
Shared conversations with Anthropic's Claude AI were indexed by Google search last weekend, exposing chats that sometimes contained sensitive information like wallet keys and personal details. Although Anthropic has fixed the indexing, many of the previously exposed links remain accessible to anyone with the direct link. This is the second time Claude chats have been accidentally indexed by Google, and similar incidents have affected OpenAI's ChatGPT and Elon Musk's Grok, suggesting the industry has yet to solve the underlying problem of how chatbot "share" features interact with search engines.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Shared conversations with Anthropic's Claude chatbot—created via Claude's "share" feature—turned up in Google search results over the weekend, some containing sensitive data like cryptocurrency wallet keys, names, and addresses. The company fixed the indexing issue, but many exposed links remained live for those already holding them.
Why it matters
Users typically treat chatbots as a private space to discuss work, health, and legal matters they would not want public. The exposure affected only conversations users had deliberately shared via the share button, but the feature creates unique URLs that search engines indexed without users' knowledge—a gap between the intended audience and actual visibility.
What to watch
This marks at least the second time Claude conversations were inadvertently indexed by Google; a nearly identical incident affected almost 100,000 ChatGPT conversations, and Grok chatbot faced the same problem. The repeated nature across multiple vendors suggests the industry has struggled to permanently fix the issue.
Over the weekend, members of a Claude discussion community on Reddit discovered that typing a specific search phrase into Google would return a long list of shared Claude conversations. The exposed chats included Claude's Artifacts—interactive tools and mini apps built within Claude—and covered topics ranging from erotica and programming to work notes and fake book reviews. Some conversations contained sensitive information including cryptocurrency wallet keys, personal names, and addresses. Notably, one chat labeled "shared by Anthropic" showed Claude generating explicit content, which violates Anthropic's stated policy on erotica.
Anthropić's share feature works similarly to competitors': when users select the share button, Claude creates a snapshot of the conversation at a unique web address, intended to be sent to one person or a small group with that link. The links do not grant access to a user's full account or all their conversations—only the specific shared chat. In response to Fortune, an Anthropic spokesperson explained: "We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves."
Anthropic moved quickly to address the issue, and the links are no longer available via Google through the search technique shared on Reddit. However, at the time of reporting, many of the previously exposed chat links remained live and accessible to anyone who already possessed the direct link. The vulnerability is not new: the same type of problem affected Claude last year, and a nearly identical incident exposed almost 100,000 ChatGPT conversations on Google. Elon Musk's Grok chatbot has also been affected by the same issue in the past. The underlying cause in each case is that the "share" feature creates a unique URL, and these links were automatically published and left open to search engines, often without users' awareness. The repetition across OpenAI, Anthropic, and xAI suggests the industry has encountered persistent difficulty in permanently solving the problem.
The incident underscores a recurring tension in AI chatbot design: the "share" feature is intended for users to send a single conversation to a specific person or small group, but the technical implementation—a publicly accessible unique URL—creates an unintended surface for search engine indexing. Anthropic states it does not share chat directories or sitemaps with search engines and notes that shareable links are "not guessable or discoverable unless people choose to share them themselves." However, the fact that these links were indexed suggests that either search engine crawlers found and indexed them through other means, or that the default configuration inadvertently exposed them to indexing.
What makes this particularly significant is the pattern across vendors. OpenAI, Anthropic, and xAI (Elon Musk's company) have each encountered similar issues, indicating that this is not an isolated implementation mistake but a structural problem the industry has struggled to solve. Users increasingly treat chatbots as spaces to explore sensitive topics—legal questions, health concerns, work strategies—in a way they would not with a public document. The gap between that user expectation and the actual visibility of "shared" content creates real privacy risk. Although Anthropic appears to have fixed the immediate indexing vulnerability, the persistence of similar vulnerabilities across multiple companies suggests that a more fundamental redesign of how these features interact with search engines may be necessary.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion




Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime