HomeArticle

Breaking: Claude has suffered a large-scale account theft incident, and a large number of users' accounts have been forcibly deactivated.

新智元2026-08-31 11:52
Overnight, your Claude may no longer belong to you

Just now, a massive account security incident suddenly broke out at Anthropic, and a large number of Claude users were forcibly logged out of their accounts!

In the past couple of days, a large number of Claude users found that without any warning of account ban, their accounts were suddenly forced to log off.

Even the payment methods such as Visa and Mastercard bound in the backend were urgently cleared by the official!

For a moment, users were in an uproar.

However, don't rush to criticize the official this time. Anthropic is not making unreasonable troubles this time, but taking emergency measures to protect users from huge losses.

The truth is: a global, covert hunting operation targeting AI users has already broken out!

Now, hackers are no longer targeting the balance of your bank card, but starting to steal AI computing power.

In this era when computing power is as precious as gold, your AI computing power is very likely being stolen and used for free by hackers frantically without your awareness.

Midnight Scare: An Official "Forced Logout" Email

"Your account has abnormal activities, we have forcibly logged you out and deleted your payment methods."

This time, in the official email, Anthropic directly named six types of trojans. If you feel that your computer has slowed down recently or there are abnormal logins on your account, please be alert to the following names immediately:

Windows System:

Vidar: A long-established information-stealing trojan that specifically collects browser passwords, browsing history, and even your encrypted wallet keys.

Lumma (LummaC2): It has been extremely rampant recently. Some users reported that when they were writing code with Claude, Windows Defender kept alerting and blocking Lumma.

StealC: A lightweight MaaS, one of the main successors after Lumma lost its influence, and it was still among the four active trojan families in early 2026

RedLine: One of the oldest trojan families; its servers were taken down by the Dutch police and the US FBI in October 2024, and its developers were indicted in the United States

Acreed: It was first observed by Webz on February 10, more than 4000 log records were uploaded in the first week, and it soon surpassed Raccoon, RedLine, Vidar and StealC in scale

Mac System:

Atomic Stealer (AMOS): A small number of Mac users were also compromised in this attack. AMOS is an information-stealing trojan specifically targeting macOS, which also sneaks into computers through cracked software and fake app updates (such as pretending to be a browser upgrade), and directly steals your Keychain and browser cookies.

What's even more terrifying is that if you are infected with the above trojans, your bank card, web versions of WeChat/Alipay, and the access permissions to your company's internal system are very likely to have been completely exposed on the hackers' servers.

The trigger of this incident was a personal experience shared by a user on Reddit.

A few days ago, he received a red alert email from the official Claude in his sleep.

"Your account has abnormal activities, we have forcibly logged you out and deleted your payment methods."

Before that, this user had just experienced a nightmare.

His social media account was hacked by attackers and used to send cryptocurrency scam messages.

Fortunately, he knew a little about technology, he spent a lot of effort to clean up the virus, and quickly changed the passwords of all accounts.

He originally thought that changing the passwords would make him safe, but he never expected that the hackers' conspiracy had just begun.

In the middle of the night, the official Claude sent a warning: Someone is frantically stealing his tokens through the API!

This user's experience is by no means an isolated case.

Since last weekend, a large number of users have reported that their accounts were inexplicably kicked offline and required to log in again.

When they opened the settings, they found that their bound credit cards had disappeared out of thin air!

Subsequently, many media followed up and reported: A large-scale account security incident broke out at Anthropic.

In order to prevent users from suffering greater economic losses, the official is taking extreme measures — forcibly logging out the accounts of infected users, and directly physically deleting the bank card information stored in the accounts!

How did the hackers do it?

Anthropic explained in the email:

We found that malicious attackers are using common information-stealing trojans to steal Claude's login sessions (session credentials) from users' computers. Then they use these credentials to directly sneak into your account and frantically consume your usage quota.

Moreover, the official also gave a "self-check standard": "If your Claude quota is inexplicably restored, and then suddenly exhausted when you are not using it at all, this is most likely the reason."

It is completely beyond expectation: in 2026, trojans have even started to steal computing power!

Why Are You Still Hacked Instantly Even After Changing Passwords and Enabling 2FA?

In fact, the most frustrating point for that Reddit user is: he had obviously changed his password, logged in through Google account authorization, and even enabled extremely strict 2FA (Two-Factor Authentication)!

How on earth did the hackers get in?

The answer is two words: Session (session cookie).

If Claude is a top club, the account password is your ID card, two-factor authentication (2FA/mobile verification code) is the face recognition at the front desk, and Session / Cookie is a "VIP pass" issued to you by the front desk after confirming your identity.

Under normal circumstances, as long as the VIP pass is within the validity period, you don't need to go to the front desk for face recognition every time.

The hackers' trick is to "bypass the front desk and steal the pass directly".

The culprits of this incident are the aforementioned Vidar, LummaC2, StealC, RedLine, Acreed on Windows, and AMOS on Mac.

These trojans don't care about your passwords and mobile verification codes at all. They lurk in the background of your browser and steal all the cookies and Session IDs you stored locally!

After obtaining these credentials, hackers can forge the same environment on their own computers, then directly log in to your Claude account without a password, and even bypass the strict 2FA two-factor authentication.

As a netizen pointed out: "Simply changing the password has no effect on the Session Cookie that has already been stolen. You must revoke the active sessions first, otherwise the attackers will continue to use your old sessions to do whatever they want."

A Dark Humor Story: When "Pirated Games" Meet "AI Antivirus"

So, how did these trojans get into the computer?

The victimized Reddit user admitted helplessly: "I made a mistake that only a novice would make — I downloaded a cracked version of a game."

Netizens traced the clues step by step, and finally found out: he downloaded the "cracked version" of an old and obscure game on the famous Russian cracked game forum (nicknamed Steam Underground).

Some people complained: Dude, if you insist on running cracked files, please run them in a virtual machine with the network disconnected!

Some even joked: Just wait for GTA6 like us, don't download unknown files randomly.

After all, in the AI era, the cost of using pirated software may be 10,000 times higher than buying the genuine version.

The most surprising thing is this user's amazing operation of "using magic to defeat magic".

After finding that he was compromised, he did not reinstall the system immediately, but let Claude Opus 5 Max act as his antivirus software!

He gave Opus 5 full unrestricted access to his computer, and gave a simple prompt:

I may have downloaded a virus recently, and my login credentials have been stolen. Please audit the malware, delete it if you find it, and report the damage level.

What happened next stunned everyone.

Opus 5 not only instantly scanned the active processes and recent downloads, accurately locked the virus, disabled it, but also carried out reverse engineering on it!

It wrote in the security report:

This attack chain perfectly matches the activity recorded by Malwarebytes in July 2026: RenPy Loader → PavinLoader → Amatera Stealer. Fake game installer, trojanized Ren'Py engine... Amatera is a stealer that steals data and leaves immediately, there is no reason for it to stay.

The user sighed: "This is so terrifying, Opus is so efficient that it makes people feel scared. It is like a cold and evil surgeon dissecting its prey. It not only disabled the virus, but also packaged the virus file on my desktop."

Netizens were completely excited: I declare that Claude is my antivirus software from now on!

However, some people told the truth: Never trust an LLM, especially when a Rootkit is implanted in the underlying system. The safest way is always to physically format the disk and reinstall the system.

Stealing Money Is Not As Profitable As Stealing Computing Power? The New "Profit Code" of Underground Cybercrime

A soul-stirring question is: Hackers went to great lengths to hack into my computer, but they didn't steal my money, instead they stole my AI quota??

If you think so, you are seriously underestimating the business acumen of cybercriminals.

In 2026, computing power is the "digital gold" with the best liquidity and the easiest to launder in the world.

Not to mention that AI computing power is getting more and more expensive, more importantly, due to regional restrictions, payment risk control and other reasons, users in many regions around the world cannot buy official AI quota even if they have money.

The huge gap has spawned a lucrative underground black market — "AI computing power distribution and API transfer station".

After hackers steal your Claude login session, they will perform the following operations.

1. Wrapped shared harvester.

Hackers integrate hundreds of stolen sessions into the backend of a "wrapped website". They sell them to unsuspecting ordinary users at the price of "9.9 yuan for unlimited chatting", and all the usage consumed by those users comes from your account quota!