Claude Leak Timeline
A chronological breakdown of the events surrounding the Claude Code source code exposure and the subsequent community response.
Mythos Cybersecurity Preview Launched
Anthropic officially announced a limited preview of Claude Mythos for defensive cybersecurity use cases, granting access to a select group of enterprise partners including Amazon and Microsoft.
The earlier data cache leak had already flagged Mythos as 'currently far ahead of any other AI model in cyber capabilities' and posing 'unprecedented cybersecurity risks.' This controlled preview — two weeks after the leak — marks Mythos's first formal public appearance. Source: TechCrunch (2026-04-07)
Official Response & Advisory
Anthropic confirmed the leak was due to human error and issued a remediation advisory for all Claude Code users.
Security Advice: Users should immediately rotate Anthropic API keys, uninstall v2.1.88, and update to the latest patched version to mitigate potential credential exposure.
Community Deep Dive
Developers on Reddit and X deconstructed the leaked code, uncovering hidden features and future model plans.
Deep Analysis: Revealed the 'KAIROS' asynchronous agent loop, internal model codenames like 'Capybara' (Claude 4.6), and 44 hidden features including 'Undercover Mode'.
Source Code Discovery
Security researcher Chaofan Shou (@Fried_rice) identified that the exposed maps contained references to the full TypeScript source code on an Anthropic cloud bucket.
Impact Scope: The leak exposed ~512,000 lines of code across 1,900 files, revealing core Agent logic, chain-of-thought prompts, and internal API structures.
Release Packaging Error
Anthropic published version 2.1.88 of @anthropic-ai/claude-code. A misconfigured .npmignore led to the accidental inclusion of a 59.8 MB source map file.
Technical Detail: The root cause was a conflict between the build tool (Bun) and .npmignore, which leaked a map file that linked directly to raw, unminified TypeScript source code.
Mythos Model Existence Exposed
Anthropic accidentally exposed draft blog posts and internal documents via an unsecured public data cache, revealing the existence of an unreleased AI model codenamed 'Claude Mythos' — before any official announcement.
Leaked materials showed Mythos achieves dramatically higher scores on coding, academic reasoning, and cybersecurity benchmarks than Claude Opus 4.6. Anthropic described it as 'a step change' and 'the most capable we've built to date.' Fortune reported the leak; the cache was taken offline the same day. Source: Fortune (2026-03-26)