Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.

The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized.

"We have recently become aware of a bad actor that is using common infostealer malware to steal Claude login sessions from people's computers, then using those login sessions to access Claude accounts and consume their usage," Anthropic said in an email sent to an affected user, who shared it on Reddit.

"If your usage limits looked like they refilled and then drained while you weren't using Claude, this was likely the cause," Anthropic warned.

Anthropic sending emails to affected users