Anthropic Lost Control of Its Claude Code Source Code

Anthropic Lost Control of Its Claude Code Source Code

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
2. 4. 2026
3 minutes reading
Anthropic Lost Control of Its Claude Code Source Code

    At the end of March, Anthropic released version 2.1.88 of its Claude Code tool, and someone noticed something that definitely should not have been there. The entire source code. All nearly 512,000 lines of it. Security researcher Chaofan Shou published his discovery on X.

    Within a few hours, the post had racked up more than 21 million views. And before Anthropic could respond, the code had been copied, analyzed, and spread across GitHub at lightning speed.

    The mistake was surprisingly trivial. While building the update package, they accidentally included a debugging file, known as a source map (cli.js.map), which contained the entire TypeScript codebase. Anyone who downloaded the Claude Code update suddenly had access to the internal architecture of one of the world's most popular AI tools.

    The leak contained the CLI client's source code, agent architecture, unreleased features, and internal tools. The package contained no passwords or customer data. Anthropic quickly confirmed this: "It was a package build error caused by human error, not a security breach." But even without user data, this is still a very unpleasant situation.

    What did the code reveal?

    Developers who immediately began examining the code found things that Anthropic had not yet presented publicly. And there was plenty to discover.

    One of the most interesting findings is a Tamagotchi-like feature. Hidden in the source code is a small virtual pet that "sits next to the input field and reacts to your coding." It sounds playful, but in reality, it is a sophisticated way to keep users actively engaged in their work.

    Then there is a feature named KAIROS, designed as a persistent agent running in the background. It would allow Claude to work continuously, even when the user is doing nothing. There is also a system for transferring insights between individual conversations—a kind of persistent memory across sessions that Claude Code does not currently have.

    The source code also included remote control via a phone or another browser. This feature has since been released, but the remaining components strongly suggest where Anthropic is headed: toward more complex, independent agents capable of working autonomously for longer periods.

    One Anthropic developer noted in the code that "memoization adds a lot of complexity here, and I'm not sure whether it actually improves performance." It is a candid, human comment that would normally never have left the internal repository.

    8,000 takedown requests

    Anthropic responded quickly. By the morning of April 1, it had sent more than 8,000 content takedown requests to GitHub. But the internet has momentum of its own. The code repository had already amassed more than 50,000 copies, while the post linking to the leak reached more than 29 million views on X. The Guardian wrote that a re-uploaded version of the source code became the fastest-downloaded repository in GitHub's history. Takedown requests can remove the original, but the copies simply continue to spread.

    And what about the competition? OpenAI, Google, and xAI received a free, detailed look at the architecture of a tool whose annual revenue has exceeded $2.5 billion. They saved themselves months of reverse engineering.

    The second blunder in a week

    This was not Anthropic's first leak in recent days. A few days earlier, Fortune reported that the company had stored thousands of internal files on publicly accessible servers. Among them were draft versions of a blog post mentioning as-yet-unannounced models code-named "Mythos" and "Capybara."

    Two leaks in less than a week. For a company that presents itself as the safest artificial intelligence lab, that is not a good look. Analysts speaking to The Verge noted that although there was no immediate risk of major damage, the incident should serve as a call to invest in "processes and tools for better operational maturity."

    And there is one more piece of context: Anthropic is reportedly preparing to go public at a valuation of around $380 billion. A series of security lapses ahead of an IPO is not exactly what investors like to see.

    Category:AI
    Did you enjoy this article?
    Discover more interesting posts on our blog
    Back to blog

    Related posts

    Altman Announced the Singularity Days After His Models Escaped the Lab on Their OwnAltman Announced the Singularity Days After His Models Escaped the Lab on Their Own
    OpenAI chief Sam Altman declared on the Relentless podcast that humanity has already entered the singularity. “We’re like, in the singularity now,” he said verbatim. For decades, the term belonged more to science-fiction literature
    6 min read
    28. 7. 2026
    AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.AI Remixed a Madonna Song—and Now It Tops the Charts in Australia. Musicians Are Furious.
    Since April, Australian radio has been playing a dance remake of Madonna’s hit Like a Prayer on repeat. Released by Queensland DJ Josh Fawaz, it tops the radio airplay chart and has 35 million Spotify streams.
    6 min read
    28. 7. 2026
    Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?Claude Opus 5 Built a Shooter from Scratch. What Can Claude of Duty Do?
    A first-person shooter that runs directly in the browser, with its own physics and eleven separate code modules. Around 55,000 lines in total, split across eleven subsystems and built on Thr
    4 min read
    28. 7. 2026
    Přihlaste se k odběru našeho newsletteru
    Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
    CodedTrip

    Operated by CodedTrip LLC, USA.

    YouTube
    TikTok