cd /news/ai-safety/anthropic-cracks-down-on-hijacked-us… · home topics ai-safety article
[ARTICLE · art-117123] src=machinebrief.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Anthropic cracks down on hijacked user accounts mining AI tokens

Anthropic has detected a wave of infostealer malware campaigns that hijack Claude user accounts to mine AI tokens, and has begun signing affected users out and removing saved payment methods to stop the abuse. The company identified Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer as the malware used, and clarified that the theft is not related to Claude itself. One affected user, who shared Anthropic's email with The Register, credited the company for alerting them and helping secure their account.

read4 min views1 publishedAug 31, 2026
Anthropic cracks down on hijacked user accounts mining AI tokens
Image: Machinebrief (auto-discovered)

Source:

The RegisterCommodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage

Rather than paying for their own

Claudeusage, crims are using malware to steal access to other people's accounts. Aware of this issue,Anthropichas signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused. According to an email shared by Reddit user WorriedAssociate7029, who sent a copy to The Register, Anthropic has been keeping an eye on a threat actor using infostealer malware to hijack Claude login details, session cookies, and other info needed to subvert multifactor authentication on user accounts. Once obtained, the miscreant is using the stolen information to use premium Claude services without having to pay the bill themselves. Fortunately for WorriedAssociate7029, Anthropic logged the user out of their account and deleted their stored payment method because it had detected evidence of attempted fraud. “A few days ago, my social media accounts were hacked,” WorriedAssociate said, adding that they'd managed to track the malware down with the help of Claude Opus 5 Max and, they believe, cleaned the system. “But last night I received this email from Anthropic warning me of an attempt to steal tokens via the API.” They explained that the attempt failed, apparently thanks to Anthropic spotting it, but they realized that meant that the cybercriminal behind the incident seemed to have hijacked Google account credentials, cookies, and session IDs as well, since that’s how they were signed into Claude. After changing their password again and removing all active sessions, it appears they are now safe. Who’s eating your cookies? Anthropic made clear in the email that the credential theft wave it’s identified has nothing to do with Claude itself, nor is it some sort of fancy, new-fangled,agentic AImalware that’s being used to create a base of accounts for bad actors to abuse. This is just good old-fashioned infostealer malware being turned to a new purpose, the email explains. “We have no reason to believe that this malware is related to Claude, installed through Claude, or related to anything you did with Claude,” the email forwarded to us by WorriedAssociate and posted to Reddit stated. “Your Claude session was likely one of the many things it collected. It appears that a bad actor has now started picking the Claude sessions out of what it collected and using them.” In this case, it’s well-known infostealing malware too: Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer have all been fingered by Anthropic as being used to steal Claude credentials, sessions, and cookies. As for WorriedAssociate, they copped to making a noob mistake that led to their infection. “I got fooled like a rookie by down a cracked game,” they admitted in a comment on their post. “Never again.” As in their post, WorriedAssociate told us in a chat that they gave credit to Anthropic for cluing them in to the fact that they hadn’t fully secured their accounts, and said they appreciated what the company did to help lock their Claude account down. “There have been several cases on Reddit in the past of accounts being hacked to steal tokens, and Anthropic’s customer service seems pretty dreadful when it comes to refunds and account recovery,” they told us. “This email appears to be new, and measures have finally been put in place to protect AI users.” “Tokens are valuable and can be resold,” WorriedAssociate added. So let this be a lesson: Providers might not catch every case of account theft, and AI accounts are the new hotness. Don’t let your tokens be burned by someone else - they’re expensive and the last thing you want them to be used for is someone else's work. ®Get AI news in your inbox

Daily digest of what matters in AI.

Key Terms Explained #

Agentic AI

Agentic AI refers to AI systems that can autonomously plan, execute multi-step tasks, use tools, and make decisions with minimal human oversight.

Anthropic

An AI safety company founded in 2021 by former OpenAI researchers, including Dario and Daniela Amodei.

Claude

Anthropic's family of AI assistants, including Claude Haiku, Sonnet, and Opus.

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-cracks-dow…] indexed:0 read:4min 2026-08-31 ·