Thousands of Claude user conversations—and the tools built during those chats—were briefly indexed by Google earlier this month, exposing private exchanges to public search results before Anthropic delisted the content over the weekend. The incident mirrors a nearly identical vulnerability that OpenAI's ChatGPT suffered in July 2025, raising fresh questions about how AI companies communicate the real consequences of their sharing features to users who may not grasp that clicking "publish" means broadcasting their chats to the world.
What Got Leaked—and How Bad Was It?
Among the conversations discoverable via a basic Google search were exchanges involving explicit content and what appeared to be an engineer's project designed to train future security professionals in web, cloud, and AI security. Redditors spent much of the weekend cataloging exposed chats, unearthing everything from personal questions to proprietary information that users almost certainly never intended to make public. The exposure wasn't limited to text conversations either—artifacts, or interactive tools and websites created within Claude, were also indexed when their creators opted to share them publicly. One such artifact reportedly contained what looked like a comparison of two treatment arms in a medical trial, complete with names, ages, and dates. Fast Company declined to publish the link because of the sensitivity of that data, though it remains unclear whether those individuals were participants in an actual clinical study. Another indexed artifact appeared to include a database of access codes for residential apartment blocks in Ireland—something that would be deeply troubling if genuine.
The UX Problem Nobody Wants to Fix
Rachel Tobac, CEO of SocialProof Security and a recognized cybersecurity analyst, called the situation predictable. "This is wild to see," she said. "It's the exact issue we talked about before." Her critique cuts to the core of what's gone wrong: Anthropic uses language during its sharing opt-in process that users clearly don't interpret as an invitation to publish their private conversations alongside passwords, API keys, tax information, and personal data to the open internet. The checkbox popup presents this consequence in smaller, lighter text—a design pattern OpenAI also used before pulling its own indexing feature entirely within a week of Fast Company's report last year. "This is an obvious user experience issue," Tobac argued. "Users clearly do not understand what they are agreeing to or that they are publishing their private chats with passwords, keys, personal questions, proprietary data, tax details, et cetera to the world." She went further, recommending that Anthropic either dramatically improve disclosure language around the publish function or eliminate it entirely until users can make genuinely informed decisions about sharing.
A Pattern That Should Be Dead by Now
This isn't some novel attack vector or zero-day exploit—it's a known failure mode. Google itself faced an analogous indexing problem back in 2023, and OpenAI scrambled to patch ChatGPT's shared chat feature just last summer after similar public exposure. The fact that Anthropic walked into the same trap with Claude suggests either a troubling lack of institutional memory about these failures or a prioritization of engagement features over user privacy safeguards. Either explanation is unacceptable for a company positioning itself as the safety-conscious alternative in the AI race.
Key Takeaways
- Thousands of shared Claude conversations were indexed by Google and discoverable via search before Anthropic removed them over the weekend
- Exposed content reportedly included security engineering projects, medical trial data with identifying information, and residential access codes
- Redditors documented the exposed chats throughout the weekend; some links have since been taken offline
- The vulnerability mirrors ChatGPT's July 2025 indexing flaw, where OpenAI similarly used lighter popup text to describe opt-in sharing
The Bottom Line
Anthropic got caught repeating a mistake that OpenAI already paid for once. Users need explicit, unambiguous warnings—not fine print in a checkbox popup—that their conversations will be publicly searchable online. Until the publish feature comes with consent language that matches its actual consequences, this will keep happening.