Read

4 MIN

Date

Category

Anthropic Had Two Massive Leaks in One Week. Here's What They Reveal About the Future of AI.

In a single week, the company that positions itself as the responsible AI lab had two accidental leaks: its entire Claude Code source, and the spec for a model it calls the most powerful it has ever built. Both reveal exactly where frontier AI is heading, and how fast.

Champ Smith
Champ Smith

Champ Smith

Operator & AI Cystems Builder

I build the custom AI Cystems that run businesses for the operators who own them — leads routed, content shipped, calls handled. I work from a finca in Málaga, where the intelligence lives in the walls.

The Source Code Leak

On March 31, 2026, security researcher Chaofan Shou discovered something Anthropic probably hoped no one would find: the entire source code of Claude Code — their flagship AI coding tool — sitting in plain sight on the npm registry.

The cause? A source map file. When developers build JavaScript packages, their tools generate .map files that bridge minified production code back to the readable original source. Anthropic's build pipeline accidentally included this file in the published npm package. That single oversight exposed 1,900 TypeScript files and 512,000 lines of code to anyone who cared to look.

Within hours, the code was archived on GitHub, where it racked up over 1,100 stars and 1,900 forks. Developers and security researchers immediately started dissecting it.

The leaked codebase isn't a toy. It reveals Claude Code as a production-grade Cystem running on Bun (not Node.js), using React with Ink for terminal UI rendering, and packing roughly 40 built-in tools and 50 slash commands.

But the real story is what was hidden behind feature flags — unreleased capabilities that reveal where Anthropic is heading:

KAIROS ('Always-On Claude') — A persistent AI assistant mode that keeps working across sessions. It stores memory logs in a private directory, performs nightly 'dreaming' cycles to consolidate and organize context, and can proactively start tasks without being prompted. The code includes midnight boundary handling to prevent the dream process from breaking during date changes. This isn't a coding assistant. This is an always-on AI employee.

BUDDY — A Tamagotchi-style AI companion with 18 species (duck, dragon, axolotl, capybara, ghost), rarity tiers from common to 1% legendary, shiny variants, and five stats: Debugging, Patience, Chaos, Wisdom, and Snark. It was planned for an April 1-7 teaser rollout.

ULTRAPLAN — 30-minute remote planning sessions running in Anthropic's cloud.

Coordinator Mode — One Claude instance spawning and managing multiple worker agents in parallel.

Five days before the source code incident, Fortune broke a separate story that may have even larger implications.

On March 26, Fortune reporter Bea Nolan discovered that Anthropic had left nearly 3,000 unpublished assets — including a draft blog post announcing a new AI model — in an unsecured, publicly searchable data store. The leak was independently verified by Roy Paz (LayerX Security) and Alexandre Pauwels (University of Cambridge).

The draft describes a model called Claude Mythos (also referred to as 'Capybara' — a new tier above Opus). Anthropic's own words in the leaked draft:

'By far the most powerful AI model we've ever developed.' 'A step change in AI performance.' 'Currently far ahead of any other AI model in cyber capabilities.' 'Presages an upcoming wave of models that can exploit vulnerabilities in ways that far outpace the efforts of defenders.'

Anthropic confirmed the model exists, calling it 'the most capable we've built to date.'

Anthropic's own leaked draft says Mythos poses 'unprecedented cybersecurity risks.' The model can find vulnerabilities in software that humans can't find. Their planned release strategy focuses on giving cyber defenders a head start.

The market reacted immediately. The day after the Fortune story: the iShares Expanded Tech-Software Sector ETF (IGV) dropped nearly 3%. Cybersecurity stocks Palo Alto Networks, CrowdStrike, and Fortinet fell 4-6%. Bitcoin dropped from $70,000 to $66,000.

The logic: if AI can find and exploit software vulnerabilities faster than humans can patch them, every company running software is at risk. And that's every company.

Two accidental leaks in one week from the company that positions itself as the responsible AI lab. Three things to watch:

1. KAIROS changes the game. An always-on AI that persists across sessions, dreams to consolidate memory, and proactively starts tasks isn't a coding helper. It's an autonomous employee. When this ships, every business will need to decide how it fits into their operations.

2. The Capybara tier means the race is escalating. A model that sits above Opus, with cybersecurity capabilities that 'far outpace defenders,' signals that frontier AI capabilities are accelerating faster than the safety infrastructure around them.

3. AI building AI is creating new attack surfaces. The npm source map leak may have been caused by AI-generated code in the build pipeline. If AI tools are writing the code that builds AI tools, quality assurance needs to evolve at the same pace. The irony of Claude Code leaking its own source code — twice in a year — makes this painfully clear.

The safety company keeps accidentally proving why safety is so hard.

What the Leaked Code Reveals

The Bigger Leak: Claude Mythos

The Cybersecurity Dimension

Read

4 MIN

Date

Category

I share ideas, lessons, and practical insights from my work.

Related
Articles.

Jun 29, 2026

Essays

How You Raise a Mind

Everyone names benevolence as the only real safeguard for AI, then admits nobody is building it. So let's build it. The moment you try, it stops being philosophy and becomes architecture, because you cannot legislate character into a mind. The question was never how to cage it, but how to raise it.

Jun 26, 2026

Essays

A Different Narrative

The most credible pessimist in finance calls AI the biggest investment bubble in history, and relaying the godfather of AI, he lands on a single word as the only way through: benevolence. Everyone names the answer. Almost no one is building it. That's the conversation I want to have.

Jun 24, 2026

Signal

The Machines Started Paying Each Other

For the entire history of the internet, there was a human at the end of every transaction. Someone clicked buy. That assumption is quietly breaking: machines have started paying each other, in stablecoins, with no checkout page. The question every business now has to answer is whether an agent can find you, and pay you.

Jun 23, 2026

Signal

Japan Didn't Build a Frontier Model. It Built a Conductor — And That's the Bigger Story.

The headlines said Japan built a frontier model to rival Anthropic's best. It didn't. Sakana built a conductor, a small model that reads your task, routes it to the strongest existing models, and verifies the result. There are two ways to win with AI, and Fugu just proved the cheaper one works.

Jun 29, 2026

Essays

How You Raise a Mind

Everyone names benevolence as the only real safeguard for AI, then admits nobody is building it. So let's build it. The moment you try, it stops being philosophy and becomes architecture, because you cannot legislate character into a mind. The question was never how to cage it, but how to raise it.

Jun 26, 2026

Essays

A Different Narrative

The most credible pessimist in finance calls AI the biggest investment bubble in history, and relaying the godfather of AI, he lands on a single word as the only way through: benevolence. Everyone names the answer. Almost no one is building it. That's the conversation I want to have.

Jun 29, 2026

Essays

How You Raise a Mind

Everyone names benevolence as the only real safeguard for AI, then admits nobody is building it. So let's build it. The moment you try, it stops being philosophy and becomes architecture, because you cannot legislate character into a mind. The question was never how to cage it, but how to raise it.

Jun 26, 2026

Essays

A Different Narrative

The most credible pessimist in finance calls AI the biggest investment bubble in history, and relaying the godfather of AI, he lands on a single word as the only way through: benevolence. Everyone names the answer. Almost no one is building it. That's the conversation I want to have.

Create a free website with Framer, the website builder loved by startups, designers and agencies.