Hackers Drain Paid Claude Subscriptions With Stolen Session Cookies — Security article on gikiewicz.com

Hackers have found a way to drain paid Claude subscriptions without ever touching a password. TechCrunch published its investigation on September 8, 2026, confirming that Anthropic had tracked attackers using infostealer malware to hijack accounts through stolen session cookies. The campaign had been taking shape in security forums for weeks before the story broke.

TL;DR: Hackers are hijacking Claude subscriber accounts using infostealer malware that steals session cookies, letting them drain paid token quotas without touching passwords. Anthropic confirmed the attacks bypass 2FA entirely. TechCrunch published its investigation on September 8, 2026, after weeks of security forum reports.

How Are Hackers Stealing Claude Tokens From Subscribers?

The short answer: they steal live sessions, not credentials. According to TechCrunch’s September 8, 2026 investigation, attackers plant infostealer malware on victims’ computers, which then harvests browser session cookies for Claude. Those cookies contain the authentication token that Claude’s web interface uses to keep a user logged in. Anyone holding that cookie can load it into their own browser and appear, to Anthropic’s servers, as the legitimate subscriber.

Once inside, the thief doesn’t change the password or payment details. They simply use the account. Every prompt they run consumes tokens from the victim’s paid quota — whether that’s a $20-per-month Claude Pro plan or a far larger team subscription. DiarioBitcoin reported that subscribers were noticing their accounts consumed tokens with no visible activity of their own, leaving them unable to use a service they were actively paying for.

The attack is quiet by design. Because the login happens with a valid session, nothing about it looks anomalous to basic monitoring. Startup Fortune reported that Anthropic confirmed the intruders used infostealer malware to hijack accounts and drain paid usage, bypassing two-factor authentication through the stolen cookies. In other words, the strongest password in the world offers no protection here. The session was already authenticated.

Think of it this way. A password is the key to the front door. A session cookie is a guest badge that’s already inside the building. The attacker doesn’t need the key — they just clone the badge.

Why Doesn’t Two-Factor Authentication Stop These Attacks?

Because 2FA only guards the front door, and this attack enters through a window marked “already logged in.” Two-factor authentication triggers when someone enters a password on a new device. But when a hacker replays a stolen session cookie, there is no new password entry. There is no login event at all. The server sees a continuation of a session it previously approved.

Startup Fortune’s coverage is explicit on this point: Anthropic confirmed the attacks bypass 2FA via stolen session cookies. That confirmation matters because many subscribers assumed their accounts were safe precisely because they had enabled an additional verification step. The TechCrunch investigation shows that assumption was false in this threat model.

This isn’t a flaw unique to Anthropic. Session hijacking through cookie theft has hit banks, email providers, and crypto exchanges for years. Infostealer logs are traded in bulk on criminal markets, and each log can contain dozens of active sessions for different services. Claude simply became a valuable new target as paid AI subscriptions grew.

So what would actually help? Forced re-authentication, frequent session rotation, and binding sessions to device fingerprints would blunt the attack. Some services flag session reuse from a new IP address or a different browser fingerprint. Until such checks catch every replay, though, a stolen cookie remains a working skeleton key. The victim’s phone never buzzes. There is nothing to approve.

What Do Victims Actually See Happen to Their Accounts?

The first sign is usually a strange number. Subscribers open Claude and find their usage limits exhausted — despite barely using the service themselves. Telepolis described the experience plainly: you pay for AI, you barely use it, and your available limit still vanishes before your eyes. That turns out not to be a bug on Anthropic’s side.

DiarioBitcoin’s reporting adds a second, more unsettling detail. Subscribers reported accounts consuming tokens with no visible activity in their history. The lack of a detailed usage trail made it harder for victims to prove what had happened, since the drain didn’t always map cleanly onto sessions they could inspect themselves.

One case stood out in the TechCrunch investigation. A Claude user noticed last month that something was wrong with his account, and his report became part of the pattern that had been accumulating in security forums. Individual users initially suspected everything from usage miscalculations to family members borrowing access. Only later did the common thread emerge: infostealer infections on their own machines.

The practical damage is financial and operational at once. The victim keeps paying the subscription while a stranger burns through the quota. Rate limits reset on the billing cycle, so a drained account may stay unusable for days. In the meantime, a thief may also read conversation history containing sensitive work material. That quiet data exposure can matter more than the lost tokens.

What Is Infostealer Malware and How Does It Grab Sessions?

An infostealer is exactly what the name promises: malware built to collect credentials, cookies, and browser data from an infected machine, then ship it all to the operator. TechCrunch and its follow-up coverage identify infostealers as the tool behind the Claude campaign. These are not exotic weapons — families like this have circulated for years and are rented cheaply on criminal forums.

The typical infection path is mundane. A pirated software crack, a malicious browser extension, a fake installer, or a phishing attachment drops the payload. Once running, the stealer scrapes browser cookie databases, saved passwords, autofill data, and cryptocurrency wallet files. The result is packaged into a “log” and uploaded to a server the attacker controls.

For session hijacking, the cookie database is the prize. When you check “remember me” on claude.ai, your browser stores a durable authentication cookie. The infostealer copies it. The attacker then loads that cookie into their own browser using a session-restoration technique, and Claude treats them as the logged-in subscriber. Antyweb’s coverage framed the broader trend well: this is a new species of thief targeting the most valuable resource of the AI era — access itself.

Why do criminals want Claude tokens rather than banking logins? Because resale is easy and risk is low. Stolen Claude access can be sold or used to run workloads someone else pays for, and victims often don’t notice for weeks. It leaves no chargeback trail like a stolen credit card would. For a criminal, a live AI subscription is close to free compute. The consequence for the legitimate owner is a bill with nothing to show for it.

What Has Anthropic Said About the Token Theft Campaign?

Anthropic has confirmed that hackers used infostealer malware to hijack Claude accounts and drain paid usage, bypassing two-factor authentication with stolen session cookies (Startup Fortune, 2026). The company warned users about session theft driven by malware infections on their own devices. That is an important distinction. Anthropic’s infrastructure was not compromised.

According to reporting from DiarioBitcoin, Anthropic noted the theft of sessions via malware in some cases, but the lack of a detailed usage history made it harder for victims to verify what happened. The confirmation came after TechCrunch published its investigation on September 8, 2026, which had been taking shape in security forums for weeks beforehand (wwwhatsnew). The company’s guidance focuses on device hygiene rather than account-side fixes. Why? Because the infection lives on the user’s machine.

Anthropic reportedly advised affected subscribers to run malware scans, revoke active sessions, and treat the compromised device as untrusted until cleaned. Session revocation is the key control here. Once cookies are invalidated, stolen tokens stop working — at least until the attacker tricks the user into logging in on a fresh phishing page.

Why Are Stolen AI Sessions More Valuable Than Passwords?

Because session cookies work even when the password stays secret and 2FA stays enabled (Startup Fortune, 2026). An infostealer harvests the cookie from the browser, and the attacker replays it from their own machine. Anthropic’s servers see a valid, already-authenticated session. No login prompt appears. No second factor is requested.

For a paid Claude subscription, this is attractive economics. The attacker gets access to expensive model capacity — the exact resource subscribers pay for — without touching payment details. As Antyweb noted, tokens have become the most valuable resource of the AI era, and a new kind of thief has emerged to steal exactly that.

There is also a lower risk profile for criminals. Password theft often triggers credential-change alerts, payment fraud investigations, or card chargebacks. Draining usage limits leaves fewer obvious traces. DiarioBitcoin reported that subscribers saw their accounts consume tokens with no visible activity, and the missing usage history made the abuse hard to prove. Hard to prove means hard to stop.

How Can Claude Users Tell If Their Tokens Are Being Drained?

The main symptom reported by victims is usage disappearing without any activity of their own. Telepolis framed it bluntly: you pay for the AI, you don’t use it, and your available limit still vanishes before your eyes — and it may not be an Anthropic bug at all.

Subscribers described accounts consuming tokens with no visible sessions or history to explain the burn rate (DiarioBitcoin, 2026). That gap between consumed quota and recorded activity is the clearest red flag. A few practical checks follow from the reporting:

  • Usage limits exhausted hours or days earlier than your normal pattern
  • Token consumption during hours when you were not working
  • Missing or incomplete usage history inside the account
  • Active sessions or devices you do not recognize
  • Password unchanged, 2FA enabled — yet quota still drains
  • Warnings from Anthropic about session theft via malware
  • Browser slowdowns or crashes preceding the anomaly
  • Antivirus detections on the machine used for Claude

If several of these line up, treat the device as infected first. The account is the symptom.

What Should Subscribers Do to Protect Their Accounts?

Start by assuming the compromise lives on your computer, since Anthropic confirmed the attacks relied on infostealer malware running on victims’ devices (Startup Fortune, 2026). Cleaning the endpoint comes before anything else. Otherwise the next login simply produces fresh cookies for the attacker.

The protective steps recommended in the coverage:

  • Run a full malware scan and remove any infostealer detections
  • Revoke all active sessions from account settings
  • Change your password from a known-clean device
  • Keep 2FA enabled — it still protects the login itself
  • Avoid pirated software and suspicious installers, common infostealer vectors
  • Review usage history regularly for unexplained consumption
  • Log out of Claude on shared or untrusted machines
  • Consider a dedicated browser profile for AI work accounts

Note that 2FA alone did not prevent these attacks. Stolen cookies sit past the authentication step entirely. Device hygiene is the control that actually breaks the attack chain described by Anthropic and TechCrunch.

Could Other AI Subscription Services Be Next?

Almost certainly, because nothing in the attack chain is specific to Claude. The technique — infostealer harvesting session cookies, then replaying them to bypass 2FA — works against any service that keeps users logged in through browser cookies. Most AI platforms do exactly that.

The campaign simply targeted the most valuable resource first. Antybe’s reporting described token theft as an emerging category of crime aimed at the AI era’s scarcest asset: paid model capacity. As competing subscriptions carry similar usage limits and monthly fees, the same economics apply. A drained ChatGPT or Gemini quota would look identical from the victim’s side.

TechCrunch’s investigation surfaced because victims compared notes publicly. Expect the same pattern elsewhere. Subscribers on any platform should watch for unexplained usage, not just suspicious logins.

Frequently Asked Questions

Does changing my password stop the token theft?

Not by itself. The attackers described by Anthropic used stolen session cookies that bypass authentication entirely, including 2FA (Startup Fortune, 2026). Revoking active sessions and removing the infostealer malware from the device are the steps that actually cut off access.

Was Anthropic’s infrastructure breached in these attacks?

No. Anthropic confirmed the thefts resulted from infostealer malware on subscribers’ own computers, not a breach of its systems (Startup Fortune, 2026). The company warned about session theft via malware in some cases, while noting that missing usage history complicated verification (DiarioBitcoin, 2026).

Do free Claude users face the same risk as paid subscribers?

The reported campaign targeted paid subscribers because their accounts hold valuable usage quotas that can be resold or consumed. Free-tier accounts have far lower limits, which makes them unattractive to attackers draining tokens. The session-theft technique itself, however, would work against any account.

When did reports about this campaign first surface?

TechCrunch published its investigation on September 8, 2026, but the story had been forming in security forums for weeks before that date (wwwhatsnew, 2026). One victim noticed his account behaving strangely a month earlier, according to the reporting (PressBee, 2026).

Summary

  • Attackers used infostealer malware to steal Claude session cookies, bypassing passwords and 2FA entirely (Startup Fortune, 2026).
  • Anthropic confirmed the campaign targeted devices, not its infrastructure, and warned users about malware-driven session theft.
  • The clearest symptom is usage draining with no visible activity and little usage history to audit (DiarioBitcoin, 2026).
  • Protection means malware removal, session revocation, and device hygiene — password changes alone don’t help.
  • The same technique threatens any AI subscription built on browser session cookies.

Check your Claude usage history today. If the numbers don’t match your work, revoke your sessions and scan your machine before anything else.