Anthropic warns infostealers are hijacking Claude sessions and draining paid usage Anthropic warned that infostealer malware is stealing active Claude login sessions from infected Windows and Mac computers and using them to drain paid usage allowances, according to emails reviewed by BleepingComputer. Anthropic said it is revoking affected sessions, removing saved payment methods and refunding charges it identifies as unauthorized, and one Claude Max subscriber told TechCrunch his account kept consuming tokens while he was inactive before Anthropic suspended the account, invalidated sessions and issued a partial refund. Anthropic has not disclosed how many accounts were affected or the campaign's duration, and the evidence points to endpoint infections rather than a confirmed breach of Anthropic's systems. Anthropic warns infostealers are hijacking Claude sessions and draining paid usage - Anthropic says infostealers are stealing active Claude sessions and using them to consume account allowances.