Attackers bypassed two factor authentication by stealing post login cookies, then burned victims' paid Claude quotas running AI workloads for resale.
Anthropic has forcibly signed out a set of Claude accounts whose browsers were compromised by commodity infostealers, and began emailing affected users on August 30, 2026. The company also stripped saved payment methods from those accounts.
Anthropic named six malware families — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, plus Atomic Stealer (AMOS) on macOS — that harvest authentication cookies already stored in the user's browser. An infostealer exfiltrates those cookies to an operator server, and the attacker loads them into their own browser to pick up an already-authenticated Claude session. Two-factor authentication does not help because the cookie is post-login proof of identity rather than a fresh credential.
Stolen Claude sessions were used to burn paid usage quotas on the victim's tab and, in some cases, to resell the resulting AI access to other users. That is the activity The Register framed as "mining AI tokens" — not cryptocurrency mining, just draining subscription capacity and arbitrage.
Session-cookie theft is a cross-LLM pattern. Huntress has framed the broader shift to credential-less account takeover. The question Anthropic has not answered in public is how the affected machines were first infected.