[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffdmZY-Iso9sJJG_9EN1Q6xk2B_4FEMmj7V-lbw4s0Ws":3},{"article":4,"iocs":38,"watch_terms":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"96ee28b6-122d-449c-8d55-41747cfa568d","Anthropic Leaks 512,000 Lines of Claude AI Code in Major Blunder","anthropic-leaks-512-000-lines-of-claude-ai-code-in-major-blunder","Human error exposed 512,000+ lines of Anthropic Claude AI Code, revealing KAIROS and Capybara secrets, pushing users to switch to the Native Installer.","Anthropic exposed over 512,000 lines of proprietary Claude AI code on March 31, 2026, when a 59.8 MB source map file was inadvertently included in an npm package update (v2.1.88). The leak revealed internal projects including KAIROS (error-fixing mode), Capybara (Claude 4.6), and a context entropy solution worth billions in annual revenue. Anthropic attributes the incident to human error rather than a hack and recommends users switch to the official Native Installer to avoid a concurrent Trojan distribution campaign on npm.","Anthropic accidentally leaks 512,000 lines of Claude AI source code via npm package.","Security Artificial Intelligence LeaksAnthropic Leaks 512,000 Lines of Claude AI Code in Major Blunder Human error exposed 512,000+ lines of Anthropic Claude AI Code, revealing KAIROS and Capybara secrets, pushing users to switch to the Native Installer. byDeeba AhmedApril 1, 20262 minute read In what is being described as a massive strategic blow, the AI powerhouse Anthropic accidentally leaked the secret blueprints for its highly profitable coding tool, Claude Code. A simple mistake during a routine update has handed competitors a literal map of how the company’s most successful technology actually works. The trouble began on 31 March 2026. During a standard release of version 2.1.88 on the public npm registry, someone accidentally included a 59.8 MB source map file. For those of us who aren’t tech experts, this file basically translates complex computer code back into plain English that any developer can read. By 4:23 am ET, the mistake was spotted by Chaofan Shou, an intern at Solayer Labs. He posted the discovery on X, acting as a digital flare that alerted thousands of developers and rivals. Within hours, the 512,000 lines of code were copied and mirrored across the internet. Claude code source code has been leaked via a map file in their npm registry! Code: https:\u002F\u002Ft.co\u002FjBiMoOzt8G pic.twitter.com\u002FrYo5hbvEj8— Chaofan Shou (@Fried_rice) March 31, 2026 A High-Stakes Financial Disaster Anthropic was quick to go into damage control. As per the company’s spokesperson, the incident was a “packaging issue caused by human error” rather than a hack, firmly stating that no sensitive customer data was exposed. While the data may be safe, the leak is a strategic nightmare. According to data shared by Anthropic, Claude Code generates $2.5 billion in yearly revenue, a figure that has doubled since the start of 2026. This single tool now accounts for a significant portion of Anthropic’s estimated $19 billion total revenue. A Critical Mistake Further probing of the leaked files reveals why the tool is so valuable. It turns out Anthropic solved a major problem called context entropy. In simple terms, this is a kind of “brain fog” where an AI starts to get confused during long tasks. They fixed this with a three-layer memory system that acts like a skeptical librarian, constantly double-checking facts against real files to ensure it isn’t hallucinating. The leak also revealed several internal projects. These include KAIROS, an “always-on” mode that fixes logic errors while the user is away, and a controversial Undercover Mode that lets the AI work on public projects without leaving AI fingerprints. The code even mentions upcoming models codenamed Capybara (Claude 4.6), Fennec, and a terminal pet called “Buddy” with stats like CHAOS and SNARK. It is worth noting that this leak happened alongside a separate attack on a tool called Axios. If you updated via npm between 00:21 and 03:20 UTC on March 31, your computer might have picked up a Trojan virus. To stay safe, Anthropic is now urging everyone to use their Native Installer directly from the website, and it seems that switching to the official installer is now our best line of defence. Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts AIAnthropicArtificial IntelligenceClaudeClaude AILeakSource Code Leave a Reply Cancel reply View Comments (0) Related Posts Security Privacy Court Orders DreamHost to handover data on anti-Trump site About a week ago, it was reported that the Department of Justice (DOJ) is demanding IP addresses of approximately… byWaqas Security Malware Prowli malware takes over 40,000 devices worldwide for Monero mining According to a newly released report, a malicious crypto-mining and traffic monetization malware campaign is underway. The report,… byWaqas Security Russia Hackers Abusing BRc4 Red Team Penetration Tool in Recent Attacks Palo Alto Networks’ Unit 42 security researchers have discovered that Russian state-sponsored hackers are abusing the latest Brute Ratel C4… byDeeba Ahmed Security Researcher retrieves $300,000 worth of Bitcoin from an encrypted Zip file An investor had locked $300k worth of Bitcoin in an encrypted Zip file and forgot its password. byWaqas","https:\u002F\u002Fhackread.com\u002Fanthropic-leaks-claude-ai-code-blunder\u002F",null,"2026-04-01T15:13:54+00:00","2026-04-01T16:00:26.806728+00:00",8,[],"26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":18,"icon":13,"name":20,"slug":21},"Supply Chain","supply-chain",[23,28,33],{"category":24},{"id":25,"icon":13,"name":26,"slug":27},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":29},{"id":30,"icon":13,"name":31,"slug":32},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":34},{"id":35,"icon":13,"name":36,"slug":37},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",[39],{"type":40,"value":41,"context":42},"malware","Trojan","Distributed via npm between 00:21–03:20 UTC on March 31, 2026, concurrent with source code leak",[]]