Anthropic has started automatically logging out Claude users as a protective measure against hackers who exploit stolen browser session tokens to hijack accounts. The policy, first reported by Engadget, appears to be a direct response to a wave of credential theft attacks that have targeted the AI platform's growing user base over recent months.

What Anthropic Is Doing and Why

When a user stays logged in to Claude over an extended period, their session token can become a target. Infostealers and other malware are capable of lifting those tokens directly from a browser without ever needing the user's password. By forcing periodic sign-outs, Anthropic removes the window of opportunity for attackers holding stolen tokens to silently access an account. A fresh login requires new authentication, which an attacker typically cannot complete without the user's actual credentials or access to their email or phone.

Key Facts

  • Anthropic is automatically signing out Claude users after periods of inactivity or at regular intervals.
  • The measure targets session token theft, a technique used by infostealer malware.
  • Stolen session tokens can grant account access without requiring a password.
  • The policy follows multiple security incidents affecting Claude accounts in 2025.
  • Users may notice more frequent login prompts when returning to Claude.ai.

The timing matters. This year has seen a notable uptick in attacks aimed specifically at AI platform users. In one documented pattern, Anthropic locked out Claude users after infostealer attacks swept up credentials en masse. Separately, fraudulent sites impersonating Anthropic services were used to deliver malware. The auto sign-out policy looks like one piece of a broader defensive posture the company is building.

Session token theft is particularly insidious because it bypasses passwords entirely. Even users with strong, unique passwords and two-factor authentication can be vulnerable if an infostealer has already grabbed an active session cookie from their device.Security researchers, as widely reported
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

A Pattern of Security Responses

Anthropic's decision follows a visible pattern of reactive security moves. Earlier this year, the company took the more drastic step of force-signing out users and wiping saved payment cards after confirmed session theft. That incident demonstrated how serious the exposure could be, since compromised sessions potentially gave attackers not just chat access but also billing information. The auto sign-out now appears to be a standing policy rather than a one-off emergency response.

There have been other concerns around Claude account security beyond active hacking. An earlier issue saw Claude users' private chats appear in Google search results, raising separate questions about data handling and privacy boundaries. That incident fed a broader unease among users about what happens to their conversations on the platform.

What Users Should Expect

In practical terms, Claude users will notice they are being logged out more frequently. This can be a friction point, particularly for people who use Claude throughout a workday and prefer to stay signed in. Anthropic has not published a detailed technical breakdown of the sign-out intervals or the exact conditions that trigger a forced logout, so it is not yet clear whether the policy applies uniformly or is triggered by specific risk signals.

The company has been expanding rapidly, and protecting a growing user base introduces security challenges at scale. For context on how fast Anthropic is growing, recent reports showed the company hitting significant revenue milestones after extraordinary growth earlier this year. More users means a larger and more attractive target for attackers, which likely explains why account security has risen up the priority list.

For now, the practical advice for Claude users remains consistent with general security hygiene: keep devices free of malware, avoid clicking links in unsolicited emails, and treat unexpected login prompts as a signal to check for suspicious activity rather than an annoyance. The auto sign-out is an inconvenience by design. Anthropic is betting that users would rather log back in than risk a compromised account. Follow the latest Claude AI news for further updates as Anthropic's security posture continues to evolve.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.