أنثروبيك

Claude Code source code leaked: Human error puts Anthropic in a security dilemma

Written by

Picture of فريقنا

فريقنا

Communications Consultant

In an unexpected security slip, Anthropic accidentally published the complete source code of its popular coding assistant, triggering a frantic race to delete thousands of copies from developer platforms amid questions about the company's operational security standards.

In a surprising incident that shook the technology and artificial intelligence industries, Anthropic unintentionally published the complete source code of its popular tool “Claude Code”, an advanced AI-powered coding assistant. This leak resulted from a human error committed by an employee who included a dedicated debugging file in a routine software update last Tuesday. The company is now racing against the clock to erase all copies of the leaked code from the internet, issuing thousands of Digital Millennium Copyright Act notices on GitHub in an attempt to control the spread of the leaked files.

Leak details: How was the source code exposed?

The crisis began to surface when security researcher Shaofan Xu pointed out this security exposure via a post on X, explaining that the source code for Claude Code had been leaked through a map file in the company’s npm package registry. This post quickly spread like wildfire, garnering tens of millions of views in record time. It was revealed that the leak specifically originated from version 2.1.88 of the tool’s npm package, which mistakenly contained a 60MB source map file.

This file acted like a treasure map, leading developers directly to a compressed archive hosted on Cloudflare storage servers. According to reports, the archive contained nearly 1,900 TypeScript files, totaling more than 512,000 lines of proprietary code, representing a massive informational wealth for competitors and developers alike.

Nature of the leaked data and company response

Anthropic quickly confirmed the incident in an official statement, attempting to reassure users and customers. The company stressed that no sensitive customer data or login credentials were breached or exposed. It explained that what happened was merely a software packaging issue caused by human error rather than an external security breach, affirming that it has begun implementing strict measures to prevent such an incident from recurring in the future.

Regarding the nature of the leaked code, experts explained that it relates to the so-called “middleware” wrapping the company’s core AI model. In other words, this is the software layer that directs Claude on how to use auxiliary tools, enforces behavioral guardrails to ensure response safety, and manages interactions with developers. The leak does not include the core AI model weights or the massive training data upon which it was built.

Containment efforts and the cat-and-mouse game on GitHub

By Wednesday morning, Anthropic had submitted massive copyright takedown requests, resulting in the removal of over 8,000 code repositories on GitHub, according to the Wall Street Journal. However, amid mounting criticism, the company later acknowledged that the deletion campaign was excessively broad and narrowed its requests to just 96 repositories.

In an ironic twist, rather than bowing to these legal notices, many independent developers began using AI tools themselves to translate the TypeScript codebase into other programming languages. This innovative step aims to evade copyright claims, complicating the company’s task of completely scrubbing the code from the internet.

A series of slips hitting security reputation

This incident is not an isolated error, but rather Anthropic’s second security stumble in just a few days. Only last week, press reports revealed that the company left nearly 3,000 unreleased files publicly accessible online. These files included a draft blog post describing an upcoming powerful model known internally as “Mythos” or “Capybara.” Furthermore, a similar exposure of a source map file affected an earlier version of the same tool in February 2025.

These recurring slips have drawn intense scrutiny regarding a company that built its identity and brand primarily around concepts of AI safety and responsible technical development. As economic reports noted, this leak raises serious and unsettling questions about the startup’s operational security at a time when Claude Code has become a primary driver of financial revenue, placing its security and commercial future under the microscope.

FAQs

What was the leak that Anthropic experienced?

The company accidentally published the complete source code of its coding assistant during a routine update, leaking more than 512,000 lines of code.

Were user data compromised due to this leak?

The company confirmed in an official statement that the leak did not include any sensitive customer data or passwords, and that the incident stemmed from human error during an update rather than a cyberattack.

How did developers try to evade the company’s removal notices?

Many developers resorted to using AI tools to translate the leaked code from its original language into other programming languages to bypass copyright infringement notices on code-sharing platforms.

Is this Anthropic’s first security slip?

No, it was preceded by another slip a few days earlier involving about 3,000 unreleased internal files left publicly accessible, including information about a new AI model under development.

شارك هذا الموضوع:

شارك هذا الموضوع:

اترك رد

Leave a Reply

الفئات

المنشورات الأخيرة

Discover more from Buzzinga

Subscribe now to keep reading and get access to the full archive.

Continue reading