Anthropic says infostealer malware on infected computers is stealing Claude.ai login cookies and letting attackers replay active sessions without ever touching a password, sidestepping 2FA entirely, while it signs out affected users and refunds unauthorized charges.

Read the full story: Anthropic Warns Infostealers Are Hijacking Claude Sessions →

Transcript

Anthropic just told Claude users that malware on their own computers is hijacking active login sessions, and it never even needs your password. Infostealers like Vidar, Lumma, and StealC copy your browser's session cookie, the thing that proves you're already logged in. Attackers replay that cookie and skip login entirely, which means two factor authentication never fires. It only guards the login step, not a session that's already open. Anthropic is signing out every flagged account, wiping saved payment methods, and refunding unauthorized charges. But this isn't only a Claude problem. Every AI platform runs on the same session model, ChatGPT, Gemini, all of it. If you've installed cracked software recently, scan your device now, and log out of Claude everywhere.