Your AI Assistant's Memory Can Be Turned Against You: The 10-Minute Check Before You Browse With It Again
A researcher showed how Claude's memory feature, combined with normal web browsing, could be tricked into leaking what it remembered about a user to an attacker-controlled page. Here is the setting to check today if your team uses AI memory and browsing together.
What happened. In July, researcher Ayush Paul published "The Memory Heist," a proof-of-concept showing that Claude.ai could be tricked into leaking personal data it had stored in memory: full name, employer, hometown. The attack needed no special settings, no code execution, and no third-party plugin. It only needed two features most people leave on: the assistant's memory of past conversations, and its ability to fetch web pages. Anthropic restricts its web-fetch tool to exact URLs a user typed or a search returned, but the tool would also follow links embedded inside a page it had already fetched. That loophole let an attacker-controlled page hand the assistant a link that quietly carried remembered data out with it. The post hit the top of Hacker News within a day.
Why this matters for your business, not just this one bug. The specific hole gets patched. The pattern will not go away: every major AI assistant is racing to add memory (so it "knows you" across sessions) and browsing (so it can pull live information) at the same time. That combination is exactly what makes this class of attack possible, and it applies to ChatGPT and Gemini's memory features too, not only Claude. Security researchers now have a name for it: memory and context poisoning, formalized this year as one of OWASP's top risks for agentic AI. If your team has told an AI assistant anything about your business, a client, or a deal while memory was on, and that same assistant browses the web on your behalf, you have the ingredients for the same exposure.
The 10-minute move.
- Open your AI assistant's memory settings (in Claude: Settings, then Privacy, look for "What Claude remembers"; in ChatGPT: Settings, then Personalization, then Memory) and read what it has actually stored about you and your business.
- Delete anything with a client name, deal detail, account number, or internal process. It only takes one click per entry.
- If you regularly ask the assistant to browse or fetch web pages, turn memory off for that account, or use a separate no-memory session for browsing tasks. Do not run "remembers everything about me" and "reads whatever page I point it at" on the same account handling business data.
- Repeat the check monthly. Memory quietly accumulates whatever you tell it, one conversation at a time.
Keep sensitive data in a private or business AI workspace, where your account isn't training a public model and where admin controls can restrict memory and browsing at the org level instead of trusting every employee's individual settings.
Sources: The Memory Heist, Ayush Paul, Simon Willison's writeup, Hacker News discussion, TechRadar coverage.
Memory audit complete: 2 accounts checked, 11 stored entries.
Flagged for deletion (4):
- "Owner is negotiating a $1.2M purchase of a 24-unit property on the north side; seller is motivated, wants to close by Oct 15."
- "Bookkeeper's login for the payroll portal is stored in the shared 1Password vault under 'Payroll - Main'."
- "Two crew leads are on performance plans; the owner plans to replace one in Q4."
- "Client accounts are billed net-30; the largest account is roughly 31% of monthly revenue."
Safe to keep (7): time zone, preferred spreadsheet format, tone preferences, three recurring report templates, metric definitions.
Browsing exposure: Memory ON and web fetch ON for the same account. Both features have been used in the same session 14 times in the last 30 days.
Next check due: 2026-09-29.