Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Anthropic blocks stolen Claude accounts used to mine AI tokens

Anthropic detected and disabled user accounts that had been compromised by infostealer malware to run unpaid Claude services.

Anthropic has begun forcibly terminating accounts that were hijacked by infostealer malware to exploit paid Claude AI tokens. According to an email forwarded by a Reddit user, attackers harvested login details, cookies and session IDs from compromised machines and used them to run Claude services without incurring charges. In response, Anthropic signed the victim out and deleted the saved payment method after detecting fraudulent activity.

The user, who initially fell for a malicious download, later cleaned the system with Claude Opus 5 Max. Anthropic clarified that the malware—identified as variants like Vidar, LummaC2, StealC, RedLine, Acreed and Atomic Stealer—is unrelated to Claude itself, merely repurposing existing credential-stealing tools. The company warned that token theft is a growing risk as AI usage expands.

Why it matters

Compromised AI accounts can let criminals consume costly services for free, highlighting new security challenges in the AI industry.

In this story

AI tokensaccount hijackinginfostealer malwareClaudesession cookiestoken theftpaid usage
Get the beta ↗