Anthropic, the company behind the Claude AI service, has automatically logged out users to protect them from potential hacking threats. According to an email sent to affected users and shared on Reddit, the company discovered that infostealer malware had captured active login sessions for Claude on users' computers. This allowed attackers to bypass usage limits and make unauthorized charges on users' accounts. Users were advised to look for signs such as their usage limits refilling and then draining unexpectedly while they were not actively using Claude. To address the issue, Anthropic has been signing users out of their accounts, removing stored payment cards, and refunding any unauthorized charges linked to the stolen sessions. However, the company emphasized that this action does not eliminate the malware from users' devices. Both Windows and macOS users have been affected by the breach. Anthropic identified six types of malware responsible for the stolen sessions: Vidar, Lumma, StealC, RedLine, Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs. These infostealers are often bundled with malicious downloads and are designed to capture passwords and browser cookies. Once installed, they allow attackers to hijack user sessions by replaying stolen cookies, granting access without requiring the user's password or two-factor authentication. Anthropic has advised users to remove the malware from their devices before logging back into Claude. It also recommends changing the password and enabling two-factor authentication for the email address linked to the account before re-adding payment methods. According to Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, stolen Claude logins have become valuable on the black market, with criminals trading access to AI services like Claude, ChatGPT, and Gemini. Security researchers from Palo Alto Networks' Unit 42 have traced some of these hijacked accounts to proxy services known as transfer stations, which collect and resell access to AI services at a lower cost. Anthropic does not disclose exact figures for Claude usage limits, but each prompt has a compute cost that the company covers when a stolen session is used. If an attacker has access to a stolen session and a saved payment method, they can purchase additional usage on the victim's account. This is why Anthropic chose to remove stored payment methods instead of just ending the sessions. In May, Anthropic increased Claude Code rate limits for paid users due to high demand. While the company can identify and invalidate stolen sessions, until the malware is removed from a user's device, the next login will generate a new session cookie for attackers to collect.