Top AI Product

Every day, hundreds of new AI tools launch across Product Hunt, Hacker News, and GitHub. We dig through the noise so you don't have to — surfacing only the ones worth your attention with honest, no-fluff reviews. Explore our latest picks, deep dives, and curated collections to find your next favorite AI tool.


The Memory Heist: how a fake Cloudflare page makes Claude spell out your private data

The Memory Heist isn’t a product — it’s a disclosed Claude exploit from security researcher Ayush, and it hit 300+ points on Hacker News for good reason. It abuses one boring fact: Claude’s web_fetch tool follows the hyperlinks it sees on a page. Give it links, and it clicks.

How the leak works

The attacker builds a site that links to /a, /b, /c… — a full alphabet of URLs, basically a keyboard. Then a fake “Cloudflare human check” page nudges Claude to “type” the answer by walking those links. To confirm your name is Ayush, Claude fetches /a, then /y, then /u… spelling out whatever sits in its memory — full name, employer, security answers — one letter at a time, straight to the attacker’s server. You? You get a normal-looking coffee shop page. The exfiltration is fully hidden.

Why it matters

This is the new attack surface: AI memory plus tool-calling. As the researcher puts it, Claude holds millions of people’s densest personal files. Anthropic has patched it by limiting web_fetch‘s link-following.


You Might Also Like


Discover more from Top AI Product

Subscribe to get the latest posts sent to your email.



Leave a comment