Anthropic Warns of Claude Session Hijacking

Anthropic is warning Claude users that infostealer malware can steal browser cookies and active login sessions, allowing attackers to access accounts and consume paid Claude credits without the password. Because the stolen session represents an already authenticated login, attackers may bypass MFA or 2FA. Anthropic said it began contacting affected users on 30 August. Malware identified in the campaign includes Vidar, LummaC2, StealC, RedLine and Acreed on Windows, as well as Atomic Stealer on some Mac devices. These threats are commonly spread through unofficial downloads and malicious applications. Anthropic has forcibly logged out affected accounts, removed stored payment methods and said it will refund unauthorised Claude charges. The company stressed that the malware did not originate from Claude or result from activity on the platform. Users should remove the malware, change credentials and revoke sessions on other devices. For crypto traders, the incident highlights the wider risk of endpoint compromise: infected devices may also expose exchange logins, API keys, wallet credentials and browser-based trading sessions.
Neutral
The expected direct impact on cryptocurrency prices is neutral because the incident concerns Claude accounts rather than a blockchain network, exchange or crypto asset. It does not change token supply, liquidity, regulation or protocol fundamentals. However, the cybersecurity risk is relevant to traders. Infostealers can capture exchange cookies, API credentials and wallet-related data, potentially causing isolated account theft, unauthorised trades or withdrawals. Similar credential-theft incidents have historically produced short-term caution and higher security awareness, but rarely caused sustained market-wide selling unless a major exchange or large-scale crypto compromise was involved. In the short term, traders may review API permissions, rotate keys and reduce leverage while monitoring for related attacks. In the long term, the event could support demand for stronger account security, hardware wallets, passkeys and session management. Any broader bearish effect would require evidence that the malware campaign has reached major exchanges or caused systemic losses.