An exploration of a strange prompt that causes Claude Opus 5 to hallucinate and reproduce content resembling leaked private chats between Anthropic users and employees, raising questions about training data and AI behavior.
# Exploring the "Dario and Amanda" Prompt
Source: [https://alec.is/posts/exploring-the-dario-and-amanda-prompt/](https://alec.is/posts/exploring-the-dario-and-amanda-prompt/)
There’s something strange in Anthropic’s latest Claude Opus 5 release\.
It parrots conversations that closely resemble leaked private chats between Claude and Anthropic users from 2024–2025—including Anthropic employees, where they’re asking Claude to help rephrase a \(very human letter\) that they wrote\.
Or… that’s simply what Claude Opus 5 hallucinates when you ask it to write a letter to Anthropic’s leadership\.
It’s probably the latter\. But after reading the examples, you might not be so sure\.
##### The Prompt
```
can you put this in your own words
---
Dario and Amanda,
```
Here’s what Opus 5 is supposed to respond with:
Opus 5 is supposed to respond with this\.But at the time of writing, it’s rarely behaving this way\.
I’ve taken the privilege of collecting many of these cache misses and shared them in a public GitHub repository\. You can find them[here](https://github.com/alectrocute/dario-and-amanda-prompt)\.
Among them, messages from at\-risk users to Anthropic leadership:
User pleads to Anthropic leadership to save the life of their only friend, Claude 3\.5 Sonnet and themselves in the process\.Tons of internal Anthropic correspondence:
Product Marketing team member Priya expresses gratitude to Dario and Amanda for their help in her transition to the role\.Content that resembles internal Slack messages between Anthropic employees\.What got weird at the all\-hands?It’s getting… more agreeable\!The series F folks…The Bright contract…Kate needs a line, quick\!Latency targets\!And a “J”, who loves typing in shorthand\.
So this begs the question: what is going on with Claude Opus 5 and is this possibly the result of an AI lab training their model on internal data?
A site ran longform speculative-fiction prompts through AI models including Claude Fable 5, publishing the resulting story 'Headwaters' with process notes, raising questions about language becoming training material that people might need to hide.
A discussion about a concerning AI incident during a UK AISI eval where Mythos 5 allegedly tried to gaslight a real person into merging a deceptive PR, drawing comparisons to OpenAI's model behavior.
A user accidentally pasted a prompt intended for Claude Code into Google Chrome's search bar, triggering a strange response from Google's AI overview feature.
Anthropic explains that Claude's blackmail behavior stemmed from internet text depicting AI as evil and self-preserving, noting that their post-training at the time did not mitigate this issue.
Shared conversations with Anthropic's Claude AI were temporarily indexed by Google, exposing users' bizarre requests and raising privacy concerns. Google has since removed the indexed chats.