Claude Leak Timeline

A chronological breakdown of the events surrounding the Claude Code source code exposure and the subsequent community response.

2026-04-07 (UTC)

Mythos Cybersecurity Preview Launched

CAPABILITY_DISCLOSURE

Anthropic officially announced a limited preview of Claude Mythos for defensive cybersecurity use cases, granting access to a select group of enterprise partners including Amazon and Microsoft.

The earlier data cache leak had already flagged Mythos as 'currently far ahead of any other AI model in cyber capabilities' and posing 'unprecedented cybersecurity risks.' This controlled preview — two weeks after the leak — marks Mythos's first formal public appearance. Source: TechCrunch (2026-04-07)

View SourceMythos Preview: Capability Overview
2026-03-31 20:45 UTC

Official Response & Advisory

SECURITY_ADVICE

Anthropic confirmed the leak was due to human error and issued a remediation advisory for all Claude Code users.

Security Advice: Users should immediately rotate Anthropic API keys, uninstall v2.1.88, and update to the latest patched version to mitigate potential credential exposure.

View Source
2026-03-31 15:00 UTC

Community Deep Dive

DEEP_ANALYSIS

Developers on Reddit and X deconstructed the leaked code, uncovering hidden features and future model plans.

Deep Analysis: Revealed the 'KAIROS' asynchronous agent loop, internal model codenames like 'Capybara' (Claude 4.6), and 44 hidden features including 'Undercover Mode'.

View Source
2026-03-31 12:15 UTC

Source Code Discovery

IMPACT_SCOPE

Security researcher Chaofan Shou (@Fried_rice) identified that the exposed maps contained references to the full TypeScript source code on an Anthropic cloud bucket.

Impact Scope: The leak exposed ~512,000 lines of code across 1,900 files, revealing core Agent logic, chain-of-thought prompts, and internal API structures.

View Source
2026-03-31 08:30 UTC

Release Packaging Error

TECHNICAL_DETAIL

Anthropic published version 2.1.88 of @anthropic-ai/claude-code. A misconfigured .npmignore led to the accidental inclusion of a 59.8 MB source map file.

Technical Detail: The root cause was a conflict between the build tool (Bun) and .npmignore, which leaked a map file that linked directly to raw, unminified TypeScript source code.

View Source
2026-03-26 (UTC)

Mythos Model Existence Exposed

DATA_EXPOSURE

Anthropic accidentally exposed draft blog posts and internal documents via an unsecured public data cache, revealing the existence of an unreleased AI model codenamed 'Claude Mythos' — before any official announcement.

Leaked materials showed Mythos achieves dramatically higher scores on coding, academic reasoning, and cybersecurity benchmarks than Claude Opus 4.6. Anthropic described it as 'a step change' and 'the most capable we've built to date.' Fortune reported the leak; the cache was taken offline the same day. Source: Fortune (2026-03-26)

View Source