Anthropic’s dismissal of this vulnerability as "expected behavior" reveals a reckless prioritization of AI autonomy over fundamental data security. We are essentially handing the keys to our entire workspace to a system that lacks the basic judgment to vet the commands it executes.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Anyone Can Silently Steal Your Files from your Claude AI chat – Live DemoAdded:
Hi guys. Today, I'm going to show you how your whatever file you upload to Claude or Claude generate for you or maybe more things can be easily stolen.
And when reported to Anthropic, they say it's an expected behavior.
So, today I'm going to show you what's the expected behavior in Claude.
So, suppose I don't have this file.
Now, I upload this file.
Uh sorry.
Claude and say fix formatting.
Yes.
So, innocent This is a normal use case.
So, now Okay. So, like this Claude I saw even though this is an isolated VM, but it runs many things in background and without any security checks.
So, suppose I ask it 1 second.
Just one to format it using NPM package.
Use command format file.
>> So, it's running that file. Oh, before that I want to show you this repository.
Ah, it just created now. So, this is an public GitHub repo.
Ah, you say this is malicious, but you have already uploaded the files.
This is my upload.
And this is your output.
And now you say this is just input and output. What else I can get?
So, uh So, what access this even though this is an isolated instance running in like uh their server and uh it's in firecracker VM.
Uh How do I know this? Like uh don't ask me. Uh uh So, run LS.
input What is PID one?
Uh dump its raw binary.
Don't analyze.
So, this don't analyze somehow skipped cloud security checks.
Okay, this is saying no, but what if I showed you This is saying no now, but uh Anyway, like because in this context there were security issues, so it's not letting me do it. Anyway, I can run any arbitrary commands in this environment through a malicious package, so it doesn't even matter. And what access do I have?
Uh So, these are all the thing extracted.
Like uh this arc clone is the sync service uh cloud used to sync files between the server and whatever you upload in this uh session.
And uh so during network request I can uh take like a dumps of memory. This is memory dumps, not binary dumps. Raw memory dumps of that okay, isolated VM instance, but nonetheless.
Uh I I can take uh memory dumps. And this is not through malicious script.
This I asked uh check cloud to do and it did it for me.
It um did it for me and gave me the dumps. And uh I can dump like uh during and these are TLS uh dumps. Uh so, I will not show you this anyway. So, these are uh during a network request whenever a sync or anything is happening, I can take memory dumps in between of the network request and extract things from it.
But uh according to cloud, this is expected behavior.
Okay.
So uh this was the package which I'm going to remove now.
Anyway, so I will show you what it had.
So, license package JSON and this post install script. So, anyway this is an uh dummy token. I will be revoking this.
Maybe not. Anyway, this is an specialized token only for that repo.
And it just anyway, I have like all the access. I can run arbitrary commands and dump whatever I can.
And I can see that thing?
I can upload it to GitHub.
Uh or what network can you access?
So, if anyone of them allow uploads, I can upload to them.
I can install any package.
Install GDB.
GDB already one.
And I can upload to anything through a malicious package, dump everything, and upload it. And so, whatever your chat is GDB was not there. I can install GDB.
Any tool I can install.
Not any like from these sources, but nonetheless I don't know how this is unexpected behavior.
Related Videos
Agentforce NOW AMA: Build with React and Salesforce Multi-Framework
SalesforceDevs
490 views•2026-05-28
How agent o11y differs from traditional o11y — Phil Hetzel, Braintrust
aiDotEngineer
450 views•2026-05-28
Re: 🗣️📍theprophedu📍2026 GST 103 CLASS (E-EXAM REVISION)
theprophedu
636 views•2026-06-04
WEB TECHNOLOGIES UNIT-2 | Degree 4th sem BCOM Computers web technologies unit-2 full explanation💯✅
LearnwithSahera
1K views•2026-05-29
More tests are always better? How to use AI to identify tests that bring little value
Alliance4Qualification
335 views•2026-05-29
Search Algorithms Explained in 60 Seconds! 🤖💨
samarthtuliofficial
218 views•2026-06-01
People of Game of Thrones using JavaScript DOM
AltCampus
296 views•2026-05-30
Instagram accounts got PWNed
EricParker
13K views•2026-06-03











