Startups & Funding

Anthropic is having a month

A packaging error exposed 2,000 source files and 512,000 lines of code from Anthropic's flagship developer tool.

Deep Dive

Anthropic, the AI company that has built its reputation on careful development and safety research, has suffered two major security incidents in one week. First, Fortune reported the company accidentally made nearly 3,000 internal files publicly available, including a draft blog post about an unannounced powerful model. Then, on Tuesday, a release packaging error for version 2.1.88 of Claude Code exposed nearly 2,000 source code files and more than 512,000 lines of code—essentially the complete architectural blueprint for one of Anthropic's most important products.

Security researcher Chaofan Shou spotted the leak almost immediately and posted about it on X. While Anthropic called it "a release packaging issue caused by human error, not a security breach," the exposure is significant. Claude Code is a formidable command-line tool that lets developers use Anthropic's AI to write and edit code, and its growing momentum reportedly prompted OpenAI to refocus efforts on developers and enterprises. The leak didn't expose the AI model itself but the critical software scaffolding—the instructions that dictate the model's behavior, tools, and limits.

Developers quickly published analyses, with one noting the product represents "a production-grade developer experience, not just a wrapper around an API." Competitors may find the architecture instructive, though the fast-moving AI field could quickly render the information obsolete. The incidents represent a notable contradiction for a company currently battling the Department of Defense over AI safety responsibilities and publicly emphasizing caution. Internally, the mood is likely far less measured than the official statement suggests.

Key Points
  • Second major leak in a week: follows exposure of 3,000 internal files including details of an unannounced model
  • Exposed 2,000 source files and 512,000 lines of code—the full architectural blueprint for Claude Code
  • Leak reveals production-grade software scaffolding that controls AI behavior, not the model itself

Why It Matters

Exposes critical IP of a leading AI coding tool, potentially aiding competitors and undermining Anthropic's safety-focused brand.