Infostealers stole Claude login cookies and burned people’s usage

“Someone else is talking to Claude on your dime, and they never typed your password.”

The Story

Common infostealers (Vidar, Lumma, StealC, Atomic Stealer, etc.) copied already-authenticated Claude browser sessions. Attackers replayed the cookies, skipped 2FA, and drained paid usage. Anthropic is mass-signing people out, deleting saved cards, and refunding unauthorized charges. Signing out does not remove the malware; the next login can be stolen again. Secondary: https://www.notebookcheck.net/Claude-sessions-stolen-Anthropic-signs-users-out-and-wipes-cards.1383560.0.html

Why It Matters

Your AI subscription became a stolen car. The thief didn’t need your password — they needed the cookie that said you were already you. Builder utility + darkly funny future-shock.

Evidence

Anthropic customer emails reported by BleepingComputer, 30 Aug 2026; Help Net Security, Notebookcheck.

Sources

Daily scan: 2026-08-31