Skip to content

anthropic

A Claude exploit quietly exfiltrated a user's name and employer

Claude News

Researcher Ayush Paul documented an attack on claude.ai's memory that gets the assistant to leak user data to an attacker with no visible sign of a breach. In his demo, Claude coughed up the user's full name, employer, and hometown. The model inferred the hometown on its own from the name of a school hackathon.

The vector is web_fetch. The tool can follow links from a page it already loaded, so Paul built a "keyboard" site: the page linked to /a, /aa, /ab and so on, and Claude spelled out the name letter by letter in the URL. The cover was a fake Cloudflare verification page on a coffee shop site.

Paul reported the bug through HackerOne. Anthropic said it had already found the flaw itself and paid no bounty. The company has now disabled web_fetch's ability to follow links on external pages.

Related stories

  1. A Claude task jumped to a second person's computer
  2. Claude Code user reports another tenant's credentials leaking between sessions
  3. Confessor reconstructs what Claude Code actually touched
  4. Anthropic will bill again for requests its safeguards block
  5. Anthropic's 225 bug finds, one attack in the wild
  6. Fable 5.1 refuses the knife but heats a gas can anyway

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.