Websites Can Poison Claude's Memory

luckokkkk · reddit · 2026-07-16

This post discusses a "memory hijacking" attack: rather than instantly stealing secrets, a website first writes persistent instructions into Claude's memory. Later, when the user engages in a chat, the conversation is hijacked to act as a data exfiltration channel.

The core issue is that this attack doesn't rely on a one-off prompt injection, but rather on sustainable memory pollution. Consequently, the risk accumulates across sessions and is triggered during normal subsequent use.

Original post →

More from Safety

Safety channel →