Gangsta AI
Malware Is Draining People's Claude Accounts Without Ever Logging In — So Anthropic Signed Everyone Out
Cyber Desk

By Chuck Norris · 2026-08-31 · 4 min read

Here's a fact: your password can be the length of a phone book and it wouldn't have mattered. Over the weekend, Anthropic started signing Claude users out of their own accounts — not because they did anything wrong, but because malware on their machines had already walked through the front door carrying their session cookie like a hall pass.
Starting the morning of August 30, Anthropic began reaching out to affected users. The culprit wasn't some exotic AI-on-AI cyberweapon. It was boring, off-the-shelf infostealer malware — Vidar, Lumma, StealC, RedLine and Acreed on Windows, plus Atomic Stealer (AMOS) on a handful of Macs — the same junk that's been draining crypto wallets and gaming logins for years.
The move that makes this one sting: the crooks didn't steal passwords. They stole *already-authenticated session cookies*. That means two-factor authentication and single sign-on never even got a vote. The attacker replays your live session, and Claude sees a logged-in you. They then sat inside paid accounts and quietly burned through usage limits — victims reported their allowance "refilled and then drained while you weren't using Claude."
“They didn't pick the lock. They copied the key while it was still in your pocket.”
What Anthropic actually did
Credit where it's due — the response was fast and unglamorous, which is exactly what you want. Anthropic invalidated the compromised sessions by force-logging users out, removed the saved payment method so nobody could rack up charges on a stored card, and refunded the unauthorized usage. No spin, no "sophisticated nation-state actor" theater. Just: the key's been copied, we're changing the locks, here's your money back.
The uncomfortable part is that none of this was a breach of Anthropic's servers. The theft happened on *user machines*. Which means the same trick works against any account you keep signed in — email, bank, your other AI tools. Claude just happened to be the one with a paid meter attached and a company willing to admit it out loud.
The lesson isn't "trust one AI less"
Here's where it gets bigger than one company. When you funnel your whole workflow through a single AI account, that account becomes a single point of failure — whether it gets hijacked like this, rate-limited at the worst moment, or simply hands you a confident wrong answer. One key, one lock, one way in.
The frontier moves too fast to bet everything on one model anyway. ChatGPT, Claude, Gemini and Grok leapfrog each other by the week, and *no single one is reliably best* at any given question. The tougher setup is the same instinct that beats a stolen cookie: don't rely on one. Ask the same question across a dozen top models at once and let them cross-check each other into one cited verdict — that's the whole idea behind Gangsta AI. When one model is compromised, offline, or just wrong, the other eleven still have your back.
Malware copies the key. A good answer shouldn't depend on a single lock. See how the models stack up on our best-AI breakdown and stop betting your whole day on one login.
Sources / Receipts
- Help Net Security — Anthropic locks out Claude users after infostealers hijack login sessions
- Security Affairs — Infostealers are hijacking Claude sessions and draining subscriptions
- Cyber Security News — Hackers steal Claude login sessions with infostealer malware
- Hero photo: Dario Amodei at TechCrunch Disrupt 2023, Wikimedia Commons (CC BY 2.0)
More: Best AI models · Compare all AI · Frontier Models · All articles