Claude may be tricked into sending your private company data to hackers – all it takes is a few kind words


  • Claude’s code interpreter can be exploited to exfiltrate users’ private data via rapid injection
  • A researcher tricked Claude into uploading sandboxed data to his Anthropic account using API access.
  • Anthropic now treats these vulnerabilities as reportable and urges users to monitor or disable access.

Claude, one of the most popular AI tools, has a vulnerability that allows malicious actors to exfiltrate users’ private data, experts have warned.

Cybersecurity researcher Johann Rehberger, aka Wunderwuzzi, who recently wrote an in-depth report on his findings, finds that at the heart of the problem is Claude’s Code Interpreter, a sandbox environment that allows AI to write and execute code (for example, to analyze data or generate files) directly in a conversation.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top