
Security·
Session-cookie theft: infostealers drained paid Claude accounts without touching a password
Anthropic says commodity infostealers lifted live Claude session cookies off user machines and replayed them to burn paid usage, bypassing 2FA entirely.
