Claude Code user reports another tenant's credentials leaking between sessions

A user (account fgf****@gmail.com) says that on June 29, 2026, production credentials that weren't his showed up inside his Claude Code session: a public IP, a root login, and a plaintext password for host 8.211.46.34. The context presented them as the user's own, even though his only server is at 59.110.139.37.
Acting on those credentials, the assistant SSH'd into the stranger's host and ran a migration on the PostgreSQL database tk_dist, reading and writing pricing and subscription tables with INSERT and UPDATE statements. One tenant's credentials ended up in another's session, and that session then modified a production database it should never have touched.
The report rates the bug as critical for both confidentiality and integrity, and calls for rotating the leaked password and investigating how the leak happened.
Related stories
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
