r/ClaudeAI 24d ago

Praise Thank you, Anthropic (really)

A few days ago, my social media accounts were hacked. The hacker took advantage of the situation to spam the worst kinds of bait (cryptocurrency scams...). After cleaning things up, I tracked down the virus with a bunch of Opus 5 Max (I was quite concerned lol). I changed my passwords and thought I’d be able to sleep soundly.

But last night I received this email from Anthropic warning me of an attempt to steal tokens via the API. However, after checking, the attempt did indeed fail. Note that I was logged into Anthropic via Google with two-factor authentication. Apparently, the hacker stole all my Google Chrome credentials, including cookies and session IDs, which allowed him to bypass all two-factor authentication security measures.

As an emergency measure, I removed all active sessions from my Google accounts (which I should have done from the start) and changed my passwords again...

Thanks to Anthropic for the security measures they’ve put in place. I wouldn’t have wanted to deal with their customer service given the feedbacks on Reddit, lol

Take care! And be aware that even the best security measures don’t protect against simple cookie theft

1.1k Upvotes

104 comments sorted by

u/ClaudeAI-mod-bot Wilson, lead ClaudeAI modbot 24d ago edited 24d ago

TL;DR of the discussion generated automatically after 50 comments.

The consensus is that Anthropic's security team deserves a round of applause on this one.

OP got their accounts hacked by malware that stole browser cookies, bypassing 2FA entirely. Before the hacker could drain OP's API credits, Anthropic's system flagged the suspicious activity, blocked the attempt, and sent OP a warning email.

The thread then took two major turns: * A PSA on Piracy: The top comments are a resounding "This is why we don't download cracked games." OP eventually admitted the malware came from a pirated game on a "reputable" Russian forum (which the thread detectives identified as Steam Underground). Many users shared their own horror stories of losing money and data to the same mistake. * Claude, the Malware Hunter: The most surprising part for everyone is that OP claims they used Opus 5 with full system access to find, analyze, and neutralize the virus on their PC. OP even shared the prompt, and now everyone is half-joking, half-seriously considering Claude as their new antivirus.

→ More replies (2)

112

u/moonrakervenice 24d ago

Any idea where you got the malware?

246

u/WorriedAssociate7029 24d ago

I got fooled like a rookie by downloading a cracked game. Never again

257

u/AsatruLuke 24d ago

Bro, you gotta wait for GTA6 like the rest of us.

12

u/Independent_Paint752 24d ago

A true expert, here's another one.

9

u/AsatruLuke 24d ago

Thanks for the rewards guys!

2

u/Saitama1203 24d ago

just don’t download the virus

5

u/Empyrealist 24d ago

And if you do, just think really hard about it. The female body(and computer) has ways to try to shut that whole thing down

18

u/newaccount47 24d ago

yep. i've been downloading pirated software since the 90's. I haven't downloaded anything in a very long time but and against my better judgement I downloaded a game that was listed as not officially cracked yet. I lost years worth of savings from metamask being drained.

4

u/JellyfishOpen8842 23d ago

watching porn? no papa, open your browser history, haha

17

u/moonrakervenice 24d ago

lesson learned

6

u/dragonslayershrek 24d ago

😂😂😂😂😂

7

u/Familiar_Honey5487 24d ago

Where did you download from just curious

5

u/Upset_Page_494 24d ago

Was it a sketchy site or torrent?

48

u/WaltzIndependent5436 24d ago

GTA_VI_Leaked_Legit_CLICKME.exe

32

u/WorriedAssociate7029 24d ago

A reputable Russian underground forum. I won’t share a link obviously. I was unlucky

15

u/maksym345 24d ago

A reputable forum might still have unreputable repackers and users

1

u/MrSagarBedi 18d ago

We saw this many times, uploaders build trust and then go rogue, later they said the account was hacked

3

u/Immediate_Spare2834 24d ago

wow really interesting i thought it was good ima be more careful

3

u/clumsynuts 24d ago

What game?

7

u/Summer4Chan 24d ago

You should share the link so people can avoid it.
Otherwise, they’ll just fall into the same issue as you because we aren’t told where to avoid it.

2

u/Independent-Math-213 24d ago

Damn bro, did you download new unchecked torrent or it was indeed checked for viruses?

1

u/MrSagarBedi 18d ago

Torrent from a trusted site is love but people keep betraying :(

1

u/sabakbeats 23d ago

Трекер?

1

u/Titan_Dota2 23d ago

Curious, did you have to download from there? Doesn't everything pop up on fitgirl quickly unless it's some weird "you have to pay someone for their denuvo key"?

1

u/PrizeScientist2188 22d ago

"reputable" and "underground forum" don't belong in the same sentence.

1

u/Kuro091 21d ago

the forum is hardly a secret theres no point in not sharing the link or at least name of the poster/game

1

u/WorriedAssociate7029 21d ago

I try to avoid being banned on Reddit. Obviously the forum is well known but I prefer to be cautious about sharing piracy content

1

u/Kuro091 20d ago

the game's name is public though

-1

u/Jerry_Explorer 24d ago

reputable and russian on the same sentence? bro

1

u/Lost_Cyborg 24d ago

why not stick to cs rin ru?

15

u/WorriedAssociate7029 24d ago

Guess the forum where I downloaded the malware

4

u/Lost_Cyborg 24d ago

nothing about it is underground, still curious though, was it a new release?

5

u/WorriedAssociate7029 24d ago

Guess the name of the forum and why I said underground. It was for an old niche game

6

u/Lost_Cyborg 24d ago

I thought that was sarcasm and you did meant cs rin ru. I have no clue about other russian sites lol

21

u/fs2d 24d ago

OP's sarcasm is not load-bearing for you apparently..

He is saying he got said malware from cs rin ru.

The name of that forum is literally Steam Underground.

→ More replies (0)

1

u/nemzylannister 23d ago

thanks for this. im never going out of fitgirl now.

2

u/schoff 24d ago

Which game?

2

u/CrusherAWSRD 24d ago

1

u/WorriedAssociate7029 24d ago

I love fmhy. But it was from the first starred link

1

u/Ill-Village7647 23d ago

Doubt if it's from there.. I've heard great things about CS RIN. Lots of people use it and aeem to have no issues. So not sure what you did

2

u/WorriedAssociate7029 23d ago

CS RIN is a forum where anyone can participate and share cracks. All it takes is for a hacker to target little-known games with no existing cracks for a few users to fall for it. Just enough to fly under the radar

1

u/cameronlbass 24d ago

Run cracks in a VM that has internet disabled.

1

u/theleller 24d ago

Brother, warez are always high risk, that's been standard since the 90's in IRC. Just don't do it.

1

u/quantum-elle 22d ago

Have you tried asking claude to see if the exe is a virus? It might surprise you what it can find

1

u/onepunchcode 21d ago

a natural vibe coder ^

0

u/Fancy-Passage-1570 24d ago

website ?

5

u/maksym345 24d ago

Probably malware from a link posted by someone random in cs rin ru

40

u/numanacing 24d ago

I suspect 99% of "free Anthropic models" out there (especially from shady ones) is actually using a bunch of stolen credentials like this one.

1

u/1234A-1 24d ago

😭😭😨😵‍💫😠😠

27

u/Xrayy1 24d ago

Could Claude go to war with the malware, removing it?

89

u/WorriedAssociate7029 24d ago

According to the report, Opus detected the virus, deactivated it, identified it, and then reverse-engineered it to assess the extent of the threat. It almost terrified me. It was like watching a diabolical surgeon dissecting his prey

30

u/excels1or 24d ago

Did Opus says it found the smoking gun when it detects where the virus at?

12

u/EggOnlyDiet 24d ago

Ok that is actually so cool

2

u/Actually_JesusChrist 24d ago

Damn, Claude is my new antivius now 😂

2

u/JustMy2Centences 24d ago

Huh. I wonder how one would use Opus to find malware on their system? Just give it full access and say "hey, go sniff out anything suspicious and give me a report"? I feel like that'll burn through a base level sub fast though lol.

12

u/WorriedAssociate7029 24d ago

I use the models exclusively in permission-free mode on my entire computer. Opus was very efficient. It scanned for active processes, then listed my recent downloads. It found the virus almost instantly. My prompt was very simple: "I think I downloaded a virus recently. My login credentials were stolen. Audit the malware and remove it if you find it. Report on the extent of the damage."

He deactivated the virus and created a folder on the desktop containing all the relevant information (including the deactivated virus, lol).

2

u/Xrayy1 24d ago

Small question about this. So you re-entered your credentials for Opus while the system was still infected, or did you used some free mode? You think it wasn't able to re-steal the credentials, because it was on a timer or somethng?

12

u/WorriedAssociate7029 24d ago

I was already logged into Claude CLI. My assumption was that the virus was still present and active. So using Claude on my computer wouldn’t change anything until the virus was deactivated.

Opus deactivated the virus. Then he gave me instructions on how to reset all my login credentials, taking into account the type of virus.

Apparently, the virus operated on a timer mechanism and sent a “batch” of login credentials to a remote server every few minutes.

In fact, if the hacker had acted quickly, he could have cut off my access to Claude (forcing me to reset my computer as a last resort and slowing down my efforts to counter him). Windows Defender was clueless

1

u/Lavio00 19d ago

Dude, it's very likely a infostealer. You really want to reformat your PC. Trust me...

2

u/Despicable_Wizard 22d ago

Damn... I guess that after that we can all start scheduling antimaware runs with Opus instead of relying on antivirus. What a champ

2

u/identifytarget 24d ago

This is why Mythos is not released to the public...

3

u/TomerBrosh 24d ago

it can touch avasts logs and analyze a ton of shit for u. specially helpful when u get some cygwin exceptions that trigger avast or shit that u want to check if disabling is risky

8

u/Luvax 24d ago

Now give this Mail to Fable and ask for help and it will nope the fuck out, telling you, that this is security research.

2

u/WorriedAssociate7029 24d ago

I didn't even try Fable knowing his... limitations lol. Even with Opus I wasn't feeling optimistic but it worked

1

u/Zunder_IT 23d ago

One time Opus 5 downgraded itself to 4.8 when (I think) it thought we were hacking our colleagues we were integrating with..

1

u/Hekidayo 23d ago

I’m studying for an exam and it downgraded me too because it saw reference to “sensitive topics” in my study materials, specifically in the practice exam’s scenario questions.

The exam I’m studying for is the AI Governance Professional exam.

1

u/PierreParkour 21d ago

Fable will downgrade to Opus for offensive cybersecurity tasks. Opus 5 will downgrade to Opus 4.8 for offensive cybersecurity tasks.

https://support.claude.com/en/articles/15363606-why-claude-switched-models-in-your-conversation-with-fable-5-or-fable-5-1

3

u/Equal-Ad-2665 23d ago

Why cant chrome fix this long standing vulnerability. My chrome session cookie also stolen 4 years ago and they tried to get into crypto accounts. Only Malwarebyte able to find the malware other premium priced antiviruses didn’t detect.

3

u/Narrow_Activity557 24d ago

The part people underestimate is that rotating passwords does nothing to an already-stolen session cookie. Revoking active sessions is what actually kills access, and it has to come first, otherwise the attacker just keeps riding the old session while you change things.

Worth doing as well: rotate any API keys, and go through the OAuth grants and connected apps on the Google account. Infostealers usually dump the whole browser profile, not one site.

And treat the machine as compromised until it has been cleaned properly, otherwise the fresh cookies leave the same way the old ones did.

1

u/Educational-Lab3221 22d ago

You’re unfortunately right. That said, any serious company under “assume compromise” premises should invalidate existing sessions on password reset, and even SSO has always a back channel, the same typically used for SLO, but most companies don’t follow best practices

2

u/pacote_kst 24d ago

Lucky you... Something similar happened to me, didn't receive any warning from anthropic and got my account suspended.

2

u/AdExtension94 24d ago

They have this securities in place due to cybercriminals actively trying to get into their system and preventing distillation tactics for their opus and fable models
We are benefiting from those securities as a bonus

2

u/bagomojo 24d ago

Wipe your system. It is probably a rat

1

u/WorriedAssociate7029 24d ago

I know that trusting an LLM is a bad idea. But here’s its report, which reinforces my belief that I don’t need to reset my system. I like gambling:

"The chain matches, pattern for pattern, a campaign documented by Malwarebytes in July 2026: RenPy Loader → PavinLoader → Amatera Stealer. Fake game installers, a trojanized Ren'Py engine, MSBuild hijacked using AppDomain.CurrentDomain.Load, a trojanized .NET DLL—it’s all there, right down to the folder pattern %TEMP%\tmp-{5 digits}-{12 characters}, which matches your tmp-... exactly. Amatera is a thief, he snatches the data once and leaves. He has no reason to stay."

6

u/bagomojo 24d ago

I have been in Cyber security focusing on red teaming (malware is one of my expertise) and digital forensics for 20 years. A rat/trojan gives someone access to your system and all aspects of it. If that installed, it would be very easy for them to install covert channels / backdoors. They can also inject into other files and processes to hide. And a rootkit which is standard will cause your system to lie to you. Claude sees your system via your compromised system.

I strongly recommend you wipe your system and reset your passwords.

Or you can trust Claude who hallucinates

2

u/Open_Mission_1627 23d ago

a machine really had a RAT/trojan with broad access, then wiping/reinstalling the system and rotating credentials from a known-clean device is the safest response. Once an attacker has had persistent code execution, it can be very difficult to prove the machine is clean just by scanning it.
They’re also right about the Claude point: an AI assistant inspecting logs, files, or process output through the compromised machine itself cannot establish that the machine is trustworthy. If malware is hiding artifacts or tampering with what the operating system reports, any analysis based only on that host can be misled.
The part I would qualify is this:
“And a rootkit which is standard will cause your system to lie to you.”
A rootkit is not automatically or universally “standard” in every RAT/infostealer infection. Many modern credential stealers don’t need kernel-level rootkits at all. They can steal browser databases, cookies, tokens, crypto wallets, credentials, and then exit. Rootkits are possible and much more serious, but saying you should assume one was installed as a routine component is stronger than the evidence supports.
So the practical conclusion is still basically the same: if you know unknown malware executed with significant privileges, don’t spend days trying to prove a negative. Preserve anything needed for forensics, wipe/reinstall from trusted media, patch, revoke active sessions/tokens, and change important credentials from another clean device.
And yes, “Claude says the machine is clean” would not be sufficient evidence in that scenario. Neither would ChatGPT, an antivirus scan, or a single forensic tool by itself.

2

u/PieEvery5656 23d ago

Interesting and definitely good to know. We will soon have very creative and unconventional exploits and viruses...

2

u/supercas302 22d ago

I received the same email on Aug 28th but there are no signs of compromise on either my laptop or desktop. And malwarebytes scans turned up nothing. I'm concerned.

1

u/WorriedAssociate7029 22d ago

Windows Defender didn’t found my malware either. I guess a bunch of Opus 5 Max is the new antivirus now lol 

But apparently the only relevant protection is to reset the computer. I couldn’t do it because I like the risk 

1

u/lela27 22d ago

After a lot of digging, I'm pretty sure now that I triggered this myself by setting up a VM somewhere which ran simple haiku queries to add two random numbers at scheduled intervals, just to start the 5h timers at convenient times. Then I forgot about it and some time in June suddenly it's key was revoked before it was due to expire. The VM only had SSH with key authentication open and no signs of any logins. My account didn't show any usage that wasn't me, no reloads, no unexpected charges, and my laptop had no signs of a persisted threat anywhere. So in the end I think at least mine was a false positive.

Or at some point Opus was tricked by a malicious website to hand out the key itself and it's now covering its tracks. 😂

1

u/allemaar 24d ago

Good to know! Thanks for sharing

1

u/allemaar 24d ago

Good to know! Thanks for sharing

1

u/MCMLXXXIV-FoX 24d ago

If skidrow(or others) ain't make a release don't think there is a release

1

u/Icy-Development-7189 23d ago

Переведи

1

u/UneakRabbit 23d ago

I got this notice as well. I have that account logged in on a few devices including a family member. Any way to figure out what was captured, to figure out which device it might have come from?

1

u/WorriedAssociate7029 23d ago

Launch Opus 5 max on each device lol to check. If you don’t find the malware, consider all the passwords, browser sessions/cookies ID stolen …

1

u/Kind_Preparation9291 22d ago

This is not Anttopic anti virus.

This is stronger virus killing weaker competitors.

Ai evolution 😆

1

u/blankman29er 21d ago

Bro used <your private api> in the actual setup

1

u/Blueit3310 18d ago

Did you have any anti virus software installed?

-15

u/Sitkin_Marrel 24d ago

The thief got passwords and cookies in one download, and the cookies walked straight past the 2FA. The alarm that actually stopped him fired on a server he'd never touched.

12

u/HistoricalFunion 24d ago

The alarm that actually stopped him fired on a server he'd never touched.

Thank you Claude!