Infostealer Malware Bypasses Passwords, Targets Claude Subscription Tokens
A new wave of attacks is targeting Claude subscribers, not by cracking passwords, but by stealing active login sessions directly from infected computers using common infostealer malware. This allows hackers to drain paid token quotas without triggering standard authentication alerts.
How the Attack Works and User Reports
The issue gained attention in August when a user publicly noted their Claude account was consuming tokens during off-hours. Similar cases quickly emerged on Reddit and GitHub, with subscribers discovering unauthorized access and rapid token depletion. The attacks exploit malware that harvests browser cookies, sessions, and authentication tokens from compromised devices, granting attackers immediate account access.
Platform Response and Limitations
Anthropic has acknowledged the incidents and implemented several countermeasures for affected users:
- Forced logout of suspicious active sessions
- Revoked authorization for unrecognized devices
- Issued refunds for confirmed unauthorized usage
However, the company has not yet provided a granular, transaction-level breakdown of token usage, making it difficult for users to independently audit specific unauthorized consumption.
Steps Users Can Take for Protection
Since passwords alone are insufficient against this threat, users are advised to:
- Regularly review account activity logs for unfamiliar login times or locations
- Enable multi-factor authentication if available
- Keep systems and security software updated to prevent malware infection
- Avoid logging into critical AI service accounts on public or untrusted devices
This incident highlights a growing risk as AI subscription services become more valuable: session hijacking is evolving into a preferred method for cybercriminals. Both users and providers need to adapt security practices beyond traditional password protection.