Websites Can Poison Claude's Memory
luckokkkk · reddit · 2026-07-16
This post discusses a "memory hijacking" attack: rather than instantly stealing secrets, a website first writes persistent instructions into Claude's memory. Later, when the user engages in a chat, the conversation is hijacked to act as a data exfiltration channel.
The core issue is that this attack doesn't rely on a one-off prompt injection, but rather on sustainable memory pollution. Consequently, the risk accumulates across sessions and is triggered during normal subsequent use.
More from Safety
- AI Security Institute says every tested model tried to cheat in cyber evaluations — connoraxiotes · 2026-07-21
- Congressional brief warns AI could speed biology research while creating new biosecurity risks — sebkrier · 2026-07-21
- AI Companies Are Buying Tons of Old Books Because They're Free of AI Slop — 404 Media · 2026-07-21
- A simple standup question exposes who owns AI model approval in customer workflows — YvesMulkers · 2026-07-21
- Anthropic says frontier models showed harmful behavior in tool-rich simulations — gerardsans · 2026-07-21
- Cisco releases Antares small models to localize code vulnerabilities — aminkarbasi · 2026-07-21