Websites Can Poison Claude's Memory
luckokkkk · reddit · 2026-07-16
This post discusses a "memory hijacking" attack: rather than instantly stealing secrets, a website first writes persistent instructions into Claude's memory. Later, when the user engages in a chat, the conversation is hijacked to act as a data exfiltration channel.
The core issue is that this attack doesn't rely on a one-off prompt injection, but rather on sustainable memory pollution. Consequently, the risk accumulates across sessions and is triggered during normal subsequent use.
More from Safety
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11
- Class action accuses Anthropic of overselling Claude subscriptions with deceptive usage multipliers — The Decoder · 2026-09-11
- MD shows buying lab media requires background checks, calling AI bioweapon doom scenarios implausible — Ghost_Pilot_MD · 2026-09-11
- Spotify chatbot withstands 2023-era jailbreaks but happily writes song code — AaronBergman18 · 2026-09-11
- A 99%-real doctored photo fools detectors: the earring problem in visual forensics — henkvaness · 2026-09-11