Anthropic blocks stolen Claude accounts used to mine AI tokens
Anthropic detected and disabled user accounts that had been compromised by infostealer malware to run unpaid Claude services.
Anthropic has begun forcibly terminating accounts that were hijacked by infostealer malware to exploit paid Claude AI tokens. According to an email forwarded by a Reddit user, attackers harvested login details, cookies and session IDs from compromised machines and used them to run Claude services without incurring charges. In response, Anthropic signed the victim out and deleted the saved payment method after detecting fraudulent activity.
The user, who initially fell for a malicious download, later cleaned the system with Claude Opus 5 Max. Anthropic clarified that the malware—identified as variants like Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer—is unrelated to Claude itself, merely repurposing existing credential-stealing tools. The company warned that token theft is a growing risk as AI usage expands.
Why it matters
Compromised AI accounts can let criminals consume costly services for free, highlighting new security challenges in the AI industry.
In this story
