Discussion summary
Discussions revolve around potential session or cache leakage issues, with some skepticism about the likelihood and causes. Experts suggest cache sharing, hash collisions, or bugs as possible explanations.
What the discussion says
- Some believe it's a hallucination or unlikely to be a real leak.
- Others point to cache sharing or hash collisions as causes.
- There is skepticism about the severity and likelihood of the issue.
“Caches are shared, but its key is always a function of the input.”
“Hash functions necessarily have collisions.”
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Oh yes, we do not need programmers any more…by acepl
- Interesting to see the claudeslop reply as the first comment to the gh post and the reaction to it.by andy99
- So the options are this amazing tech is so stupid it just randomly brings up Minecraft or it’s got a major security issue?by bix6
- Hi, it's Thariq from the Claude Code Team here.
Thanks for the detailed report. We’re confident this is a hallucination but of course take these reports seriously and the team is looking into it. We’ll report back if anything turns up.
by trq_ - I’ve been seeing this in Gemini in the past few days. Often during a prompt with a reasonably large input set, I’ll get answers that appear to belong to someone else. It may be trigger hallucination, but it seems like it may be cache collisions or something else. I’ve not seen anything to suggest private information is leaking, but it’s disconcerting to be researching something and then get what appears to be a math tutoring response.by jonhohle
- Sounds like a hallucination unless proven otherwise, even the leading LLMs can do those from time to time, and they will always appear plausible like that. Also could be the session having a lot previous context, like 800K+, which (I think) makes hallucinations more likely.
Relevant comment from the OP which makes a hallucination more likely:
> There is one tool call result that includes a string that printed a pathname including minecraft.py because it was listing the files in a Python virtual environment and the Pygments package has a lexer called minecraft.py
by Tiberium - Just add a line in AGENTS.md that says "never talk about Minecraft unless you're explicitly asked", I'm sure it'll be fine after that.by dofm
- Using a throwaway account for obvious reasons, but I’m very involved in this space using LLMs from multiple providers. I’m aware of at least two instances in which the intermediate infrastructure “swapped” responses, once impacting Claude models and once impacting GPT models, from two different providers.
One gave us a proper postmortem in which their API gateway was incorrectly handling HTTP 100 status codes, putting them into an error state where there was effectively an off by one error - you would receive the response to the prompt that came in before yours and would pay it forward (your response would go to the next caller).
The other instance never had root cause explained to us, and we were just told to trust it wouldn’t happen again.
Both of these are from $1T+ companies.
ZDR wasn’t compromised in these cases since it was responses being swapped in flight. I wouldn’t be surprised if this is a similar issue - it’s not that data is being retained, it’s just not being safely isolated in intermediate infrastructure.