AI developers are warning about theft of active Claude sessions by infostealer malware, reports infohub.kz.

American company Anthropic has begun mass-sending warnings to users of its AI assistant Claude. Account holders faced forced session terminations and removal of linked bank cards. The company took these emergency measures after detecting large-scale malicious software activity aimed at stealing credentials and exhausting AI usage limits.

In an official notice, Anthropic explained that attackers use common infostealer programs such as Vidar, LummaC2, StealC, RedLine, and Acreed for Windows, and AMOS for macOS. These programs infiltrate computers via unlicensed software or malicious downloads, then copy authorization cookies and saved passwords. This allows hackers to bypass two-factor authentication and connect to other people's Claude profiles, consuming available request limits.

The company stressed that Claude services themselves contain no vulnerabilities and were not the source of infection. To protect customers, Anthropic canceled suspicious sessions, reset saved payment data, and promised to refund unauthorized transactions. Owners of compromised devices are strongly advised to fully clean their systems of viruses before logging back into their accounts.