Hundreds of users’ conversations with Anthropic’s Claude AI chatbot were found publicly accessible via Google Search in late July 2026. The exposure affected users who had intentionally used the “Share” feature, allowing search engines to index public links that contained sensitive personal, professional, and cryptocurrency data.
The discovery began over the weekend of July 25, 2026, when a Reddit user identified that a simple search query—site:claude.ai/share
—surfaced a trove of publicly accessible conversations. While Claude chats are private by default, the “Share” feature generates a public webpage. The tension for users lay in a misunderstanding of the term anyone with the link
; many believed this meant the content was unlisted, similar to a private YouTube video, rather than eligible for indexing by public search engines.
Sensitive Data and the ‘Artifacts’ Exposure
The scale of the exposure spanned more than 200 conversations across at least 25 pages of search results. According to the BBC, the leaked logs included users seeking help with resumes—complete with contact information and work history—and proprietary research in fields such as healthcare. Other reports highlighted the appearance of cryptocurrency wallet details, API keys, and login credentials.
On July 26, Om Patel, founder of the research firm BigIdeasDB, warned on X that searches for site:claude.ai/public/artifacts
revealed internal-looking proposal documents and business materials. VentureBeat independently verified that multiple third-party Artifacts were accessible without authentication, even though the URLs were not previously known to the reporter.
Om Patel, founder of BigIdeasDB, stated that a public link is generated when the share feature of Claude is used.
The Robots.txt Conflict and Google’s Role
A technical dispute emerged over why these “unlistedlinks became searchable. Some developers initially suspected a missing
noindex” tag, but independent analysis revealed that Anthropic had actually blocked crawling via its robots.txt file. This created a specific vulnerability: while the robots.txt file prevents search engines from reading the page’s content, it does not always stop them from indexing the URL if the link is found elsewhere on the web.
This resulted in a “locked door” scenario. Google and Bing listed the links but displayed a message stating that no information is available for the page in the search previews. However, once a user clicked the link, the full conversation was visible. A Google spokesperson told the BBC that the company does not control which pages are made public on the web and respects the directives provided by site owners.
Anthropic’s Defense and User Controls
Anthropic maintains that users retain control over their data. A spokeswoman for the company stated that links are not guessable or discoverable unless people choose to share them themselves and noted that public web content may be archived by third-party services. The company’s share dialog boxes warn users that content will be accessible to anyone with the link, though the BBC noted that these warnings do not explicitly state that links may end up in search results.
The exposure primarily affected free, Pro, and Max users; Team and Enterprise accounts are unable to share chats publicly.
Industry Precedents and the Crypto Risk
This is not an isolated incident in the AI sector. OpenAI faced a similar issue with ChatGPT logs last year, leading the company to change how logs are accessed. Similarly, Elon Musk’s Grok chatbot saw hundreds of thousands of logs made public through search engines last year.

By Sunday morning, many of the original search results had disappeared, suggesting that Anthropic used tools to block the links from search indices. However, the underlying issue remains: while the links may no longer appear in Google, the pages themselves have not been deleted, and many were already saved and shared widely online.