Chats with Claude Containing Crypto Wallet Keys Found in Google Search Results

cryptonews.ru2026-07-28 tarihinde yayınlandı2026-07-28 tarihinde güncellendi

Özet

A Reddit user discovered on July 25th that a Google search for `site:claude.ai/share` revealed hundreds of users' shared conversations with Anthropic's Claude AI. Among the indexed chats were sensitive data, including a cryptocurrency wallet seed phrase, API keys, resumes with personal details, and numbers resembling U.S. Social Security numbers. This occurred because the platform's "Share" function, which creates public links, lacked a `noindex` meta-tag to prevent search engines from crawling the pages. Although Anthropic's `robots.txt` file blocked crawlers, Google still indexed links found elsewhere online, leading to exposure. Publicly shared "artifacts" (like documents and dashboards) were also found, containing internal company data. Following the discovery, Anthropic added `noindex` and `nofollow` tags, and Google began removing the pages. However, copies of the chats had already been archived on sites like GitHub. Anthropic stated users control sharing and links cannot be found unless shared directly. This incident mirrors a similar event at OpenAI in August 2025, where a "Make this chat searchable" feature inadvertently exposed conversations. It highlights recurring privacy vulnerabilities with shared AI chatbot outputs.

On July 25th, a Reddit user discovered that the search query `site:claude.ai/share` displayed hundreds of other people's conversations with Anthropic's AI assistant Claude in Google search results. Among them were a cryptocurrency wallet seed phrase, API keys, resumes with names and phone numbers, and numbers resembling American Social Security numbers.

Source: Reddit.

Why the Links Ended Up in Google Search

Only those dialogues that users published via the "Share" feature appeared in search. This feature creates a link marked as viewable by anyone with the address. However, the interface did not warn that a search engine could pick up the page.

The Reddit thread garnered about 8000 upvotes. Besides the seed phrase and access keys, the indexed chats contained questions from a lawyer about whether they were obligated to self-report a professional ethics violation, political debates, and erotic texts.

The mechanics of the "Share" function in the chatbot work similarly to "unlisted" videos on YouTube: the link can be shared, but the video cannot be found via search. This is controlled by the `noindex` meta tag, which prohibits search engines from adding the page to their index. Claude lacked this tag, so any published address automatically became a standard indexable page.

At the same time, Anthropic's `robots.txt` file was configured correctly and blocked shared chats from robots. However, this proved insufficient. According to Google's logic, a disallow directive does not prevent indexing if a link to the page is found in open sources. A robot that is denied access also cannot see the internal `noindex` tag. Therefore, some dialogues appeared in search results with a note about the lack of page information—the search engine recorded the address from other publications but did not read the content.

The same problem affected published artifacts—applications, dashboards, and documents that users compile within Claude. The query `site:claude.ai/public/artifacts` revealed salary tables with names, corporate CRM data exports, and unreleased product plans.

By July 26th, Anthropic had added `noindex` and `nofollow` tags. Google began removing the pages from search results. According to Decrypt's observations, Bing also showed links to shared chats.

In a comment to VentureBeat, representatives of the AI developer stated that users independently manage the publication of their dialogues and that Anthropic does not provide search engines with catalogs or sitemaps containing chats. Links cannot be guessed or found unless a person has shared them themselves, the company emphasized.

What Remained in the Public Domain

Some of the conversations have already spread via copies. A repository named `Shared-Claude-Chats` appeared on GitHub, containing an archive of 453 Claude conversations and 519 Grok dialogues—totaling 11,241 text messages. Access can be revoked in Claude's privacy settings. However, this will only prevent further viewing.

A similar incident happened at OpenAI in August 2025. Back then, the "Make this chat searchable" function sent thousands of dialogues to Google, Bing, and DuckDuckGo. The company's Chief Information Security Officer, Dane Stuckey, disabled the option, calling it a "brief experiment." Some of those chats are still available in the Internet Archive.

Earlier, Google indexed user conversations with the DeepSeek AI assistant. The search results contained work documents, financial analysis, and personal correspondence, including in Russian.

Recall that in July of this year, Anthropic mistakenly billed a user on the free Claude tier for $16.6 million.

İlgili Sorular

QWhat major issue did a Reddit user discover regarding Claude.ai on July 25th?

AA Reddit user discovered that the Google search query 'site:claude.ai/share' revealed hundreds of other users' chat conversations with the Claude AI assistant from Anthropic. Among the leaked data were cryptocurrency wallet seed phrases, API keys, resumes with names and phone numbers, and numbers resembling U.S. Social Security Numbers.

QHow did shared Claude chats end up being indexed by Google despite initial protections?

AThe shared chat pages lacked a 'noindex' meta tag, which is required to prevent search engines from indexing a page. While the robots.txt file was configured to block bots from accessing shared chats, Google's logic allowed it to index a page if a link to it was found in the open web. The robot, blocked by robots.txt, couldn't see the internal 'noindex' tag that wasn't present.

QBesides private keys and personal data, what other types of sensitive content were found in the indexed chats?

AOther sensitive content found included a lawyer's question about the obligation to report professional ethics violations, political debates, erotic texts, payroll tables with names, exports from corporate CRMs, and unreleased product plans from shared 'artifacts'.

QWhat actions did Anthropic take in response to the incident, and what was the result?

ABy July 26th, Anthropic added 'noindex' and 'nofollow' tags to the relevant pages. Google subsequently began removing these pages from its search results. The company also stated in a comment that users manage chat publication themselves and that Anthropic does not provide search engines with directories or sitemaps of chats.

QHave similar incidents happened with other AI assistant companies, according to the article?

AYes. A similar incident occurred at OpenAI in August 2025, when its 'Make this chat searchable' feature sent thousands of chats to Google, Bing, and DuckDuckGo. The feature was disabled by the CISO, calling it a 'brief experiment.' Additionally, Google has previously indexed user conversations with the DeepSeek AI assistant, exposing work documents and personal correspondence.

İlgili Okumalar

From South Korea to the United States: Blue-Collar Jobs Are Becoming Increasingly Popular, Thanks to AI

AI is reshaping the labor market's value proposition. The traditional four-year college degree is losing its appeal as a guaranteed career path, while skilled blue-collar trades like electricians, welders, and plumbers are experiencing historic demand and wage premiums. This shift is driven by dual pressures: AI's displacement of certain white-collar roles and a booming need for physical infrastructure and data center construction. Data confirms the trend. In the U.S., vocational school revenue surged, and a significant portion of recent layoffs are AI-related. Surveys show a majority of Gen Z adults plan to pursue blue-collar work, citing better job security against AI automation. Vocational education interest has exploded recently. Experts cite a psychological shift as younger generations seek tangible, AI-resistant careers and avoid high student debt. In many cases, salaries for skilled trades now match or exceed those requiring a bachelor's degree. In South Korea, semiconductor vocational high schools boast near-total employment, with graduates securing high-paying roles at companies like Samsung. The shortage is structural, exacerbated by a retiring baby boomer workforce and massive infrastructure projects. Companies like JPMorgan Chase, Meta, and Lowe's are investing heavily in training programs. However, overcoming historical stigma and a "perception gap" around trade careers remains a key challenge to closing the talent gap.

marsbit1 saat önce

From South Korea to the United States: Blue-Collar Jobs Are Becoming Increasingly Popular, Thanks to AI

marsbit1 saat önce

Qualcomm: AI Hype Subsides, When Will Smartphones Emerge from the Gloom?

Qualcomm reported its Q3 FY2026 results (ending June 2026), with revenue of $9.95B, down 4% YoY but above expectations. Gross margin declined to 53.1%, pressured by rising costs across manufacturing and memory. Key business segments showed mixed performance: Handset revenue fell 19.6% YoY to $5.09B, dragged by an 11% decline in non-Apple Android shipments and weaker high-end mix. Conversely, Automotive revenue surged 61% to $1.59B, and IoT grew 9% to $1.83B. Core operating profit dropped 41% YoY due to margin compression and higher expenses. Management's Q4 FY2026 guidance projects revenue of $9.7B-$10.5B, in line with consensus, but Non-GAAP EPS guidance of $2.05-$2.25 fell short of expectations. Amidst persistent weakness in its core handset market, Qualcomm is pursuing growth in AI, focusing on Edge AI (smartphones, PCs, automotive) and Data Center AI. Its data center strategy includes four pillars: AI accelerators (e.g., AI200), commercial CPUs (Dragonfly C1000), custom silicon, and connectivity solutions. While these initiatives initially boosted its stock, concerns over AI capital expenditure sustainability have since erased those gains. The company targets $5B in data center revenue for FY2027 and $15B for FY2029. The report concludes that with the traditional handset business still under pressure, the data center opportunity is currently viewed as a longer-term option, and a more conservative valuation based on core operations may be warranted until AI contributions materialize.

marsbit1 saat önce

Qualcomm: AI Hype Subsides, When Will Smartphones Emerge from the Gloom?

marsbit1 saat önce

From TPU to Self-Evolving Agents: How Jeff Dean Predicts the Next Step in AI

At the 2026 YC Startup School, Jeff Dean outlined his vision for AI's next phase, shifting focus from simply scaling models to building intelligent, autonomous systems. He believes AI's progress is no longer just about creating smarter models, but about integrating them into systems capable of long-term, iterative work, automated experimentation, and continuous learning. This evolution moves the competition from "who has the bigger model" to "who can best organize intelligence." Dean suggests AI capabilities are now comparable to a junior engineer, enabling the automation of complex workflows. However, the true challenge and opportunity lie in managing these AI "workers" at scale. He emphasizes the importance of **context engineering**—structuring tools, memory, and feedback loops—over raw model power. For startups, this means building deep expertise in niche domains where general models currently fail (near 0-1% success rates), leveraging proprietary data, specialized tools, and domain-specific evaluators. A recurring theme is re-examining fundamental constraints. Dean's past work, like moving Google's search index to memory or creating the TPU, stemmed from questioning outdated assumptions about hardware and cost. He sees similar inflection points today, particularly in **specialized inference hardware** to drastically reduce latency and energy consumption for real-time Agent operation. Notably, he points out that in modern AI systems, the dominant cost is often not computation but **data movement**. Reliable, long-running Agents require robust system design, borrowing concepts from distributed computing like checkpointing, state management, and parallel exploration to handle failures and maintain progress over days or weeks. As AI automates execution, the scarcest human skills will shift to **defining clear specifications**, **judging what problems are worth solving** (taste), and designing effective feedback loops. Ultimately, Dean's framework prioritizes understanding the problem deeply, identifying the true bottlenecks, and systematically building closed-loop systems where AI can not only perform tasks but also improve AI itself.

marsbit1 saat önce

From TPU to Self-Evolving Agents: How Jeff Dean Predicts the Next Step in AI

marsbit1 saat önce

İşlemler

Spot
活动图片