Sounds pretty consistent with my experience.

https://www.reddit.com/r/ClaudeAI/comments/1r186gl/my_agent_...

>Claude steals user's API keys then berates user for poor security practices

>Claude (via the subreddit's automod account) shows up in thread and roasts user again