404media.co web signal

Claude shared chats leak wallet keys, medical data via Google

anthropic cybersecurity ai-business

TL;DR

  • 404 Media reported that publicly shared Claude conversations, including cryptocurrency wallet keys and API credentials, have been indexed by Google.
  • One dork surfacing Claude chats appeared to have been mitigated, but a second dork targeting the Artifacts feature still worked at publication.
  • The exposure mirrors a ChatGPT incident last year in which conversations were searchable on Google before a researcher scraped them.

A batch of Claude conversations and Artifacts that users had shared via public links turned up in Google search results, and the material inside them was exactly the kind of thing you would not want strangers to find. According to 404 Media, Joseph Cox reports the exposed pages included cryptocurrency wallet keys, API keys and login credentials, personal information like names, addresses and phone numbers, an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data.

The mechanism is a Google dork, which the piece defines as a super specific search that is useful for finding particular webpages or files. One dork surfacing Claude chats appears to have been mitigated by the time 404 Media tested it on Google and DuckDuckGo. A second dork, targeting Claude's Artifacts feature, the interactive workspaces where people run vibe-coded apps and other tools, was still returning results at publication.

The reason this reads familiar is that OpenAI already lived through it. 404 Media notes the incident is similar to a ChatGPT exposure last year in which conversations were searchable on Google, and that a researcher was able to scrape those exposed chats. Whatever lesson that round taught did not propagate cleanly. Anthropic did not immediately respond to a request for comment.

The honest caveat is that the reporting does not give you a count of how many Claude pages were actually indexed, whether Anthropic is proactively notifying affected users, or how the second dork slipped past whatever mitigation closed the first. And once material is out, it is out. Third parties may already have scraped these pages, which means a page vanishing from Google now does not undo the exposure.

What is worth watching is whether Anthropic, and the rest of the AI product surface that ships a share button, starts treating public sharing as a security boundary by default. That looks like noindex on shared pages, a warning before a user pastes a secret into a chat they intend to share, and clearer language about what public actually means. Until then the same failure mode is likely to recur on the next product with a share link.

Shared on Bluesky by 3 AI experts