TIDEZINE.

No Account Hack, No Leaked Password: The Truth Behind Mysteriously Drained Claude Usage

Anthropic sent an email to affected users last week, force-logging them out of their accounts, deleting saved credit cards, and issuing refunds. The cause: info-stealing malware on users' computers that hijacked their Claude login sessions.

No Account Hack, No Leaked Password: The Truth Behind Mysteriously Drained Claude Usage

If your Claude usage quota looked like it got refilled only to mysteriously get burned through again, an email Anthropic sent out last week has the answer: the problem wasn't your password or two-factor authentication—it was something in your browser called a session cookie that got stolen.

The email was first shared by a user on Reddit, and later reported by SecurityWeek. According to the letter, Anthropic has force-logged out all sessions on affected accounts, deleted saved credit cards, and refunded charges from the abnormal usage. The company also clarified that the root cause was info-stealing malware on users' own computers, not a breach of Anthropic's systems.

Anthropic has identified six malware families behind the incidents, including Vidar, Lumma, StealC, RedLine, and Acreed on Windows, and Atomic Stealer (AMOS) on macOS. The company described the number of affected Mac users as "very small." None of these tools were designed specifically to target Claude—they're common generic info-stealers, typically bundled with malicious downloads. Once executed, they harvest passwords and cookies stored in the browser.

The key lies in what a session cookie actually does: once you log into Claude, your browser holds onto this credential so the system doesn't need to ask for your password every time you load the page. Once an attacker copies that cookie, they can simply pick up right where the victim's already-logged-in, already-2FA-verified session left off—no need to trigger a password prompt or two-step verification at all. That's exactly why the account password never leaked, yet the quota mysteriously got burned through.

Anthropic warns that a forced logout only cuts off the currently hijacked session—it doesn't remove the malware itself from the user's computer. The company's recommended order of operations: first remove the malware from your computer, then log back into Claude, set a new password for the linked email account and turn on two-factor authentication, and only after that re-add your payment method. Do the steps out of order, and the same malware could just intercept the new cookie generated by your fresh login.

The email didn't disclose the scale of affected accounts, and Anthropic has not yet responded to Engadget's request for comment.

Related

Memphis Data Center Hiccup Knocks Grok Offline for Over 3 Hours—SpaceXAI Apologizes to "Compute Partners"
Tech

Memphis Data Center Hiccup Knocks Grok Offline for Over 3 Hours—SpaceXAI Apologizes to "Compute Partners"

SpaceXAI's data center in Memphis suffered a "model outage" on September 3, taking Grok down for more than three hours. The company also issued an apology to unnamed "compute partners." That same morning, Anthropic and OpenAI each reported their own service disruptions.

Motorola Razr Gets Swarovski Crystal Treatment Again, This Time in Black
Tech

Motorola Razr Gets Swarovski Crystal Treatment Again, This Time in Black

Motorola is rolling out a new Swarovski-collab Razr, featuring Pantone Meteorite black paired with 35 hand-set crystals. It launches September 10, starting at $900.

TikTok Overhauls Comment Section: 60-Second Voice Notes, 9-Photo Carousels & Polls Roll Out Together
Tech

TikTok Overhauls Comment Section: 60-Second Voice Notes, 9-Photo Carousels & Polls Roll Out Together

TikTok is rolling out four new comment section features at once—voice comments, comment polls, live photo uploads, and 9-photo carousels—pushing comments beyond plain text into a richer, more multimedia format.

The Xbox Cloud Streaming Free-For-All Is Over: Starting November, Time Caps Kick In at 5 to 15 Hours Depending on Your Tier
Tech

The Xbox Cloud Streaming Free-For-All Is Over: Starting November, Time Caps Kick In at 5 to 15 Hours Depending on Your Tier

Game Pass Ultimate subscribers used to get unlimited cloud gaming, but starting in November that's changing to a fixed monthly allotment. Non-subscribers will also be able to buy streaming time separately, with Xbox set to announce regional pricing later.

Apple Sued in UK Over App Tracking Transparency Policy, Facing $2.7 Billion Lawsuit
Tech

Apple Sued in UK Over App Tracking Transparency Policy, Facing $2.7 Billion Lawsuit

A former UK Competition and Markets Authority official is suing Apple on behalf of developers, claiming ATT's privacy policy imposes stricter rules on third-party apps than on Apple's own services, seeking £2 billion in damages.

America's First VPN Age Verification Law Halted the Moment It Takes Effect, Utah Delays Enforcement Amid Lawsuit
Tech

America's First VPN Age Verification Law Halted the Moment It Takes Effect, Utah Delays Enforcement Amid Lawsuit

Utah's SB 73 was originally set to take effect this Thursday, making it the first law in the US to hold websites accountable for VPN usage. But the Department of Commerce has already announced it won't enforce the law for now, pending a federal judge's ruling on Aylo's lawsuit.