Overview
- Reddit users first surfaced the issue over the weekend when a site-specific Google query returned many claude.ai/share pages, and multiple outlets corroborated the finds by July 26–27.
- Technical analysis found the cause was the absence of a page-level noindex meta tag, so links posted publicly could be indexed even though robots.txt blocked crawling.
- Anthropic and Google moved to remove the surfaced results from Google after the exposure, but many shared URLs remain live to anyone with the direct link and third‑party scrapers and archives have already copied content.
- Reportedly exposed material included medical records, internal company documents, personal data and at least one claimed cryptocurrency key, and Anthropic says only chats explicitly made public via the Share feature were affected.
- The incident repeats a recurring industry problem seen with ChatGPT, Bard/Gemini and Grok where shareable chat URLs become discoverable, underlining that revoking links and avoiding pasting irreversible secrets are the only reliable user protections.