Public Claude Chats Exposed in Search Engines Along with Passwords and Cryptocurrency Wallet Data
Learn about a serious data leak in public Claude chats, where passwords and information about cryptocurrency wallets were exposed. Protect your privacy and security.
Краткий пересказ от QRazy ИИ
- Claude users may accidentally make their chats public and face the risk of personal information leaks.
- Search engines like Google index links to public chats due to the access settings in the Anthropic system.
- Care should be taken when publishing dialogues as they may contain sensitive information, including details about cryptocurrency wallets.
Links to public dialogues with Claude have started appearing on Google and other search engines. Among the open pages, users found resumes, corporate documents, login data, and information about cryptocurrency wallets.
Why search engines saw public chats of Claude
The problem was noticed last weekend by discussion participants on Reddit. A regular search query allowed users to view page after page of other people's Claude dialogues.

Initially, users thought that Anthropic forgot to add the noindex tag that prevents the page from being shown in search results. In reality, the situation turned out to be a bit more complicated.
In the robots.txt file, Anthropic prohibits search engines from opening pages with shared chats. Due to this, Google cannot access the page and see the indexing prohibition located there. This results in a strange construction: the search engine has been locked out, while the request not to show the page remains on the inside.
The content of such chats was not displayed in search results. Below the links, Google showed a message saying, "No information about this page." A similar note appeared in Bing as well.
However, the search engine knew the address due to links from other websites. A user could click on the result and open the entire published conversation, even if their messages did not appear in the search preview.
The issue affects not only Claude
Researchers at Digital Digging previously discovered tens of thousands of public conversations created through the sharing features of various chatbots. These included Claude, Gemini, Grok, Copilot, ChatGPT, and DeepSeek.
Google quickly limited access to such results. However, some pages could still be found through Yahoo using specially crafted queries.
This is not about account hacking or gaining access to originally closed chats. The pages that entered search engines were those that users had previously made public themselves. The problem is that many of them apparently did not expect that the link could end up in an open search.
What exactly gets published after pressing Share
Ordinary Claude dialogues remain private by default. A public page appears only after the user presses the Share button.
At that moment, Claude creates a separate web page and places all messages that were sent in the chat by the time of publication on it. Anyone with the link can open this conversation without access to its owner's account.
According to Anthropic's support materials, uploaded files and unprocessed data obtained through connected tools are not transferred to the public page.
In corporate Team and Enterprise plans, public publishing of conversations is not available at all. Only users on Free, Pro, and Max plans can create shared links.
How to check your old links
All previously published conversations can be found in the Claude settings. To do this, open the Settings section, go to Privacy, and then select Shared chats.
To close a specific dialogue, simply press the Unshare button. After that, the public page will become unavailable.
Removing the result from Google does not solve the problem itself. Even if the link no longer appears in search, it continues to work for those who have managed to save or forward it.
Particular risk for cryptocurrency holders
Developers discussing the incident claimed that among the results there were details about cryptocurrency wallets and login data. Some users also reported finding and reading other people's conversations through Brave Search.
For cryptocurrency holders, the consequences of such a publication can be much more serious than an ordinary password leak. A website password can be changed. A wallet's private key cannot be replaced: if it falls into the hands of an outsider, it's safer to consider the wallet compromised and transfer assets to a new address.
Small personal wallets have already become one of the main targets for malicious actors. According to Chainalysis, in 2025, there were 158,000 hacks of personal wallets, affecting about 80,000 people and causing a total loss of $713 million. In comparison, there were 54,000 such incidents in 2022.
This statistic is not directly related to public chats of Claude. It merely shows how actively malicious actors are currently hunting for access to ordinary user wallets.
The risk is further heightened as traders increasingly connect artificial intelligence tools to wallets, using them for code verification and preparing transactions. Researchers have already warned about programs and integrations that can accidentally reveal seed phrases.
At the same time, there is no confirmation that working private keys or seed phrases were indeed found in the discovered chats. There have also been no reports of funds being stolen due to this incident.
Some developers do not consider what happened to be a leak at all. In their opinion, users themselves pressed the publication button and made the pages available to everyone. Formally, this is true, but not every person perceives "access by link" as placing a conversation on Google.
This kind of story has happened before
Most of the disputed pages soon disappeared from search results. The conversations themselves, however, remained in place. As long as the owner does not cancel the publication, anyone with a saved link can continue to open the chat.
A similar case occurred in September 2025. Then, Google indexed just under 600 shared Claude dialogues, as reported by Forbes.
The OpenAI company abandoned its experimental chat publishing feature about a month before this incident. Now it is also involved in legal proceedings related to the possible transfer of ChatGPT user data.
How Anthropic can close the problem
The technical solution seems paradoxical, but it is quite simple. Anthropic can allow Google to access public pages so that the robot can see the noindex tag and exclude them from the results.
Currently, the ban in robots.txt prevents the search engine from checking the page's content. Therefore, it can save and display the found address, although it does not analyze the conversation itself.
At the time of preparing this material, Anthropic had not publicly commented on the situation. Whether this story will be repeated for a third time depends on the decision the company makes.
Users, on the other hand, should adhere to a simple rule: everything published via a shared link can potentially become completely public. Passwords, documents, keys, internal code, and other sensitive data should not be sent in such a chat even when the link is intended for one acquaintance only.