This video from Silicon Money details a massive security blunder by Anthropic where the entire proprietary source code for Claude Code was accidentally leaked.
The Incident: A 512,000-Line Mistake
During a routine software update to npm at 4:00 AM, Anthropic included a 60-megabyte source map file in the production build [
What is a Source Map? It is essentially a "cheat sheet" used for debugging that maps minified, unreadable production code back to its original human-readable source [
].00:46 The Leak: This file contained over 512,000 lines of Anthropic’s proprietary code [
].00:07 The Speed of the Internet: A researcher discovered the file within 23 minutes [
]. By the time Anthropic realized the error, the code had been forked over 41,000 times on GitHub [01:45 ].02:05
The "Claw Code" Clean-Room Rewrite
One of the most active Claude Code users, a developer known as Secret Jin, performed a "clean-room rewrite" of the leaked code [
He rewrote the entire architecture from JavaScript into Python in just 8 hours [
].02:55 Because it was an original rewrite and not a copy-paste, it qualifies as a new creative work, making it difficult for Anthropic to take down via DMCA [
].03:08 This project, named Claw Code, became one of the fastest-growing repositories in GitHub history [
].03:24
Unannounced Features Revealed
The leak exposed several "wild" features Anthropic has been working on behind the scenes:
Buddy: A virtual terminal pet (species include ducks, capybaras, and dragons) with an "AI-generated soul" [
].03:40 Chyros: An always-on background agent that uses "autodream" to consolidate project observations and convert notes into facts while the user is idle [
].04:13 Ultra Plan: A high-level reasoning mode that offloads complex tasks to a powerful cloud model for up to 30 minutes of "thinking" time [
].04:42 Coordinator Mode: A system where one Claude instance manages multiple worker agents in parallel [
].05:06
Wider Business & Political Context
The leak comes at a disastrous time for Anthropic, which is currently valued at $380 billion and planning an IPO [
National Security Tension: Anthropic recently fought a legal battle with the U.S. government after refusing to allow Claude to be used for autonomous weapons or mass surveillance [
]. This led the Pentagon to briefly label them a "supply chain risk" [06:46 ].07:18 Series of Failures: This is Anthropic's second major leak in five days, following a separate incident where internal files and a blog post about a new model called Mythos were left on a publicly accessible system [
].06:06
The video highlights the irony that Claude Code—a tool largely written by AI—was leaked because of a simple human configuration error that any junior engineer should have caught [
youtube.com/watch?si=F5vuoDN5NMTsFT5B&v=IIpBzGTY7QU&feature=youtu.be
No comments:
Post a Comment