律动BlockBeats
律动BlockBeats|8月 31, 2026 10:39
**[Claude Quota Mysteriously Drained? Hackers Start Stealing Login Sessions, Even 2FA Can't Stop Them]** Beating AI News Flash: Anthropic is sending security warnings to some Claude users. The company has discovered that hackers are stealing Claude login sessions from computers infected with malware, then using these sessions to access accounts and drain user quotas. Users on Reddit have already shared screenshots of warning emails received from Anthropic. What’s being stolen isn’t passwords, but rather the already authenticated login sessions stored in browsers. Once attackers obtain this login state, they can impersonate users directly without needing to re-enter passwords or pass 2FA. One user reported logging in via Google and enabling two-factor authentication, yet their browser cookies and session IDs were still stolen. In its email, Anthropic listed several trojans responsible for stealing such information, including Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, as well as Atomic Stealer (AMOS) on Mac. These are malware programs specifically designed to steal browser cookies, passwords, and other sensitive information, and are not security vulnerabilities within Claude itself. The affected user mentioned during interactions with others online that they had previously downloaded pirated software. Anthropic stated in the email that it has already logged out suspicious sessions, removed saved payment methods from accounts, and addressed unauthorized charges. The company also warned that simply changing passwords won’t resolve the issue. If the malware on the computer isn’t removed, newly generated login sessions could still be stolen. [Original Link]
+6
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads