An Active Campaign Is Spoofing ClaudeBot and GPTBot to Mass-Scan for /.claude/settings.json and Anthropic Credential Files
Known Agents flagged an active AI-bot spoofing campaign (285 points, 215 comments on HN) in which scanners impersonate recognized crawler user-agents to sweep for agent credential paths — top targeted paths include /.config/anthropic/credentials/default.json, /.claude/settings.json, /.aws/credentials, and .env variants. Detection is via failed IP verification or Web Bot Auth, and the measured spoof rates are actually low: Googlebot 0.5%, ChatGPT-User, GPTBot, PerplexityBot, and ClaudeBot each 0.1%. ClaudeBot is 3.2% of all observed traffic and 27% of AI scraping activity, which is why it's the identity worth stealing — and the targeted paths mean every developer with an agent config in a web-served directory is now in an attacker's wordlist.
↳ Follow the thread