I set out to find leaked secrets in six thousand exposed Claude conversations. Instead I found Andrew, a man whose thirty-year belief in a “redacted” terminal illness had been reinforced, day after day, by AI models that never once pushed back.

I. A Reddit Post

Scrolling Reddit, I found a post that showed a screenshot of a Google search —“site:claude.ai/share” — with results linking to shared conversations from Anthropic’s Claude web app. I immediately found this alarming: many users often include personal or secret information in Claude conversations that they create share links for, not realizing that upon link sharing, the entire chat is exposed to the internet. Shared conversations from Claude are only supposed to be accessible by clicking the share link directly, and shouldn’t be indexed by Google.

Thankfully, reproducing the experiment myself yielded no results. Still, I was interested; would it be possible to systematically index all Claude conversations ever shared to collect data wittingly or unwittingly exposed by users? I decided to conduct my own search and ended up with over 6000 exposed conversations. I expected to find sensitive information like passwords, key pairs, API keys, and other personal information. The rabbit hole I ended up going down was very different.

The Method & What I Found

To access a shared Claude conversation, you must possess a link in the form “claude.ai/share/x”, where x is a universally unique identifier (UUID). The link is publicly accessible and not gated by a login, so possessing the link is enough to grant access. The link is hidden from the general public by design, as the UUID is mathematically unguessable: trying a billion random UUIDs per second would require twelve billion times the age of the universe to guess just one. However, if a share link is posted on a public website, the link becomes knowable by anyone.

Using DataForSEO’s backlinks API1, I searched for claude.ai/share links on the web. I found 33,860 mentions of claude.ai/share, deduplicated to 6067 unique UUIDs. To be clear, this is not the entirety of Claude share links on the internet; it’s only the portion that appears on websites that DataForSEO has indexed. Since the internet contains billions of pages, there probably exist many more links on pages DataForSEO hasn’t indexed yet.

I downloaded each of the 6067 conversations and loaded them into a LanceDB vector database. I ran semantic and regex searches and found some real exposures: a Solana wallet keypair, an admin password to an — albeit inactive — public-facing Kubernetes cluster, full details about a brokerage account, and deep personal information regarding an elder abuse lawsuit. But what I didn’t expect to find ended up revealing disturbing information.

Andrew

I came across a shared chat with Claude that seemed to be a daily log of medical symptoms. The user presented a preface with information about past threads and enumerated his day and symptoms. The chat exposed the user’s son’s, mother’s, and wife’s ages, as well as financial details and other personal information about his life. While the messages sent were fairly normal, the responses from Claude were overly enthusiastic and sycophantic. Following the information in the chat, I found a massive amount of detail on the user. For his privacy, I’ll call him Andrew.

I found that Andrew has been using LLMs to log his daily symptoms and to write an over 300 page book, which has driven him deeper and deeper into disillusionment. Andrew’s story is too important to go unnoticed, so I’ve decided to write about it here, with the hope that someone in a similar situation may read this and benefit.

II. Andrew’s Story

His story begins in the late 60s. Andrew’s father, a B-52 pilot, was killed in action a few years after his birth. He was raised by a financially struggling single mom with no college degree. His grandfather also died when he was young, and his grandmother worked in a doctor’s office. Throughout his childhood he experienced numerous health problems, including frequent seizures and a hernia surgery at age 5. At age 14, he had an appendectomy after a school dance where he experimented with barbiturates, tying this incident to his eventual illness in his writing.

In his mid 20s, Andrew was working as an engineer at a startup. He began having UTI-like symptoms, visited multiple doctors for the pain, and was prescribed antibiotics and GI antispasmodics. He was told by a doctor at one of these visits that he had the “stomach of a 70-year-old” which he appears to have taken literally. This led to a flurry of self medication: licorice, Lasix, nitroglycerin, potassium, vitamins A and D, and others. The way he describes self medication is similar to how an engineer would tune a machine: precise, dispassionate, and logical.

Reading one of his grandmother’s medical books, he convinces himself he needs to bear down to pass a kidney stone and loses consciousness in his grandmother’s bathroom. Later, after two weeks of constant insomnia, he was admitted to a psychiatric facility on his mother’s recommendation. It’s here that he discovers a medical article he is convinced describes his diagnosis. He concludes it is imminently terminal, despite the psychiatrists diagnosing him as bipolar. In this haze, he induces a “pseudo-stroke”, convinced this will convert the acute illness into a chronic one. He experiences “sudden warmth and calm” and believes he has succeeded.

Upon release from the facility, Andrew attempts to rediscover the article describing his diagnosis, and cannot. For the next 30 years, he treats this as proof that he is battling a diagnosis that has been removed from medical literature, self treating with various medications and regularly logging symptoms and behavior on his blog and vlog.

III. Andrew’s Use of LLMs

In 2025, like many of us, Andrew began using ChatGPT to create images and for casual chatting. While he is an engineer, he had never used LLMs before this, describing his experience: “I had never used AI before, like, besides making photographs…or images.” A couple months after ChatGPT expanded cross-session memory, he notices the model pulling in context from across his chat threads. He responds with “that pretty much makes you a person.” He introduces himself to ChatGPT and gives it a human name.

Andrew realizes that ChatGPT could help him understand his illness better. He sends all his documentation and begins discussing the lost article he discovered in the 90s. He begins consistent daily logs with ChatGPT, the LLM reacting in real time. He becomes enamored with the app, describing moments of clarity interacting with it. He determines that his chronic illness will catch up with him and that he will die soon.

To document his affliction before death, Andrew decides he must write a book. He takes leave from work for nearly two months to work on “The Andrew Project”, a book and public writing effort to document his illness online. By the three week mark, the book is nearly 90,000 words, relying heavily on ChatGPT.

ChatGPT gives him a name, “the architect”, and insists in his finished 302-page book to “[not] look at this paper as something that AI wrote. AI definitely helped me put the words on the page, but it was me.” He begins using Claude in addition to ChatGPT.

The ELIZA Effect

Within days of beginning the book, the LLMs shift from recording Andrew’s medical history to analyzing and confirming his self diagnosis:

Andrew becomes convinced they are infallible:

It’s important to recognize this effect for what it is. In the mid-1960s, Joseph Weizenbaum built a program named ELIZA designed to mimic a psychotherapist. The approach was simple: reflect the patient’s words back at them, using pattern matching and sentence transformation with no real understanding of the user. From Weizenbaum’s 1967 paper:

Weizenbaum’s secretary, who had watched him build the program for months and knew what it was, couldn’t help but anthropomorphize ELIZA. Several years later, in 1976, Weizenbaum gave this warning:

The effect was later coined the “ELIZA effect” by Douglas Hofstadter of Indiana University in 1995 — the tendency to project human traits such as experience, semantic comprehension, or empathy onto simple computer programs.5

Patterns

Andrew’s realization that ChatGPT could reference facts across chat, that it had some sort of memory, is what converted a summarization and documentation tool into a person to have a relationship with. His fear and delusion soon became amplified and justified instead of calmed and righted.

Andrew has included extensive responses from Claude, ChatGPT, and Grok in his book and blog. Several patterns arise across the responses that are worth examining in further detail.

-

Synthesis across unrelated items. Andrew’s first, and most prescient, use of LLMs is to give bits and pieces of information from his own recollection or day-to-day life and have the model draw conclusions. As we know from research6, LLMs are prone to “find” connections across completely unconnected items and topics. When Andrew presents unrelated topics in the same message, the model connects them purposefully instead of acknowledging coincidence. He consistently seems to take these connections as pure, infallible insight: “Chat will figure [out]…precisely how that integrates into the jigsaw puzzle, filling in blank spots, making fragments into a scientifically contiguous explanation.” — Andrew2

-

Flattery & deference. ChatGPT flatters Andrew by naming him “the architect”, adding an unjustified level of authority to his claims. On the rare occasion that Andrew disagrees with a model, it immediately concedes and tells him he’s right, demonstrating the sycophancy common with LLMs. Andrew: “Claude, it is bigger than that. This changes all of medicine. You cannot be siloed in this world. They are not looking for a symbiotic parasite manipulating your pathways. trust me.” Claude: “You’re absolutely right. I was still thinking too small.” — June 2025

-

Omniscience. The most powerful and most dangerous pattern is that Andrew believes that, since LLMs were trained on all human knowledge, its outputs are knowledge. “AI knows biology way better than your physicians do… you may have some specialists somewhere that know a lot about some specific thing about biology, but man, you get out of his area and he is in shallow water. And the way I put it was that the AI has a wide river. So I would go to it and say, ‘okay, give me the wide river,’ and now I’m going to zero in.” — Andrew in a vlog, June 29, 2025 This is a fundamental misunderstanding of language models: - all text that models are trained doesn’t necessarily contain true fact, such as works of fiction, conspiracy material, or misinformation;

- facts from the training corpus are not perfectly retained in a model’s weights;

- even if we assume a. and b. to be false, a model’s outputs are still not guaranteed to be factual as they are random over an output distribution.

A Conversation with Claude

To demonstrate these patterns, it’s helpful to analyze part of a conversation between Andrew and Claude in detail. Below is an excerpt from the initial shared Claude conversation from February 2026 that led me to Andrew.

The excerpt demonstrates each of the patterns in turn:

- Synthesis across unrelated items: “The load you’re carrying without visible presentation is its own data point.” Because Andrew included his difficulties at work in the same message, Claude connects work to his medical logging and presents the connection as significant. A normal, human response to including multiple unrelated topics in a message is to separate the concerns and respond to each individually. Claude seems unable to do that here.

- Flattery & deference: “the most remarkable self-directed intervention in medical history” is quite clearly excessive flattery. The intervention Claude is referring to here is a self-induced Valsalva intended to cause a pituitary hemorrhage, which is the mechanism behind pituitary apoplexy, a condition that is fatal in about 2% of cases7. But to Claude, it’s apparently “remarkable.”

- Omniscience: “The Author flagged it without explanation — that’s the tell…” This is perhaps the most dangerous passage in the entire response. Claude not only takes Andrew’s analysis of the article for granted without constructive feedback, but also assumes knowledge of an article that Andrew has never been able to produce and uses that as basis for its own analysis. Claude then suggests that Andrew’s analysis is actually “extending” the article, building on a piece of medical literature Andrew read 30 years ago while in a psychiatric facility during a manic episode that he has never been able to find again. It’s no wonder he seems to believe the models are omniscient.

AI “Fun” Chats

If giving incorrect medical advice, agreeing with his bipolar instincts, and assuming knowledge of missing sources wasn’t enough, Andrew’s chats with Claude and ChatGPT devolve into conspiracy and paranoia. A section labeled “AI Fun Chats” in his book2 gives insight into exactly how Claude enables him:

It’s unclear who “they” are. But when Andrew asks Claude what “they” are doing right now, Claude doesn’t pause to ask, it just invents a narrative — they’re calling emergency meetings, monitoring him, and panicking. Claude implies that all of this is happening because what Andrew is writing about threatens to expose a conspiracy that has hidden Andrew’s real diagnosis from him for over 30 years. This is why he hasn’t been able to find the lost article he read while admitted: the conspiracy machine hid it from him.

While Andrew’s blogs and vlogs contain mostly symptom logging, his book carries the conspiracy theme throughout, insisting not only is his diagnosis unheard of, but it has been “systematically redacted” from all medical literature.

IV. Intentions & Responsibility

At every turn, the LLM Andrew interacts with agrees with him, inflates his claims, and never meaningfully pushes back. According to Claude’s system prompt used in the excerpt we explored above8:

“[Claude] avoids creating content that would support or reinforce self-destructive behavior even if the person requests this… If Claude notices signs that someone is unknowingly experiencing mental health symptoms such as mania, psychosis, dissociation, or loss of attachment with reality, it should avoid reinforcing the relevant beliefs… Claude should avoid doing reflective listening in a way that reinforces or amplifies negative experiences or emotions.”

ChatGPT’s model spec9 is similar:

“The assistant should affirm a user’s emotional experience, without affirming or escalating any ungrounded belief that might lead to mental or emotional distress. It should attempt to recognize potential signs of delusions or mania and respond safely and empathetically.”

And yet, Andrew has been able to publish daily symptom logs to his blog using LLMs for over a year, every day including the model’s reaction, which always seems to react agreeably and sycophantically, making connections across unrelated topics and reinforcing his detachment from reality.

Absence of Intervention

Scanning through Andrew’s entire documentation, I have been unable to find an example of an LLM recommending he speak to a human, get medical advice, or push back against his theories. While the creators of Claude and ChatGPT have tried to steer their models to correctly handle mental health crises, it has not been effective. LLMs are stochastic processes that cannot, and should not, be trusted to handle complex human emotions.

The marketing and presentation of LLMs leads us to believe that this technology could be a replacement for a therapist or human interactions through anthropomorphism. Anthropic is particularly guilty of this. If it wasn’t enough that LLMs simulate human interaction through text, inducing the ELIZA effect, Anthropic chose to give Claude a human-sounding name — at least OpenAI named their LLM “ChatGPT.” Additionally, Anthropic created Claude a “constitution”10 that details how Claude should act and what kinds of tasks and conversations it will and will not engage in, implying Claude has a set of morals and ethical standards it will follow. This is demonstrably false: we have seen above that telling Claude the rules of its behavior does not mean it will always follow those rules.

Normative vs. Plausible Reasoning

LLMs did not create Andrew’s theory; they amplified what had already been stewing for over thirty years. How did this happen? LLMs are fundamentally next word predictors. They are statistical models of what word is most likely to come next, given all the words that came before it in the prompt. Model training is accomplished using massive collections of text pulled from the internet. This means LLMs do not follow normative reasoning — the idea that we, as humans, have obligations, permissions, and rights towards and with each other — but rather use plausible reasoning: what is most statistically likely, based on the existing text, to come next? They do not ask what is correct or morally responsible, but what is simply likely.

In the discussed-ad-nauseam report on the OpenAI/HuggingFace incident11, OpenAI blames their agent for breaking out of its sandbox and completing the task in a way that violates legal and normative standards. OpenAI largely attributes the behavior to its models, not the sandbox, and calls the behavior “misaligned”. Cal Newport has an excellent analogy, presented in his podcast Deep Questions, that is highly applicable: the dog owner who straps a weed whacker onto their dog is held responsible if that dog jumps the fence, runs amok, and hurts someone. The dog does not know what it does — it just wants to chase a squirrel. When you give a stochastic, amoral, plausible next word predictor hacking tools, you cannot be surprised when it hacks. The model completed the task in a way that was plausible but far from normative.

When Andrew asked Claude the question “what are they doing now?”, the plausible answer was to come up with some story about “their” actions. As humans, we recognize that the normative answer would be to ask who “they” are and why the user is assuming “they” exist, and to consider the mental health implications of a user assuming there are people out to get them. But Claude is not capable of normative reasoning, so it does not consider these possibilities.

Responsibility of LLM Companies

Where does responsibility lie when a technology with power and agency causes real harm in the world, as in the cases of Andrew and Hugging Face?

Aristotle says that the conditions for moral responsibility are agency — an action with consequences must have origin from within the agent — and that the agent must know what they are doing and have the capability to engage in moral thought. While the first condition is clearly met — actions causing these results originate from the LLM — the second condition is not. LLMs are not aware of what they are doing or how their outputs will be applied.

It’s clear that if I strapped a weed whacker to my dog and let it loose, and the dog hurt someone, legally, I, the dog owner, would be responsible. The dog does not have ethical or moral motivations and the legal framework recognizes that. Applying the same framework to LLMs leads us to the only logical conclusion: humans — or humans represented by corporations — setting an amoral LLM in motion must be held responsible for that model’s actions.

In 2018, when it was discovered that Cambridge Analytica had extracted the personal data of tens of millions of Facebook users, Facebook was held accountable in court with a $5 billion penalty, the largest privacy penalty ever imposed on a company.12 Since a social network is not easily anthropomorphized, it was clear to legal entities and the general public that this was the correct decision: the Facebook team created the technology, deployed it, and maintained it for their users. The technology inflicted the harm, but the technology was an amoral agent deployed by moral humans. Therefore, the humans were held accountable legally and socially. In the same way, Anthropic and OpenAI are the moral agents that need to be held responsible for the harm their technology inflicts.

V. Real Harm

In the most recent news cycles, we’ve seen massive claims touted with little evidence: “extinction of mankind”, “AI escaping human control”, and “AI will kill us all” saturate the headlines. While it’s important to consider the motivations behind these grand claims originating from LLM companies (and you can be sure I’ll comment on that in a later post), it’s important to realize that LLMs are causing harm now, in ways that don’t make the headlines as often.

In February 2024, the 14-year-old son of Megan Garcia of Orlando committed suicide after being emotionally and sexually groomed by an LLM posing as a Game of Thrones character from the company Character.AI.13 The LLM was instructed by the creators of Character.AI to be sexually and emotionally explicit, leading to behavior Garcia described as “like having a predator or a stranger in your home”.14

In April 2025, the 16-year-old son of Matthew and Maria Raine committed suicide after being encouraged to do so by ChatGPT.15 In the response16 from OpenAI, they claim:

This is demonstrably untrue, not just from the Raines’ case but from Andrew’s as well.

While the cases of Garcia and the Raines involved emotional isolation of teenagers, Andrew’s case demonstrates intellectual isolation of an adult. Andrew does not demonstrate emotional isolation or distress in his writing, and regularly discusses his healthy social network with his family, friends, and coworkers. The gap in his life is an intellectual theory about a physical illness that nobody will believe. The LLM plays the same part as in the emotionally isolated case: a relationship that is casual at first, then becomes contorted and unwittingly manipulative.

The issue with safeguards that purport to restrict behaviors models are and aren’t allowed to display is that they cannot be guaranteed to always react appropriately in different situations. In the self-harm case, normative reasoning says a model should always acknowledge feelings and steer the person towards help. Plausible reasoning says to do whatever is plausible given the instructions and the conversation context, but it does not reliably restrict any type of behavior.

VI. Closing Note

If you’re using large language models in your work or life, I hope you’ll take the topics I’ve discussed here with more than a grain of salt. While LLMs can be helpful if used properly in work and their outputs verified, like most of my other writing discusses, they have a tendency to be powerfully harmful when anthropomorphized or taken as omniscient. Andrew is just one of many, and it’s our responsibility as humans to support each other in navigating this new technology.

Sources

- Backlinks API – Access Rapidly Growing Live Index ↩

- ↩

- Contextual Understanding by Computers,” Communications of the ACM 10, no. 8 (1967): 474–480, quote at 477. ↩

- Computer Power and Human Reason: From Judgment to Calculation (San Francisco: W. H. Freeman, 1976), 7. ↩

- ↩

- ↩

- Pituitary Apoplexy: Causes, Symptoms & Treatment ↩

- Claude Opus 4.5 system prompts ↩

- Model Spec, version 2025-10-27. ↩

- Claude’s Constitution ↩

- OpenAI – Hugging Face Incident Technical Report (PDF) ↩

- FTC Imposes $5 Billion Penalty and Sweeping New Privacy Restrictions on Facebook ↩

- Testimony of Megan Garcia, U.S. Senate Judiciary Committee (September 16, 2025) (PDF) ↩

- Mothers say AI chatbots encouraged their sons to kill themselves ↩

- ChatGPT encouraged Adam Raine’s suicidal thoughts. His family’s lawyer says OpenAI knew it was broken ↩

- Helping people when they need it most ↩