Full article:
Claude is exposing a wealth of users’ chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly available for strangers to see.
The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses
Anthropic did not immediately respond to a request for comment.
Like other chatbots, Claude lets people share their conversations with others by creating a publicly accessible link of the chat. People may do this to send the full text of a conversation to their friends or coworkers in a group chat, for example. But they may not realize Google is also surfacing these links in search results, making them available to essentially anyone.
One Google dork — a super specific search that is useful for finding particular webpages or files — surfaced Claude chats, according to this post on the Claude subreddit. At the time of writing, that Google dork appears to have been mitigated. No results appeared when 404 Media tested it, on both Google and DuckDuckGo. The post said some of the surfaced chats included API keys, login credentials, and personal information like names, addresses, and phone numbers.
Claude also offers Artifacts, which are interactive work spaces for trying out vibe-coded apps or other tools. A Google dork for surfacing them is still working at the time of writing.
The data exposure is similar to one that impacted OpenAI’s ChatGPT last year, in which nearly 100,00 ChatGPT conversations were searchable on Google. A researcher was able to scrape those exposed chats, meaning that even if Google or Anthropic works to remove the Claude search results, third parties may have already grabbed their content. And it is still possible to view exposed chats even if they’re removed from Google results if you have the direct link itself.
Forbes reported the same thing happened with Claude last year too.
Claude users can change their privacy and sharing settings to make their chats no longer publicly accessible.
I don't use Claude, so I am not familiar with their UI, but back when I used another service I would find myself occasionally accidentally toggling some threads to "public" and making them sharable with a link. Even if this is unlikely, considering the huge userbase they have, it would still be a significant number of "leaked" threads.
To share a chat via https://claude.ai/, you first have to click on the "Share" button in the top right corner of the chat window. On mobile you first have to click the
...button in the same location. You then have to click the "Create public link" button. That creates a link to that chat that allows anyone to view it.However, each chat is identified by an UUID4 in the URL (e.g.
https://claude.ai/share/01234567-890a-bcde-f012-34567890abcd)*. That means that the URL cannot be guessed even if you accidentally make a chat public, and search engines cant index it either. For anyone else to actually access the chat, you have share the URL with them.While it is theoretically possible that somebody went through all those steps purely by accident, it seems is very, very unlikely to me
* Additionally, this public URL is different from the URL you use to access the chat, meaning that sharing your private URL by accident and later creating a shared URL does not allow anyone else to access the chat from the private URL