News
Anthropic's misconfiguration allowed Claude shared conversations to be publicly searchable, leading to user privacy leaks
en
On July 28, according to Decrypt, Anthropic's Claude chat sharing feature, due to the lack of a noindex tag, caused conversations generated by users through "share links" to be indexed by Google and publicly searchable. A Reddit user discovered hundreds of complete Claude conversations through a simple search on July 25, exposing sensitive information such as cryptocurrency wallet mnemonic phrases, social security numbers, and legal discussions.
The root cause of the problem lies in the missing noindex tag for share links—although robots.txt blocked crawling, after the links appeared on third-party platforms, Google could still index the pages and display entries with "no information available." This vulnerability also affected Claude's public Artifacts, leaking employee payrolls, internal CRM chat logs, and unreleased product roadmaps. Google began removing relevant results on July 26, but Bing is still indexing them. A GitHub repository has archived 453 Claude conversations and 519 Grok conversations, totaling 11,241 messages. Users can revoke sharing through the settings page, but saved data cannot be deleted. OpenAI had a similar issue in September 2025, leaking thousands of conversations to search engines.