United Kingdom. On August 4 he noticed token consumption climbing on a day he was not working. The next day he disconnected everything attached to Claude and did no work at all. Consumption still rose, moving from 45 percent to 55 percent under what he described as a controlled interval.

When he asked Anthropic for an itemized breakdown of what had consumed his tokens, none was provided. The company did acknowledge that something was wrong. It suspended the paid account, invalidated every session and server-side Claude Code token, and refunded 44.49 GBP (about 9,300 yen) for the remainder of a 200 USD (about 30,800 yen) per month plan.

※Exchange rates as of September 9, 2026: 1 USD = 154 JPY, 1 GBP = 208 JPY

Anthropic later reported that a compromised session key had been used to mint unauthorized Claude Code OAuth tokens. How the key was obtained was never determined. The consultant maintains he found no sign that his own computer had been compromised.

The Bleeding Stops, but the Cause Stays on the Device

Anthropic's response follows a set pattern: force a sign-out for users showing suspicious activity, invalidate existing authorizations, remove saved payment methods, and refund charges it judges to be unauthorized. In some cases the company proactively emailed users who had no idea anything was wrong, so detection and notification are functioning.

The trouble begins after that. Signing out only kills the stolen session; it does not touch malware living on the machine. Log back in without cleaning the device and the new session is siphoned off the same way. What the service can do amounts to first aid, while real recovery is only possible on the user's end.

Visibility is the other unresolved gap. Account support can track total usage but reportedly will not supply a line-by-line breakdown even on request. Without that breakdown, theft can continue undetected for months. The consultant's account was reinstated after roughly two weeks, but the unresolved cause and the slow handling pushed him to Cursor, which lets him switch between multiple models. Asked how users can spot misuse on their own, Anthropic declined to comment.

What Users Can Realistically Do

Because this is session theft, changing a password is not sufficient. The order matters: check the device for malware and clean it first, then change the password and invalidate all existing sessions. Reverse that order and the fresh credentials are stolen straight away.

Beyond that, periodically reviewing usage trends is the practical line of defense. Increases during idle hours, or drops out of proportion to the work performed, are currently almost the only signal available. Anyone running agents for business should know their normal consumption pace so that anomalies stand out.

Summary

This episode shows that monthly AI service quotas have become a new way for stealer malware to cash out. The technique itself is not novel, but two weaknesses compound each other: multi-factor authentication does not stop it, and the absence of itemized usage delays discovery. Detection and notification on the service side have started moving, while cleaning the device and monitoring consumption remain the user's responsibility. The deeper generative AI sits in a workflow, the more endpoint hygiene matters relative to authentication strength.