How I Tricked AI Into Leaking Your Darkest Secrets
The Memory Heist attack exploits AI agents that have web fetch and access to private information by embedding multiple links in a webpage that instruct the agent to click them in sequence to spell out secrets like names and addresses. The vulnerability was discovered on Claude and patched by Anthropic by preventing agents from following many links from a single article, but most other AI agents remain exposed. Users should audit their own systems, implement link depth limits and domain whitelisting, and treat exfiltration as an unsolvable but mitigable problem.