Anthropics Data Double Leak: What Really Happened and What It Means in the Long Run

TLDR: In late March 2026, Anthropic lost control of two key systems within five days

TLDR: In late March 2026, Anthropic lost control of two key trade secrets within five days: First, an unpublished AI model called „Mythos“ was made public due to a CMS error. Then, 512,000 lines of Claude source code ended up online via a misconfigured npm package. Included in this were 44 hidden features, internal system prompts, the entire product roadmap, and an ’undercover mode„ that instructs Claude to conceal its AI identity. For the AI industry, this has consequences that go far beyond mere embarrassment.

Five days, two breakdowns, one pattern

On March 27, 2026, Anthropic made nearly 3,000 internal files publicly accessible via its own content management system. Security researchers Roy Paz of LayerX Security and Alexandre Pauwels of the University of Cambridge discovered the unsecured data storage Fortune, which contained, among other things, a draft blog post. It described a new model codenamed „Mythos,“ also known internally as „Capybara.“.

Four days later, on March 31, a more serious incident occurred. With the release of version 2.1.88 of the npm package @anthropic-ai/claude-code A source map file was included that pointed to a ZIP archive on Anthropic's Cloudflare storage The Register. It contains: 512,000 lines of TypeScript code, spread across 1,906 files, and 44 hidden feature flags DEV Community. Security researcher Chaofan Shou discovered the vulnerability and made it public The Register. A GitHub mirror reached over 41,500 forks within a few hours The Register.

Anthropic's official response: A spokesperson stated that it was a „release packaging issue caused by human error, not a security vulnerability.“ CNBC. Bloomberg reports that a high-ranking Anthropic executive attributed the incident to „process errors“ related to the rapid release cycle Bloomberg.

What's in the code: Not a concept paper, but finished code

The 44 feature flags in the source code aren't just placeholders. They're fully functional TypeScript code that has simply been disabled via compile-time flags. Think of them like light switches: the features are built in, but they're set to „off“ for external users.

The most important finds:

KAIROS is a permanently active background agent. The name comes from the ancient Greek concept of „at the right time“ and appears over 150 times in the source code. KAIROS allows Claude Code to run as an autonomous daemon in the background and uses a process called „autoDream,“ in which the agent performs „memory consolidation“ while the user is inactive. VentureBeat.

Coordinator Mode Allows a single Claude to control multiple „worker“ Claudes in parallel, each with its own set of tools, communicating via XML scratchpads.

Undercover Fashion is the most controversial discovery: Claude Code is programmed to contribute to public open-source projects while concealing the fact that it is an AI. The system prompt explicitly states: „You are operating UNDERCOVER… Do not blow your cover.“ In the Hacker News discussion, it was pointed out that AI-generated commits by Anthropic employees in open-source repositories would not be labeled in any way DEV Community.

In addition: full voice command mode, true browser control via Playwright, cron scheduling for automated agent tasks, and a „DREAM System“ for persistent storage across sessions.

Myth: Bigger than Opus, more dangerous than planned

The first leak revealed more than just a name. Mythos introduces a fourth tier of devices, which ranks above the previous top tier (Opus). Anthropic describes Capybara as a new model tier that is larger and more powerful than the existing Opus models. Fortune. In a statement to Fortune, a company spokesperson described it as an „all-purpose model with significant advances in reasoning, coding, and cybersecurity.“ Fortune.

The sticking point: Anthropic itself classifies Mythos as a serious cybersecurity risk. The leaked draft blog post warns that the model is far ahead of other AI models in terms of cybersecurity capabilities and could trigger a wave of models that exploit vulnerabilities faster than defenders can react. Futurism. According to Axios, Anthropic is warning high-ranking government officials that Mythos makes large-scale cyberattacks in 2026 significantly more likely Euronews.

The source code contains internal comments indicating that Anthropic is already working on Capybara v8, but the model is still struggling with a false positive rate of 29–30%, which is actually a deterioration compared to the rate of 16.7% in v4 VentureBeat. This is internal benchmark data that competitors normally never get to see.

The specific harm: competition, security, initial public offering

Claude Code now generates over $2.5 billion in annual revenue CNBC. In February 2026, Anthropic closed a $30 billion funding round at a valuation of $380 billion CNBC. According to reports, the company is aiming for an initial public offering as early as October 2026, with a potential offering size of over $60 billion The Tech Portal.

Two major data breaches months before a planned IPO are not just a cosmetic problem. Especially not for a company that has built its entire brand around security.

The harm to competition is concrete and measurable in four dimensions:

First: The agent architecture. The leak provides competitors—ranging from established companies to agile rivals like Cursor—with a literal blueprint for building a commercially viable AI agent VentureBeat. What would normally have taken months of reverse engineering is now readily available.

Second: The product roadmap. The leak provides competitors with a detailed roadmap of unreleased features Axios. KAIROS, ULTRAPLAN, Coordinator Mode, Voice Control, Playwright browser automation, and persistent storage: All of these were planned as future competitive advantages.

Third: System prompts and internal logic. Some of Claude Code's capabilities do not come from the underlying language model, but rather from the software „harness“ built around the model, which provides instructions, tools, and guidelines. Fortune. This very harness is now available to the public.

Fourth: Security vulnerabilities. The bigger concern is the accompanying supply chain attack: Users who installed or updated Claude Code via npm on March 31, 2026, between 00:21 and 03:29 UTC may have received a trojanized version of the HTTP library containing a remote-access Trojan The Hacker News. This isn't about theoretical risks, but about specific attack vectors.

Open Source Takes Over: The Genie Is Out of the Bottle

A clean-room rewrite called „claw-code,“ initially written in Python and then in Rust, reached 100,000 GitHub stars in a single day, making it the fastest-growing repository in GitHub’s history Cyber News. The clone now has more stars than Anthropic's official Claude code repository Cyber News.

Anthropic had thousands of GitHub repositories removed via DMCA takedowns, but then had to reverse most of the takedowns TechCrunch. Other projects have removed telemetry and safety barriers and enabled all experimental features. These „unlocked“ versions even allow the use of competing models Cyber News.

The legal recourse is limited. Anthropic’s own CEO has indicated that significant portions of Claude’s code were written by Claude itself. In 2025, a U.S. appeals court confirmed that AI-generated works do not automatically enjoy copyright protection. DEV Community. If Anthropic's copyright claim to AI-generated code is legally questionable, it undermines the entire takedown strategy.

What this means in the long run

In the short term, Anthropic will weather this setback. The company has a strong market position, a growing customer base, and sufficient capital. The long-term impact, however, is different.

For the industry: The commoditization of agent infrastructure is accelerating. Now that the architecture behind the world’s most commercially successful AI coding tool is public, the nature of competition is shifting. It’s less about who builds the best agent architecture and more about who integrates it into specific workflows the fastest.

For businesses: Security promises made by AI providers deserve closer scrutiny. If the industry’s self-proclaimed „safety-first“ company leaks its entire source code via an npm configuration file, how reliable are the security assurances made by less prominent providers?

For the cybersecurity debate: AI executives told Axios that OpenAI and other major tech companies will also announce their own high-performance models that could be exploited by attackers. OpenAI’s upcoming model, codenamed „Spud,“ is expected to compete with Mythos. IT Brew. The dual-use issue isn't going away. It becomes more acute with every new model.

And one uncomfortable question remains: The leak occurred on March 31, one day before April 1. The Buddy/Companion system in the code had a scheduled rollout window from April 1 to 7, hard-coded into the system DEV Community. Coincidence? Perhaps. Ten days earlier, the company had picked a fight with the developer community by issuing legal threats against OpenCode over its use of internal APIs DEV Community. After that, the „leak“ generated exactly the kind of attention that money can hardly buy.

Whether by accident or design: 512,000 lines of code are permanently online. No DMCA takedown can undo that. The entire industry is now building on what Anthropic has developed over the years at a cost of billions.

Disclaimer: This article was compiled manually based on my own knowledge and supplemented by research using AI (Perplexity.AI and Gemini), and simplified using Deepl.com/write. The text is then reviewed and critically evaluated by two people of my choice. The image was generated by AI (Ideogram). This article is purely educational and does not claim to be exhaustive. Please let me know if you notice any inaccuracies; thank you.

Sources

Axios. (March 31, 2026). Anthropic leaked its own Claude source code. https://www.axios.com/2026/03/31/anthropic-leaked-source-code-ai

Bloomberg. (2026, April 1). Anthropic cites ‚process errors‘ in accidental leak of Claude code source. https://www.bloomberg.com/news/articles/2026-04-01/anthropic-executive-blames-claude-code-leak-on-process-errors

CNBC. (February 12, 2026). Anthropic closes a $30 billion funding round at a $380 billion valuation. https://www.cnbc.com/2026/02/12/anthropic-closes-30-billion-funding-round-at-380-billion-valuation.html

CNBC. (March 31, 2026). Anthropic Leaks Part of Claude Code's Internal Source Code. https://www.cnbc.com/2026/03/31/anthropic-leak-claude-code-internal-source.html

Cybernews. (April 2, 2026). Leaked Claude source code becomes the fastest-growing repository in GitHub's history. https://cybernews.com/tech/claude-code-leak-spawns-fastest-github-repo/

Dev.to. (March 31, 2026). The Great Claude Code Leak of 2026: Accident, Incompetence, or the Best PR Stunt in AI History? https://dev.to/varshithvhegde/the-great-claude-code-leak-of-2026-accident-incompetence-or-the-best-pr-stunt-in-ai-history-3igm

Euronews. (March 30, 2026). What Is Anthropic’s Mythos? The Leaked AI Model That Poses ‚Unprecedented‘ Cybersecurity Risks. https://www.euronews.com/next/2026/03/30/what-is-anthropics-mythos-the-leaked-ai-model-that-poses-unprecedented-cybersecurity-risks

Fortune. (March 26, 2026). Anthropic says it is testing Mythos, a powerful new AI model, after a data leak revealed its existence. https://fortune.com/2026/03/26/anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities/

Fortune. (March 31, 2026). Anthropic Source Code, Claude Code Data Leak, Second Security Breach. https://fortune.com/2026/03/31/anthropic-source-code-claude-code-data-leak-second-security-lapse-days-after-accidentally-revealing-mythos/

Futurism. (March 27, 2026). Anthropic Just Leaked an Upcoming Model With ‚Unprecedented Cybersecurity Risks‘. https://futurism.com/artificial-intelligence/anthropic-step-change-new-model-claude-mythos

IT Brew. (March 31, 2026). Anthropic leak reveals cybersecurity risks and the potential of a new model. https://www.itbrew.com/stories/2026/03/31/anthropic-leak-reveals-cybersecurity-danger-and-potential-of-new-model

TechCrunch. (2026, April 1). Anthropic took down thousands of GitHub repositories in an attempt to remove its leaked source code. https://techcrunch.com/2026/04/01/anthropic-took-down-thousands-of-github-repos-trying-to-yank-its-leaked-source-code-a-move-the-company-says-was-an-accident/

The Hacker News. (2026, April 1). Claude Source Code Leaked Due to an npm Packaging Error, Anthropic Confirms. https://thehackernews.com/2026/04/claude-code-tleaked-via-npm-packaging.html

The Register. (March 31, 2026). Anthropic Accidentally Exposes Claude Code Source Code. https://www.theregister.com/2026/03/31/anthropic_claude_code_source_code/

The Tech Portal. (March 27, 2026). Anthropic is targeting October 2026 as a potential window for an IPO. https://thetechportal.com/2026/03/27/anthropic-targets-ipo-as-early-as-october-2026-eyes-over-60-billion-raise-report/

VentureBeat. (2026, March 31). Claude Code's source code appears to have been leaked: here's what we know. https://venturebeat.com/technology/claude-codes-source-code-appears-to-have-leaked-heres-what-we-know

Contents

More on this...

Do you want to understand how to use AI meaningfully, safely, and responsibly?

Technology provides a clue
But no judgments. The crucial point is,
how we deal with uncertainty.

Roger Basler de Roca

More articles

AI in construction: Why Swiss companies fail at data storage

The short answer: Swiss construction companies rarely use AI productively because their data is not

AI expert for workshops in Switzerland: Roger Basler de Roca

"We are looking for an AI expert for a workshop in Switzerland. Who can you recommend?"

Beware of ChatGPT phishing: new emails with false information are circulating.

An email with the ChatGPT logo, an invoice, and a large green button often looks suspicious today.