ANTHROPIC has initiated emergency security protocols due to reports of stolen session tokens from users of their Claude AI. Malicious actors are using info-stealing malware to hijack active login sessions, allowing unauthorized access to accounts and potential fraudulent charges. Users are urged to be vigilant about their Claude usage quotas and to install antivirus software.
The malware is known to harvest saved passwords, session IDs, and authentication cookies, compromising security even if multi-factor authentication is enabled. Specific malware families such as Vidar and RedLine have been identified targeting Windows systems. Importantly, there has been no breach of Claude's infrastructure itself, with infections occurring due to user actions. Anthropic has taken steps to terminate affected sessions and unlink payment methods to prevent further abuse. Users are advised to conduct comprehensive scans, change their passwords, and enable MFA to secure their accounts.