Anthropic Leaks Claude Code CLI Source Code: 512,000 Lines Exposed, Crypto Community Raises Supply Chain Concerns

Anthropic Leaks Claude Code CLI Source Code: 512,000 Lines Exposed, Crypto Community Raises Supply Chain Concerns

N
News Editor 01
2026-07-08 20:50:12
Anthropic accidentally published the full source code of its Claude Code CLI tool via an npm package, exposing 512,000 lines of TypeScript including unreleased features like KAIROS and BUDDY. A blockchain security researcher first discovered the leak, sparking debate over AI tool supply chain security.
AnthropicClaude Codesource code leaksupply chain securitycrypto community

On July 8, 2026, artificial intelligence company Anthropic suffered a significant security incident: the entire source code of its Claude Code CLI tool was accidentally published through an npm package. The leak exposed approximately 512,000 lines of TypeScript code, including numerous unreleased features and internal architecture details, triggering widespread discussion in both the crypto and AI developer communities.

Root Cause: npm Source Map File Leak

Anthropic confirmed that the leak resulted from a human error in the release packaging process. Version 2.1.88 of the @anthropic-ai/claude-code package contained a 59.8MB JavaScript source map file that mapped minified production code back to the original TypeScript and directly pointed to a publicly accessible zip archive stored in Anthropic's Cloudflare R2 bucket. Anyone who discovered the file could download the full source code.

Chaofan Shou, an intern researcher at blockchain security firm Fuzzland, first disclosed the direct download link on social platform X. Within hours, multiple mirrored repositories appeared on GitHub, some accumulating tens of thousands of stars before Anthropic issued DMCA takedown requests. Community members have already begun extracting telemetry data, toggling hidden feature flags, and preparing clean reimplementations in Python and Rust to avoid copyright issues.

Unreleased Features Exposed: KAIROS, BUDDY, and Agent Swarms

The leaked source code revealed several experimental features not yet released to the public:

  • KAIROS: An always-on background daemon that monitors file changes, records events, and runs a memory consolidation process called 'dreaming' during idle time.
  • BUDDY: A terminal pet system with 18 species (including capybara), carrying stats like DEBUGGING, PATIENCE, and CHAOS.
  • COORDINATOR MODE: Allows a single agent to spawn and manage multiple parallel worker agents.
  • ULTRAPLAN: Enables 10- to 30-minute remote multi-agent planning sessions.

Additionally, the code shows Claude Code includes an 'Undercover mode' that instructs the AI to remove references to internal code names and project details from git commits and pull requests. The telemetry system scans prompts for vulgar words as frustration signals but does not record full conversations or user code.

Crypto Community Raises Supply Chain Attack Concerns

The timing of the incident coincides with another npm supply chain attack targeting the axios package, which occurred between 00:21 and 03:29 UTC on March 31. Developers who installed or updated Claude Code via npm during this window are advised to audit their dependencies and rotate credentials. Anthropic recommends using its native installer instead of npm going forward.

Blockchain security researchers warn that Anthropic's source code leak—given the company's role as a provider of AI code generation tools—could be leveraged for reverse engineering, building competitive tools, or implanting backdoors. Crypto projects heavily rely on AI to assist writing smart contracts, highlighting the fragility of supply chain security. Fuzzland emphasized that model weights and customer data remain unaffected, but the architectural details exposed will significantly lower the barrier for competitors to replicate the tool.

History Repeats: Second Similar Leak in 13 Months

Notably, this is the second time Anthropic has leaked code due to a source map file. A nearly identical leak occurred with an earlier version of Claude Code in February 2025. Just a week prior, on March 26, a misconfigured CMS at Anthropic exposed approximately 3,000 internal files containing details about the unreleased 'Claude Mythos' model. Three security incidents in less than a week raise serious questions about the company's release security practices.

As of press time, the leaked source code remains available in archived and mirrored form despite active DMCA enforcement. Anthropic has not released a broader root cause analysis beyond its statement to Venture Beat. While the company stressed that no user data or model weights were exposed, the crypto community has ignited debates about AI tool supply chain security, the balance between open source and proprietary code, and the risks of relying on third-party AI development tools. For Web3 developers dependent on AI, securing the development environment has become an urgent priority.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.