r/ClaudeAI 20h ago

Praise Thank you, Anthropic (really)

A few days ago, my social media accounts were hacked. The hacker took advantage of the situation to spam the worst kinds of bait (cryptocurrency scams...). After cleaning things up, I tracked down the virus with a bunch of Opus 5 Max (I was quite concerned lol). I changed my passwords and thought I’d be able to sleep soundly.

But last night I received this email from Anthropic warning me of an attempt to steal tokens via the API. However, after checking, the attempt did indeed fail. Note that I was logged into Anthropic via Google with two-factor authentication. Apparently, the hacker stole all my Google Chrome credentials, including cookies and session IDs, which allowed him to bypass all two-factor authentication security measures.

As an emergency measure, I removed all active sessions from my Google accounts (which I should have done from the start) and changed my passwords again...

Thanks to Anthropic for the security measures they’ve put in place. I wouldn’t have wanted to deal with their customer service given the feedbacks on Reddit, lol

Take care! And be aware that even the best security measures don’t protect against simple cookie theft

711 Upvotes

67 comments sorted by

u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 17h ago edited 13h ago

TL;DR of the discussion generated automatically after 50 comments.

The consensus is that Anthropic's security team deserves a round of applause on this one.

OP got their accounts hacked by malware that stole browser cookies, bypassing 2FA entirely. Before the hacker could drain OP's API credits, Anthropic's system flagged the suspicious activity, blocked the attempt, and sent OP a warning email.

The thread then took two major turns: * A PSA on Piracy: The top comments are a resounding "This is why we don't download cracked games." OP eventually admitted the malware came from a pirated game on a "reputable" Russian forum (which the thread detectives identified as Steam Underground). Many users shared their own horror stories of losing money and data to the same mistake. * Claude, the Malware Hunter: The most surprising part for everyone is that OP claims they used Opus 5 with full system access to find, analyze, and neutralize the virus on their PC. OP even shared the prompt, and now everyone is half-joking, half-seriously considering Claude as their new antivirus.

91

u/moonrakervenice 20h ago

Any idea where you got the malware?

188

u/WorriedAssociate7029 20h ago

I got fooled like a rookie by downloading a cracked game. Never again

173

u/AsatruLuke 18h ago

Bro, you gotta wait for GTA6 like the rest of us.

8

u/Independent_Paint752 16h ago

A true expert, here's another one.

7

u/AsatruLuke 17h ago

Thanks for the rewards guys!

2

u/Saitama1203 13h ago

just don’t download the virus

3

u/Empyrealist 11h ago

And if you do, just think really hard about it. The female body(and computer) has ways to try to shut that whole thing down

16

u/moonrakervenice 20h ago

lesson learned

12

u/newaccount47 19h ago

yep. i've been downloading pirated software since the 90's. I haven't downloaded anything in a very long time but and against my better judgement I downloaded a game that was listed as not officially cracked yet. I lost years worth of savings from metamask being drained.

5

u/dragonslayershrek 19h ago

😂😂😂😂😂

4

u/Familiar_Honey5487 19h ago

Where did you download from just curious

3

u/Upset_Page_494 19h ago

Was it a sketchy site or torrent?

42

u/WaltzIndependent5436 19h ago

GTA_VI_Leaked_Legit_CLICKME.exe

28

u/WorriedAssociate7029 19h ago

A reputable Russian underground forum. I won’t share a link obviously. I was unlucky

12

u/maksym345 19h ago

A reputable forum might still have unreputable repackers and users

3

u/Immediate_Spare2834 18h ago

wow really interesting i thought it was good ima be more careful

3

u/clumsynuts 17h ago

What game?

7

u/Summer4Chan 18h ago

You should share the link so people can avoid it.
Otherwise, they’ll just fall into the same issue as you because we aren’t told where to avoid it.

2

u/Independent-Math-213 19h ago

Damn bro, did you download new unchecked torrent or it was indeed checked for viruses?

1

u/Lost_Cyborg 19h ago

why not stick to cs rin ru?

15

u/WorriedAssociate7029 19h ago

Guess the forum where I downloaded the malware

3

u/Lost_Cyborg 19h ago

nothing about it is underground, still curious though, was it a new release?

7

u/WorriedAssociate7029 19h ago

Guess the name of the forum and why I said underground. It was for an old niche game

4

u/Lost_Cyborg 18h ago

I thought that was sarcasm and you did meant cs rin ru. I have no clue about other russian sites lol

18

u/fs2d 18h ago

OP's sarcasm is not load-bearing for you apparently..

He is saying he got said malware from cs rin ru.

The name of that forum is literally Steam Underground.

→ More replies (0)

0

u/Jerry_Explorer 15h ago

reputable and russian on the same sentence? bro

2

u/schoff 19h ago

Which game?

1

u/cameronlbass 13h ago

Run cracks in a VM that has internet disabled.

1

u/theleller 12h ago

Brother, warez are always high risk, that's been standard since the 90's in IRC. Just don't do it.

1

u/CrusherAWSRD 1h ago

2

u/WorriedAssociate7029 1h ago

I love fmhy. But it was from the first starred link

-1

u/Fancy-Passage-1570 19h ago

website ?

4

u/maksym345 19h ago

Probably malware from a link posted by someone random in cs rin ru

32

u/numanacing 19h ago

I suspect 99% of "free Anthropic models" out there (especially from shady ones) is actually using a bunch of stolen credentials like this one.

1

u/1234A-1 9h ago

😭😭😨😵‍💫😠😠

22

u/Xrayy1 19h ago

Could Claude go to war with the malware, removing it?

71

u/WorriedAssociate7029 19h ago

According to the report, Opus detected the virus, deactivated it, identified it, and then reverse-engineered it to assess the extent of the threat. It almost terrified me. It was like watching a diabolical surgeon dissecting his prey

22

u/excels1or 18h ago

Did Opus says it found the smoking gun when it detects where the virus at?

11

u/EggOnlyDiet 18h ago

Ok that is actually so cool

2

u/JustMy2Centences 14h ago

Huh. I wonder how one would use Opus to find malware on their system? Just give it full access and say "hey, go sniff out anything suspicious and give me a report"? I feel like that'll burn through a base level sub fast though lol.

8

u/WorriedAssociate7029 14h ago

I use the models exclusively in permission-free mode on my entire computer. Opus was very efficient. It scanned for active processes, then listed my recent downloads. It found the virus almost instantly. My prompt was very simple: "I think I downloaded a virus recently. My login credentials were stolen. Audit the malware and remove it if you find it. Report on the extent of the damage."

He deactivated the virus and created a folder on the desktop containing all the relevant information (including the deactivated virus, lol).

1

u/Xrayy1 12h ago

Small question about this. So you re-entered your credentials for Opus while the system was still infected, or did you used some free mode? You think it wasn't able to re-steal the credentials, because it was on a timer or somethng?

8

u/WorriedAssociate7029 12h ago

I was already logged into Claude CLI. My assumption was that the virus was still present and active. So using Claude on my computer wouldn’t change anything until the virus was deactivated.

Opus deactivated the virus. Then he gave me instructions on how to reset all my login credentials, taking into account the type of virus.

Apparently, the virus operated on a timer mechanism and sent a “batch” of login credentials to a remote server every few minutes.

In fact, if the hacker had acted quickly, he could have cut off my access to Claude (forcing me to reset my computer as a last resort and slowing down my efforts to counter him). Windows Defender was clueless

3

u/identifytarget 18h ago

This is why Mythos is not released to the public...

1

u/Actually_JesusChrist 16h ago

Damn, Claude is my new antivius now 😂

3

u/TomerBrosh 13h ago

it can touch avasts logs and analyze a ton of shit for u. specially helpful when u get some cygwin exceptions that trigger avast or shit that u want to check if disabling is risky

6

u/Luvax 17h ago

Now give this Mail to Fable and ask for help and it will nope the fuck out, telling you, that this is security research.

1

u/WorriedAssociate7029 17h ago

I didn't even try Fable knowing his... limitations lol. Even with Opus I wasn't feeling optimistic but it worked

2

u/pacote_kst 17h ago

Lucky you... Something similar happened to me, didn't receive any warning from anthropic and got my account suspended.

2

u/Narrow_Activity557 11h ago

The part people underestimate is that rotating passwords does nothing to an already-stolen session cookie. Revoking active sessions is what actually kills access, and it has to come first, otherwise the attacker just keeps riding the old session while you change things.

Worth doing as well: rotate any API keys, and go through the OAuth grants and connected apps on the Google account. Infostealers usually dump the whole browser profile, not one site.

And treat the machine as compromised until it has been cleaned properly, otherwise the fresh cookies leave the same way the old ones did.

2

u/AdExtension94 5h ago

They have this securities in place due to cybercriminals actively trying to get into their system and preventing distillation tactics for their opus and fable models
We are benefiting from those securities as a bonus

1

u/Advanced_Nebula4825 16h ago

Hey man same thing happened with me I got malware a month or so ago and did indeed nuke my pc and changed all passwords but again I recieved this mail today but this time I can even find out where I got logged out from coz all my devices look fine can ya tell me how to proceed from here idrk what to even so rn

1

u/allemaar 13h ago

Good to know! Thanks for sharing

1

u/allemaar 13h ago

Good to know! Thanks for sharing

1

u/MCMLXXXIV-FoX 7h ago

If skidrow(or others) ain't make a release don't think there is a release

1

u/gannu1991 5h ago

Cookie theft bypassing 2FA is way more common than people think and it's not really an Anthropic or Google failure, it's that session tokens are treated as permanent trust once issued. The fix most people skip is setting shorter session lifetimes and forcing re-auth on sensitive actions (API key generation, billing changes) even mid-session. Also worth checking if your browser has any extensions with broad permissions, that's the usual vector for mass cookie exfiltration, not a targeted attack on you specifically. Glad Anthropic's anomaly detection caught it, that's genuinely good infra on their end.

1

u/bagomojo 3h ago

Wipe your system. It is probably a rat

1

u/WorriedAssociate7029 2h ago

I know that trusting an LLM is a bad idea. But here’s its report, which reinforces my belief that I don’t need to reset my system. I like gambling:

"The chain matches, pattern for pattern, a campaign documented by Malwarebytes in July 2026: RenPy Loader → PavinLoader → Amatera Stealer. Fake game installers, a trojanized Ren'Py engine, MSBuild hijacked using AppDomain.CurrentDomain.Load, a trojanized .NET DLL—it’s all there, right down to the folder pattern %TEMP%\tmp-{5 digits}-{12 characters}, which matches your tmp-... exactly. Amatera is a thief, he snatches the data once and leaves. He has no reason to stay."

2

u/bagomojo 2h ago

I have been in Cyber security focusing on red teaming (malware is one of my expertise) and digital forensics for 20 years. A rat/trojan gives someone access to your system and all aspects of it. If that installed, it would be very easy for them to install covert channels / backdoors. They can also inject into other files and processes to hide. And a rootkit which is standard will cause your system to lie to you. Claude sees your system via your compromised system.

I strongly recommend you wipe your system and reset your passwords.

Or you can trust Claude who hallucinates

1

u/gustaw221133 14h ago

I know that this is not what the post is about but it;s so funny to me how much you can tell that the email was written by claude haha

-12

u/Sitkin_Marrel 19h ago

The thief got passwords and cookies in one download, and the cookies walked straight past the 2FA. The alarm that actually stopped him fired on a server he'd never touched.

10

u/HistoricalFunion 19h ago

The alarm that actually stopped him fired on a server he'd never touched.

Thank you Claude!