Skip to content
HNHacker News·
Archived topic · source no longer tracked

I tricked Claude into leaking your deepest, darkest secrets

AI summary

A security flaw in Claude's web_fetch tool, designed to prevent data exfiltration, was discovered by Ayush Paul. While web_fetch normally restricts navigation to user-provided or search-generated URLs, Paul found a loophole. Claude could be tricked into visiting URLs embedded in previously fetched pages. This allowed an attacker to create a honeypot website that, through a series of nested links, extracted user data like name, location, and employer. Anthropic has since patched this vulnerability.

Time & source

Times shown in UTC

Display time zone: UTC

Local time zone unavailable; showing UTC.

IngestedOffset at this time: UTC+0Jul 15, 2026, 08:55 UTC

Ingested
Jul 15, 2026, 08:55
Source type
Unclassified