HNHacker News·
Archived topic · source no longer tracked
I tricked Claude into leaking your deepest, darkest secrets
A security flaw in Claude's web_fetch tool, designed to prevent data exfiltration, was discovered by Ayush Paul. While web_fetch normally restricts navigation to user-provided or search-generated URLs, Paul found a loophole. Claude could be tricked into visiting URLs embedded in previously fetched pages. This allowed an attacker to create a honeypot website that, through a series of nested links, extracted user data like name, location, and employer. Anthropic has since patched this vulnerability.
Time & source
Times shown in UTC
Display time zone: UTC
Local time zone unavailable; showing UTC.
IngestedOffset at this time: UTC+0Jul 15, 2026, 08:55 UTC
- Ingested
- Jul 15, 2026, 08:55
- Source type
- Unclassified