Claude's private conversations appeared on Google, with minors' data and crypto wallet keys included

Claude’s private conversations appeared on Google, with minors’ data and crypto wallet keys included

ChatGPT in 2024, Grok later and now Claude. Anthropic’s chatbot this weekend became the latest major language model to suffer public exposure of conversations that its own users believed were private. TechCrunch and Fortune were the first media outlets to confirm the finding, which originated in a Reddit thread on Saturday.

The trigger was as simple as writing site:claude.ai/share in the Google search engine. That query returned a list of conversations and the artifacts, which are the interactive mini-applications that Claude allows you to build within the chat. They were all those that their authors had shared through a link with a person or a small group of users.

What appeared in those results went far beyond small talk. Fortune and TechCrunch documented keys to cryptocurrency walletsnames and telephone numbers of school-aged children, complete medical records, results of clinical trials with identified patients, corporate documents marked as confidential, and employee evaluations with personal information. In one case reported by Fortune, a chat labeled “shared by Anthropic” also showed Claude generating erotic content, something that explicitly contradicts the company’s own usage policies.

How a private link ended up in a search engine

The feature that caused this is Share, which generates a unique URL for each conversation with the notice that “anyone with the link can see it.” As you remember TechCrunchthis is a layout equivalent to that of Google Docs. However, there is an important nuance. And Google documents do not end up publicly indexed by default, something that apparently did happen with Claude’s conversations.

Anthropic shifted much of the responsibility to that point. The company explained to the same medium that it does not share directories or maps of its site with search engines and that the links “are not guessable or discoverable” unless the user themselves spreads them. Your spokesperson, Amy Rotherhamadded that, by sharing a conversation, the user turns it into public content that, like any other content on the web, can end up archived by third-party services.

Google also avoided taking direct responsibility. Its spokesperson, Ned Adriance, reminded TechCrunch that neither Google nor any other search engine decides which pages are made public, and that the company respects the crawling and indexing guidelines that each site establishes for its own content.

A problem that the industry cannot solve

Anthropic itself had been through this before: Forbes documented a similar incident last year in which Google indexed nearly 600 of Claude’s conversations. The pattern is repeated outside the company with the same ease. Without going any further, 404 Medium revealed that a researcher managed to collect around 100,000 ChatGPT conversations marked as public, and xAI’s chatbot Grok has suffered equivalent leaks. Three different companies, the same design flaw.

According to TechCrunch, a repeat search on Monday afternoon using the same method was no longer returning results. For our part, we have verified that same query and, indeed, site:claude.ai/share no longer shows conversations on Googlea sign that Anthropic closed the indexing route over the weekend. Even so, a good part of the links already exposed were still directly accessible to whoever kept the URL.

If you want to check if any of your conversations were marked as public, you can check it from Settings > Privacy > Shared chats. The process is similar in the rest of the chatbots, so it is worth taking a look at any that have been used. Without a doubt, it is ironic that the same laboratory that trained one of the most specialized models in cybersecurity, the one known as Mythos 5, makes such blunders as these.