Skip to main content
Emerging ThreatsMalware & Ransomware

Anthropic Disrupts AI Token Mining by Hijacked User Accounts

Person sitting at laptop in quiet home office with blurred screen.

"We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude," Anthropic wrote in an email shared with The Register.

Anthropic signs out users and removes payment methods after detecting fraud

Anthropic has taken direct action against at least one account it judged compromised: the company logged the user out and deleted the saved payment method after detecting evidence of attempted fraud. That step, the company told the affected user, was intended to stop stolen sessions from being abused for paid Claude usage.

The notification was shared by a Reddit user known as WorriedAssociate7029, who forwarded the email to The Register. According to WorriedAssociate, the attempted theft failed “apparently thanks to Anthropic spotting it,” and the provider’s automated or manual intervention prevented the account from being used to run paid AI workloads on someone else’s dime.

Infostealer malware — Vidar, LummaC2, RedLine, Acreed, StealC and Atomic Stealer — is the mechanism

Anthropic’s message made clear this is not a novel, agentic AI malware or a vulnerability in Claude itself, but a repurposing of established infostealer toolkits. The company identified known families — Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer — as being used to capture login credentials, session cookies, and the data needed to bypass multifactor protections.

According to the forwarded email, a “bad actor has now started picking the Claude sessions out of what it collected and using them.” The company emphasized that the session data was likely one of many artifacts harvested by the infostealers, not something installed or distributed by Claude.

How sessions and Google credentials were used to hijack Claude access

WorriedAssociate reported that the attacker had apparently taken Google account credentials, cookies, and session IDs — and that those tokens were the route by which the attacker gained access to Claude. The user said they had already been through a broader social-media account compromise and, with the help of Claude Opus 5 Max, traced and removed the malware from their system.

After being notified by Anthropic the user changed their password again, removed all active sessions, and reported that they now appear to be safe. The user also conceded the root cause of their infection: “I got fooled like a rookie by downloading a cracked game.”

What this means for technologists, end users, and AI providers

  • Technologists and security teams: Expect infostealers to include AI sessions as valuable targets. Anthropic’s identification of multiple known stealer families shows attackers are adding session cookies and API tokens to their harvest lists and then extracting sessions for paid usage.
  • End users and the general public: Stolen sessions can be used to access paid AI services without the victim’s consent and to consume expensive compute or token-based plans. As WorriedAssociate noted, “Tokens are valuable and can be resold,” and providers may take steps such as signing out accounts and removing payment information when fraud is detected.
  • AI providers and customer support teams: Anthropic’s intervention in this case — the sign-out and removal of stored payment methods — illustrates a mitigation path. The affected user praised the alerting but also criticized customer support for account recovery and refunds, saying customer service “seems pretty dreadful” in those areas, while noting the new email and protections are a welcome change.

Lessons from a single traced compromise and a pointed open question

This incident stitches together a familiar crime pattern — cracked software leading to infostealer infection — with a new monetization target: AI tokens and premium model access. Anthropic’s email framed the problem plainly: the malware “collected” Claude sessions among other artifacts, and attackers then selected those sessions for abuse. For the individual who reported the incident, the provider’s detection and remedial steps appear to have halted financial misuse.

The case leaves one practical question in stark relief: will providers expand automated detection and proactive account lockdowns beyond isolated incidents, or will these measures remain ad hoc responses? Anthropic’s action here prevented a billed attack on a single account; the broader efficacy of similar defenses across the user base remains to be seen.

Original story: Anthropic cracks down on hijacked user accounts mining AI tokens — The Register