The AI Sift is part of you-do-nothing

← Back to The Latest

Anthropic never shipped a noindex tag. Hundreds of Claude shared chats landed on Google.

Anthropic's Claude share feature produced public URLs with no noindex meta tag, allowing Google and Bing to crawl and index hundreds of shared conversations and Artifacts containing API keys, resumes, legal notes, medical histories, and apparent SSNs. Anthropic patched robots.txt around July 27 but Bing and third-party scrape sites were still serving results.

Context from: 404media | ZDNet | Gizmodo

The decision it puts on your desk

Run `site:claude.ai/share` in Google and Bing today. Unshare every conversation that contains anything you would not paste on a public billboard within 7 days. If you build AI products, ship `noindex` on every shareable URL before your next deploy, not after the next Reddit post.

A Reddit post on July 25 showed that a single Google query, site:claude.ai/share, surfaced page after page of publicly shared Claude conversations. Within hours the post hit 640 comments. By the next morning an X thread from Om Patel had pulled 2 million views and screenshots of resumes with real names, phone numbers, and home addresses. API keys. Crypto wallet details. A lawyer working through a potential ethics violation. What looked like Social Security numbers.

The Google query `site:claude.ai/share` returned dozens of indexed shared conversations with resumes, API keys, medical histories, and apparent SSNs. Source: Om Patel, X.
The Google query `site:claude.ai/share` returned dozens of indexed shared conversations with resumes, API keys, medical histories, and apparent SSNs. Source: Om Patel, X.

The technical failure was smaller than the outcome. Anthropic did not ship a noindex meta tag on claude.ai/share/* or claude.ai/public/artifacts/* pages. Anthropic's robots.txt was reported to disallow crawlers, but Google indexes a URL it discovers through inbound links without crawling the page. The search result showed the link with "No information is available for this page" as the description. Click it and the full unredacted chat loaded.

What showed up in the index

The volume was not small. Forbes had already reported ~600 Claude chats indexed in September 2025. This round was broader.

Documented across 404 Media, Futurism, BeInCrypto, ZDNET, and TechCrunch:

  • API keys, env variables, credentials pasted in to debug code
  • Crypto wallet details (community claims, unverified as live wallets)
  • Resumes with real names, home addresses, phone numbers
  • Patient medical histories, clinical trial results, medical billing data
  • A lawyer's notes on a potential ethics violation
  • Internal company docs, meeting notes, unreleased product plans
  • A directory of phone numbers for primary school students
  • Vibe-coded AI therapy apps
  • Financial models, cap tables, payroll breakdowns, CRM exports, tax documents

The same class of failure hit ChatGPT in mid-2025 and Grok later that year. Forbes covered the September 2025 Claude incident. OpenAI patched theirs quickly. The fix Anthropic skipped this round: one <meta name="robots" content="noindex"> tag in the shared page head.

The Claude share button creates a public URL each time a user clicks Share. The URL is unguessable but not crawl-protected. Source: Shutterstock, via ZDNET.
The Claude share button creates a public URL each time a user clicks Share. The URL is unguessable but not crawl-protected. Source: Shutterstock, via ZDNET.
The same class of failure has now hit ChatGPT, Grok, and Claude within 18 months: share links indexed because no `noindex` tag was shipped. Source: Pierre Larrieu / Hans Lucas / AFP, via TechCrunch.
The same class of failure has now hit ChatGPT, Grok, and Claude within 18 months: share links indexed because no `noindex` tag was shipped. Source: Pierre Larrieu / Hans Lucas / AFP, via TechCrunch.

How the indexing happened

A Claude chat is private by default. Hitting Share changes that. Anthropic builds a snapshot of every message up to that moment and publishes it at claude.ai/share/<id>. The URL is unguessable. Anthropic's own help docs say uploaded files and connected tool data are excluded. Team and Enterprise accounts cannot generate public share links at all. This lands on free, Pro, and Max users.

The contract users accepted: link-only access. The contract users got: search-engine-indexed. Both cannot be true. Anthropic never told them which one they were getting.

Once any user posted a share link on Reddit, X, a forum, or any channel a crawler could reach, Google's indexer added it. The site:claude.ai/share Google dork returned pages of titles. ChatGPT's 2025 incident had the same shape. Same missing tag. Same public surprise.

The mechanism, in one diagram

Link-only vs indexed: Anthropic intended the share URL to be accessible only by people who had the link. Google indexed it when inbound links were found on Reddit and X, because no `noindex` meta tag told search engines not to list it.
Link-only vs indexed: Anthropic intended the share URL to be accessible only by people who had the link. Google indexed it when inbound links were found on Reddit and X, because no `noindex` meta tag told search engines not to list it.

Anthropic's robots.txt was supposed to be the safety net. It failed for two reasons.

  1. Google indexes a URL it finds through inbound links even when robots.txt blocks the crawl. Google shows the URL with no description. The click works.
  2. robots.txt is a hint, not a guarantee. Other crawlers do not all honor it the same way.

The one-line fix that would have prevented the entire exposure: a <meta name="robots" content="noindex"> tag in the shared page HTML head. Every shared chat page renders HTML. Anthropic could ship the fix in a single deploy.

Anthropic's response

Anthropic's statement to Gizmodo: "We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services."

That framing puts the responsibility on the user. The same framing OpenAI tried in 2025 before public pressure forced a more direct acknowledgment. As of writing, Anthropic has not issued a formal security advisory, blog post, or CVE. That silence is itself part of the story.

Around July 27, community reports indicated Anthropic updated robots.txt. Google-side delisting was largely complete the same day. Bing was still surfacing claude.ai/share/* results into July 28 across multiple languages. Third-party scrape sites had already begun collecting shared links into browsable catalogs. robots.txt cannot retroactively scrub what was already indexed, and cannot stop a copy already made elsewhere.

What got exposed, by category

Indexed Claude chats spanned five sensitivity tiers, from casual conversations to crypto seed phrases that cannot be rotated once leaked. Financial and medical categories had the highest concentration of credentials and PII.
Indexed Claude chats spanned five sensitivity tiers, from casual conversations to crypto seed phrases that cannot be rotated once leaked. Financial and medical categories had the highest concentration of credentials and PII.

The categories are not symmetric. Resume and contact info leaks are reversible if the user acts fast and the bad actor has not yet scraped the data. API keys and credentials can be rotated. Crypto seed phrases cannot be rotated. A leaked seed phrase is a one-way door to a drained wallet.

Why it keeps happening

This is Anthropic's third indexing incident on shared content in 18 months. The September 2025 round hit ~600 chats. This round is broader. ChatGPT had the same incident in mid-2025. Grok had one later that year. Same product pattern: a "share" button that produces a public URL without telling the user the URL is crawlable. Same missing fix.

The reason it matters more for AI chat than for an old-school "share this doc" link is the content type. AI chat is the only surface where users routinely paste API keys to get a script working, real resumes to get feedback, real medical questions with symptoms attached, real legal questions with client detail. The share button was designed for "send my friend this recipe idea." It became "publish my credentials" because of a missing HTTP header.

The fix is one line. Anthropic ships it eventually. The next AI vendor will skip it. The cycle continues until "share = accessible via link" and "share = indexed by every search engine on Earth" stop being conflated at the product-design level.

What to do right now

If you have ever clicked Share or Publish on Claude:

  1. Settings > Privacy > Your Data > Shared Chats > Manage. Audit every "Anyone with the link" conversation and artifact.
  2. Unshare anything sensitive: financial data, real names paired with contact info, credentials, health information, internal company docs, anything you would not want indexed forever.
  3. Self-search site:claude.ai/share and site:claude.ai/public/artifacts on both Google and Bing to see what is still resolving.
  4. Assume revocation is damage control, not erasure. Cached snapshots and third-party scrapes can outlive the original link.

If you build AI products with a share feature:

  • Default noindex on any link-based sharing surface. Require a separate, explicit opt-in for "publish to web." This is the same distinction Google Docs and Notion draw.
  • Audit artifact publishing separately from chat sharing. Different sensitive-content profiles. Secrets in code versus PII in conversation.
  • Treat this as a checklist item next to prompt-injection and exfiltration defenses.