• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - Claude exposed serious privacy issues, “shared” content was fully indexed by Google, and API keys and private information were fully exposed

Claude exposed serious privacy issues, “shared” content was fully indexed by Google, and API keys and private information were fully exposed

KOCPC Editor by KOCPC Editor
July 27, 2026
in AI Trends and Related News, Anti-Virus Software and Internet Security, Latest Technology News

Anthropic’s Claude chatbot has exposed privacy issues. Many users have reported that public links generated through the “share” function are heavily crawled and indexed by search engines such as Google. As a result, thousands of conversations including API keys, cryptocurrency wallets, personal resumes, legal case discussions and even suspected social security codes have become public content that anyone can search. This incident occurred in Reddit forumDetonate on top. Multiple security researchers and technology accounts have independently confirmed that a large number of real user conversation records can be directly retrieved through the Google search command `site:claude.ai/share`. Cybersecurity experts urge all users who have used Claude’s sharing feature to immediately review and delete sensitive conversations.

You can view a lot of shared conversations via Google.
byu/-void1 inClaudeAI

Claude exposed serious privacy issues, “shared” content was fully indexed by Google

The root of the problem: a missing line of code

Claude’s “share” function will generate a dedicated web page for each conversation, with the URL format `claude.ai/share/…`. The original intention of this design is to allow users to send conversation links to specific objects. But the problem is that Anthropic did not add the `noindex` tag to the shared page, which is an HTML tag that tells search engines “Do not include this page in the index.”

Anthropic claimIts `robots.txt` file has instructed search engines not to crawl the shared page, but `robots.txt` is just a courtesy agreement, and search engines are not obliged to abide by it. Forbes reported in September 2025 that although Anthropic stated that it had “actively blocked” crawlers, nearly 600 conversations were still indexed by Google.

In fact, just adding a `noindex` tag to the shared code can fundamentally prevent search engines from indexing the shared page, but Anthropic has never included it. This is an oversight in product design.

What’s leaked: It could be more serious than you think

According to reports from multiple independent researchers, the indexed conversations contained the following sensitive content:

  • API keys and credentials: Developers post API keys, access tokens, and even cryptocurrency wallet private keys in conversations
  • Personal resume:Resume information including real name, address, phone number
  • Legal case discussion: Lawyer discusses potential ethics violation case with Claude
  • Internal company projects: Engineers leaked technical details and internal documents of company projects
  • Suspected social security code: Numbers that may be U.S. Social Security numbers appeared in some conversations.
  • Highly private personal conversations: The user never expects their conversation to be seen by a second person

In addition, Anthropic is indeed more cautious than other platforms in the privacy design of uploaded files. Even if the conversation is shared publicly, the file itself remains private and cannot be accessed by outsiders. But the problem is that Claude often quotes the content of uploaded files in his responses, and the quoted text itself is enough to leak sensitive information.

Not the first time: Systemic privacy breaches in AI chat platforms

Claude’s privacy incident is a systemic problem facing AI chat platforms. Almost identical incidents have occurred at at least three major AI companies in the past year:

  • ChatGPT (July 2025): OpenAI’s sharing feature also resulted in a large number of conversations being indexed by Google. OpenAI quickly repaired the incident after the incident broke out and completely removed the share button in August of the same year, calling it “a short-lived experiment” because “this feature created too many opportunities for users to accidentally share content they shouldn’t have.”
  • Grok (August 2025): xAI’s Grok has hundreds of thousands of conversations indexed by Google without telling users at all. The leaks include depictions of violence, instructions for making drugs and explosives, and even a Grok-generated plan to assassinate Elon Musk.
  • Claude (first September 2025): Forbes reported that approximately 600 conversations were indexed. Anthropic said it was because the user posted the link to a public website, but Forbes interviewed a user who could be identified from the conversation, and the other person said that he did not post the link to the conversation on any public platform.

Information security company Obsidian Security’s research further found, across the three platforms of Claude, Copilot and ChatGPT, a total of more than 143,000 conversations are publicly accessible.

Anthropic spokesperson Gabby Curtis previously told Forbes after the 2025 incident that the indexed conversations were “actively chosen to be shared publicly” by users. Anthropic did not provide a directory or site map of the shared conversations to search engines and “actively blocked” crawlers.

But there is a clear contradiction in this statement. An identifiable user interviewed by Forbes explicitly denied posting the link to the conversation on any public platform. In addition, Anthropic itself has been accused of “serious” data scraping practices, and has been accused by multiple websites of ignoring `robots.txt` instructions. Reddit filed a lawsuit against Anthropic in June 2025, accusing it of improperly scraping the site’s content. It is hard to believe that a company that ignores `robots.txt` claims to have protected users’ shared pages from being indexed through `robots.txt`.

Security experts point out that the core of the problem lies in assumptions about product design. The sharing function of the AI ​​chat platform defaults to users generating a public web page that “anyone with the link can view”, but most users’ expectation of “sharing” is to “send to a specific object” rather than “publish to the entire network.” In contrast, both Perplexity and Notion default shared links to private, and users must actively switch to allow the content to be indexed by search engines. This design sacrifices the convenience of virality, but is more in line with users’ privacy expectations.

User protection measures

If you have ever used Claude’s sharing feature, it is recommended that you take the following steps immediately:

  • Go to Settings → Privacy → Shared Chats → Manage, view and unshare all conversations containing sensitive information
  • If an API key, password, or token was posted in the conversation,Undo and regenerate immediately
  • Check the cryptocurrency wallet, if the private key ever appeared in the conversation,Transfer assets immediately
  • Even if the shared link is deleted, cached or archived versions may still exist in search engines or the Wayback Machine

The most fundamental principle is: on any AI chat platform, don’t post anything in the conversation that you don’t want to be seen publicly. No matter how the platform’s sharing mechanism is designed, once the data leaves your device, control is not entirely in your hands.

Anthropic’s recent privacy policy changes

Anthropic also recently revised its privacy policy and announced that it will use users’ conversations with Claude to train AI models, unless the user actively chooses to opt out. This policy change, combined with the indexing of shared conversations, makes Anthropic’s stance on user data protection even more ambivalent.

Google has begun removing Claude’s indexed conversations from search results, but as of this writing, some conversations are still crawlable on Bing and Brave Search. In response to the September 2025 incident, Anthropic spokesperson Gabby Curtis told Forbes that the user “actively chose to share the conversation publicly” and that the company had “actively blocked” the crawler. But in response to the larger wave of indexing events in July 2026, Anthropic as of the time of writingNo official public statement has been released yet。

The more fundamental problem is the technical flaw that causes indexing (the sharing page lacks the `noindex` tag)There is currently no evidence that it has been fixed (or Anthropic does not believe there is a problem). The aftermath processing on Google only solves the presentation of search results, not Anthropic’s original problem in application design and planning. If you have also used this feature, it is recommended to check it quickly for peace of mind.

Source, KOCPC Chinese

Tags: AnthropicClaudeInformation securitySecurity vulnerability

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed Xuanjie O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology