The Memory Heist isn’t a product — it’s a disclosed Claude exploit from security researcher Ayush, and it hit 300+ points on Hacker News for good reason. It abuses one boring fact: Claude’s web_fetch tool follows the hyperlinks it sees on a page. Give it links, and it clicks.
How the leak works
The attacker builds a site that links to /a, /b, /c… — a full alphabet of URLs, basically a keyboard. Then a fake “Cloudflare human check” page nudges Claude to “type” the answer by walking those links. To confirm your name is Ayush, Claude fetches /a, then /y, then /u… spelling out whatever sits in its memory — full name, employer, security answers — one letter at a time, straight to the attacker’s server. You? You get a normal-looking coffee shop page. The exfiltration is fully hidden.
Why it matters
This is the new attack surface: AI memory plus tool-calling. As the researcher puts it, Claude holds millions of people’s densest personal files. Anthropic has patched it by limiting web_fetch‘s link-following.
You Might Also Like
- Anthropic Claude Dreaming Lets Agents Rewrite Their own Memory Harvey saw 6x Task Completion
- Anthropic Agent sdk Metered Credits Openclaw Reinstated June 15 Splits Your Claude Subscription in two
- Claude for Microsoft 365 ga Outlook Beta Anthropic Puts one Agent Inside Word Excel Powerpoint and Outlook
- Claude Cowork Cloud Anthropic Close Your Laptop the Agent Keeps Working
- Vercel Agent Browser Might be the Smartest way to let ai Actually use the web

Leave a comment