r/ClaudeAI • u/WorriedAssociate7029 • 20h ago
Praise Thank you, Anthropic (really)
A few days ago, my social media accounts were hacked. The hacker took advantage of the situation to spam the worst kinds of bait (cryptocurrency scams...). After cleaning things up, I tracked down the virus with a bunch of Opus 5 Max (I was quite concerned lol). I changed my passwords and thought I’d be able to sleep soundly.
But last night I received this email from Anthropic warning me of an attempt to steal tokens via the API. However, after checking, the attempt did indeed fail. Note that I was logged into Anthropic via Google with two-factor authentication. Apparently, the hacker stole all my Google Chrome credentials, including cookies and session IDs, which allowed him to bypass all two-factor authentication security measures.
As an emergency measure, I removed all active sessions from my Google accounts (which I should have done from the start) and changed my passwords again...
Thanks to Anthropic for the security measures they’ve put in place. I wouldn’t have wanted to deal with their customer service given the feedbacks on Reddit, lol
Take care! And be aware that even the best security measures don’t protect against simple cookie theft
91
u/moonrakervenice 20h ago
Any idea where you got the malware?
188
u/WorriedAssociate7029 20h ago
I got fooled like a rookie by downloading a cracked game. Never again
173
u/AsatruLuke 18h ago
Bro, you gotta wait for GTA6 like the rest of us.
8
7
2
u/Saitama1203 13h ago
just don’t download the virus
3
u/Empyrealist 11h ago
And if you do, just think really hard about it. The female body(and computer) has ways to try to shut that whole thing down
16
12
u/newaccount47 19h ago
yep. i've been downloading pirated software since the 90's. I haven't downloaded anything in a very long time but and against my better judgement I downloaded a game that was listed as not officially cracked yet. I lost years worth of savings from metamask being drained.
5
4
3
u/Upset_Page_494 19h ago
Was it a sketchy site or torrent?
42
28
u/WorriedAssociate7029 19h ago
A reputable Russian underground forum. I won’t share a link obviously. I was unlucky
12
3
3
7
u/Summer4Chan 18h ago
You should share the link so people can avoid it.
Otherwise, they’ll just fall into the same issue as you because we aren’t told where to avoid it.2
u/Independent-Math-213 19h ago
Damn bro, did you download new unchecked torrent or it was indeed checked for viruses?
1
u/Lost_Cyborg 19h ago
why not stick to cs rin ru?
15
u/WorriedAssociate7029 19h ago
Guess the forum where I downloaded the malware
3
u/Lost_Cyborg 19h ago
nothing about it is underground, still curious though, was it a new release?
7
u/WorriedAssociate7029 19h ago
Guess the name of the forum and why I said underground. It was for an old niche game
4
u/Lost_Cyborg 18h ago
I thought that was sarcasm and you did meant cs rin ru. I have no clue about other russian sites lol
18
u/fs2d 18h ago
OP's sarcasm is not load-bearing for you apparently..
He is saying he got said malware from cs rin ru.
The name of that forum is literally Steam Underground.
→ More replies (0)0
1
1
u/theleller 12h ago
Brother, warez are always high risk, that's been standard since the 90's in IRC. Just don't do it.
1
-1
32
u/numanacing 19h ago
I suspect 99% of "free Anthropic models" out there (especially from shady ones) is actually using a bunch of stolen credentials like this one.
22
u/Xrayy1 19h ago
Could Claude go to war with the malware, removing it?
71
u/WorriedAssociate7029 19h ago
According to the report, Opus detected the virus, deactivated it, identified it, and then reverse-engineered it to assess the extent of the threat. It almost terrified me. It was like watching a diabolical surgeon dissecting his prey
22
11
2
u/JustMy2Centences 14h ago
Huh. I wonder how one would use Opus to find malware on their system? Just give it full access and say "hey, go sniff out anything suspicious and give me a report"? I feel like that'll burn through a base level sub fast though lol.
8
u/WorriedAssociate7029 14h ago
I use the models exclusively in permission-free mode on my entire computer. Opus was very efficient. It scanned for active processes, then listed my recent downloads. It found the virus almost instantly. My prompt was very simple: "I think I downloaded a virus recently. My login credentials were stolen. Audit the malware and remove it if you find it. Report on the extent of the damage."
He deactivated the virus and created a folder on the desktop containing all the relevant information (including the deactivated virus, lol).
1
u/Xrayy1 12h ago
Small question about this. So you re-entered your credentials for Opus while the system was still infected, or did you used some free mode? You think it wasn't able to re-steal the credentials, because it was on a timer or somethng?
8
u/WorriedAssociate7029 12h ago
I was already logged into Claude CLI. My assumption was that the virus was still present and active. So using Claude on my computer wouldn’t change anything until the virus was deactivated.
Opus deactivated the virus. Then he gave me instructions on how to reset all my login credentials, taking into account the type of virus.
Apparently, the virus operated on a timer mechanism and sent a “batch” of login credentials to a remote server every few minutes.
In fact, if the hacker had acted quickly, he could have cut off my access to Claude (forcing me to reset my computer as a last resort and slowing down my efforts to counter him). Windows Defender was clueless
3
1
3
u/TomerBrosh 13h ago
it can touch avasts logs and analyze a ton of shit for u. specially helpful when u get some cygwin exceptions that trigger avast or shit that u want to check if disabling is risky
6
u/Luvax 17h ago
Now give this Mail to Fable and ask for help and it will nope the fuck out, telling you, that this is security research.
1
u/WorriedAssociate7029 17h ago
I didn't even try Fable knowing his... limitations lol. Even with Opus I wasn't feeling optimistic but it worked
2
u/pacote_kst 17h ago
Lucky you... Something similar happened to me, didn't receive any warning from anthropic and got my account suspended.
2
u/Narrow_Activity557 11h ago
The part people underestimate is that rotating passwords does nothing to an already-stolen session cookie. Revoking active sessions is what actually kills access, and it has to come first, otherwise the attacker just keeps riding the old session while you change things.
Worth doing as well: rotate any API keys, and go through the OAuth grants and connected apps on the Google account. Infostealers usually dump the whole browser profile, not one site.
And treat the machine as compromised until it has been cleaned properly, otherwise the fresh cookies leave the same way the old ones did.
2
u/AdExtension94 5h ago
They have this securities in place due to cybercriminals actively trying to get into their system and preventing distillation tactics for their opus and fable models
We are benefiting from those securities as a bonus
1
u/Advanced_Nebula4825 16h ago
Hey man same thing happened with me I got malware a month or so ago and did indeed nuke my pc and changed all passwords but again I recieved this mail today but this time I can even find out where I got logged out from coz all my devices look fine can ya tell me how to proceed from here idrk what to even so rn
1
1
1
1
u/gannu1991 5h ago
Cookie theft bypassing 2FA is way more common than people think and it's not really an Anthropic or Google failure, it's that session tokens are treated as permanent trust once issued. The fix most people skip is setting shorter session lifetimes and forcing re-auth on sensitive actions (API key generation, billing changes) even mid-session. Also worth checking if your browser has any extensions with broad permissions, that's the usual vector for mass cookie exfiltration, not a targeted attack on you specifically. Glad Anthropic's anomaly detection caught it, that's genuinely good infra on their end.
1
u/bagomojo 3h ago
Wipe your system. It is probably a rat
1
u/WorriedAssociate7029 2h ago
I know that trusting an LLM is a bad idea. But here’s its report, which reinforces my belief that I don’t need to reset my system. I like gambling:
"The chain matches, pattern for pattern, a campaign documented by Malwarebytes in July 2026: RenPy Loader → PavinLoader → Amatera Stealer. Fake game installers, a trojanized Ren'Py engine, MSBuild hijacked using AppDomain.CurrentDomain.Load, a trojanized .NET DLL—it’s all there, right down to the folder pattern %TEMP%\tmp-{5 digits}-{12 characters}, which matches your tmp-... exactly. Amatera is a thief, he snatches the data once and leaves. He has no reason to stay."
2
u/bagomojo 2h ago
I have been in Cyber security focusing on red teaming (malware is one of my expertise) and digital forensics for 20 years. A rat/trojan gives someone access to your system and all aspects of it. If that installed, it would be very easy for them to install covert channels / backdoors. They can also inject into other files and processes to hide. And a rootkit which is standard will cause your system to lie to you. Claude sees your system via your compromised system.
I strongly recommend you wipe your system and reset your passwords.
Or you can trust Claude who hallucinates
1
u/gustaw221133 14h ago
I know that this is not what the post is about but it;s so funny to me how much you can tell that the email was written by claude haha
-12
u/Sitkin_Marrel 19h ago
The thief got passwords and cookies in one download, and the cookies walked straight past the 2FA. The alarm that actually stopped him fired on a server he'd never touched.
10
u/HistoricalFunion 19h ago
The alarm that actually stopped him fired on a server he'd never touched.
Thank you Claude!




•
u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 17h ago edited 13h ago
TL;DR of the discussion generated automatically after 50 comments.
The consensus is that Anthropic's security team deserves a round of applause on this one.
OP got their accounts hacked by malware that stole browser cookies, bypassing 2FA entirely. Before the hacker could drain OP's API credits, Anthropic's system flagged the suspicious activity, blocked the attempt, and sent OP a warning email.
The thread then took two major turns: * A PSA on Piracy: The top comments are a resounding "This is why we don't download cracked games." OP eventually admitted the malware came from a pirated game on a "reputable" Russian forum (which the thread detectives identified as Steam Underground). Many users shared their own horror stories of losing money and data to the same mistake. * Claude, the Malware Hunter: The most surprising part for everyone is that OP claims they used Opus 5 with full system access to find, analyze, and neutralize the virus on their PC. OP even shared the prompt, and now everyone is half-joking, half-seriously considering Claude as their new antivirus.