Hundreds of conversations shared on Anthropic's generative AI service Claude were exposed in Google search results, revealing sensitive information such as crypto wallet seed phrases, personal data and legal consultation content.
On July 27, blockchain outlet Decrypt reported that Claude's shared link feature did not include a setting to block search engine indexing, allowing public links to appear in Google search results.
The issue became known after a Reddit user on July 25 found large numbers of other users' shared chats by searching for "site:claude.ai/share". Claude's shared links display a notice that "anyone with the link can view" them. But because search engines could still collect the links, Google users could effectively access them through searches.
The exposed conversations were reported to include sensitive content such as crypto wallet seed phrases, personal information believed to be U.S. Social Security numbers, and legal consultations asking whether to self-report a professional ethics violation.
The direct cause was the absence of a "noindex" meta tag that blocks indexing by search engines. Anthropic had already restricted crawling of Claude shared pages through a robots.txt file, but that setting alone could not fully prevent indexing.
Google explains in its official documentation that if the URL is linked from an external website, the link itself can be included in search results even if Google cannot read the page content. In such cases, search results may display the message, "No information is available for this page," but the link remains visible.
The problem was not limited to shared chats. The same issue was found to apply to public Artifacts created in Claude. Decrypt reported that searches for "claude.ai/public/artifacts" surfaced a payroll spreadsheet containing employee names, internal customer relationship management (CRM) conversations and a pre-release product roadmap.
The case resembles a similar incident OpenAI experienced last year. At the time, thousands of conversations were exposed in Google, Bing and DuckDuckGo search results through ChatGPT's "make this chat searchable" feature. OpenAI later stopped the feature, but some conversations were reported to remain accessible because they were stored on the Internet Archive and elsewhere.
Anthropic fixed the issue on July 26 and added a noindex tag to shared pages. As a result, Claude shared links began dropping out of Google search results.
However, Decrypt reported that some shared links were still appearing in Microsoft's Bing search. As of the time of writing, Anthropic had not issued an official statement on the matter.
The problem is that information already exposed is difficult to fully retrieve. A public repository, "Shared-Claude-Chats", was confirmed to store 11,241 messages in plain text, including 453 Claude conversations and 519 Grok conversations collected before this incident.
Users can revoke shared links in Claude settings under the privacy menu, but that does not delete data already stored in external repositories or logging services.
The incident is seen as an example showing that generative AI sharing features, when combined with search engine indexing, can lead to unexpected privacy leaks. Critics say particular caution is needed before entering or sharing information in conversational AI, especially data such as crypto wallet seed phrases that can lead to loss of control over assets once exposed.