> ## Content Index
> Fetch the complete content index at: https://www.betteratcoding.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Stolen Claude sessions are draining people's usage
- URL: https://www.betteratcoding.com/trending-news/stolen-claude-sessions-are-draining-peoples-usage/
- Published: 2026-09-01T03:50:47.000Z
- Updated: 2026-09-01T03:50:47.000Z
- Author: Zacarias Ripoll Cid
- Tags: trending-news

If your Claude usage refill vanished while you were not even at the keyboard, Anthropic thinks it knows why. Bleeping Computer reported on August 30, 2026 that the company is emailing some Claude users about a campaign that steals live login sessions from infected PCs, then burns through the account's usage.

This is not a Claude bug. Anthropic told affected people it has no reason to believe the malware came from Claude, was installed through Claude, or had anything to do with how they used Claude. The computers were already infected with ordinary infostealer malware. That kind of program arrives through a bad download or a shady app, then copies whatever it finds: browser passwords, login cookies, and credentials for other apps. A Claude session was one more item in the pile. A bad actor started pulling those sessions out and using them.

[ ![](https://m.media-amazon.com/images/I/81cat7yAIzL._AC_SY355_.jpg) Amazon Leather journal Hardcover notebook ↗ ](https://amzn.to/4cjVuHH?ref=betteratcoding.com) 

A session cookie is the digital wristband you get after you log in. The site already knows it is you, so the attacker does not have to type your password or pass a second factor. They walk in wearing your wristband. That is why two-factor authentication does not save you once the session is already live on a dirty machine.

Anthropic named the malware families it has seen. On Windows: Vidar, LummaC2, StealC, RedLine, and Acreed. On a small number of Macs: Atomic Stealer, also called AMOS. The person who posted the company email on Reddit said they had downloaded a pirated game. That is a classic way this stuff lands.

[ ![](https://m.media-amazon.com/images/P/B0DBJ5DBL8.01._SX355_.jpg) Amazon Shure MV6 USB microphone ↗ ](https://amzn.to/4gtli6G?ref=betteratcoding.com) 

The company is signing affected users out, stripping saved payment methods, and refunding charges it flags as unauthorized. Signing out kills the stolen session. It does not clean the PC. Anthropic said that plainly. If the malware is still sitting there, the next login can be stolen the same way.

I would treat that email as a two-part job. First, lock the account: change credentials on anything that lived in that browser, revoke other sessions, and do not save a card back onto Claude until the machine is clean. Second, clean the machine. A scan from inside a still-infected Windows session can lie to you. Boot to Safe Mode, run a real malware pass, and assume the browser profile is burned. If you sideloaded a cracked installer, that is the smoking gun. Delete it. Do not log back into Claude, your bank, or your email from that box until you trust it.

The useful close is boring. If your usage bar refilled and then drained while you were away, check Anthropic's email and your active sessions before you buy more credits. If you did not get an email, still look at sessions. Infostealers do not care that you pay for Claude. They care that a cookie is sitting in a browser on a dirty PC.