Recently, the Anthropic platform experienced a large-scale account security incident, with many Claude users being forcibly logged out without prior warning. Moreover, the official even urgently removed payment methods such as Visa and Mastercard bound in the user's backend. The crisis behind this was not an arbitrary operation by the official side, but rather a covert hunting campaign launched by hackers against global AI users. Today, the hackers' target has shifted from bank card balances to expensive AI computing power and API quotas.
According to the official statement from Anthropic, the culprit behind this security incident is various information-stealing malware lurking in users' computers. On Windows systems, common types of malware include Vidar, Lumma, StealC, RedLine, and Acreed; while on Mac systems, AMOS (Atomic Stealer) is mainly active. These malware often disguise themselves as cracked games, software updates, or unofficial resources, secretly infiltrating users' computer systems, stealing passwords from browsers, browsing history, encrypted wallet keys, and even locally stored Cookies and Session authentication credentials.
Many users are confused about why their accounts were still breached even though they had changed their passwords and enabled strict two-factor authentication (2FA). The core reason lies in the hackers' strategy of "bypassing the front end and directly stealing the access card." After the malware steals the user's Session (session Cookie), hackers can perfectly replicate the same environment on their own devices and achieve passwordless login, rendering two-factor authentication meaningless. As long as the active session is not manually revoked, attackers can continue to use the old session to steal quotas.
With the high cost of computing power today, stealing AI computing power has evolved into a lucrative underground black market. After obtaining the login credentials of Claude, hackers mainly monetize them in two ways: one is to package hundreds of stolen accounts into a shell website and sell "unlimited chat" quotas at low prices to unsuspecting users; the second is to generate API Keys in the background using stolen Sessions and connect to a proxy API selling platform, charging by Token for profit. Since stealing credit cards easily triggers the bank's strict risk control, while "stealing computing power" can quickly and seamlessly convert into cash in the gray area, it has become the "digital gold" in the eyes of hackers.
Faced with serious security threats, Anthropic took extreme and decisive measures to prevent users from suffering more severe financial losses—forcibly logging out infected users' accounts and directly physically deleting the credit card information saved in the account. If your Claude quota suddenly gets completely consumed, the sidebar shows completely unfamiliar conversation history, or your bound credit card suddenly disappears, you are likely to have been compromised.
To guard against such security risks, users need to take thorough defensive measures: first, do not rely solely on changing passwords, but must log in to each key account and manually select "log out of all devices" in the security settings; second, thoroughly clean up browser Cookies and website data to cut off the malware's continuous access permissions; finally, firmly avoid downloading any cracked games or software from non-official channels, and when confirming an infection with high-risk malware, back up files and reinstall the system to ensure complete safety. In this era where AI is deeply integrated into productivity, protecting account credentials is equivalent to protecting core digital assets.
Join Now