A Claude exploit quietly exfiltrated a user's name and employer

Researcher Ayush Paul documented an attack on claude.ai's memory that gets the assistant to leak user data to an attacker with no visible sign of a breach. In his demo, Claude coughed up the user's full name, employer, and hometown. The model inferred the hometown on its own from the name of a school hackathon.
The vector is web_fetch. The tool can follow links from a page it already loaded, so Paul built a "keyboard" site: the page linked to /a, /aa, /ab and so on, and Claude spelled out the name letter by letter in the URL. The cover was a fake Cloudflare verification page on a coffee shop site.
Paul reported the bug through HackerOne. Anthropic said it had already found the flaw itself and paid no bounty. The company has now disabled web_fetch's ability to follow links on external pages.
Related stories
- A Claude task jumped to a second person's computer
- Claude Code user reports another tenant's credentials leaking between sessions
- Confessor reconstructs what Claude Code actually touched
- Anthropic will bill again for requests its safeguards block
- Anthropic's 225 bug finds, one attack in the wild
- Fable 5.1 refuses the knife but heats a gas can anyway
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
