Anthropic Shipped 512,000 Lines of Source Code Inside a Claude Package by Mistake

Security researcher Chaofan Shou found ~2,000 source files hiding inside a Claude Code release package. It's the second accidental exposure Anthropic has confirmed in the same week.

Anthropic Shipped 512,000 Lines of Source Code Inside a Claude Package by Mistake
Photo by Solen Feyissa / Unsplash

Anthropic has had a rough week. In a span of days, the company that markets itself as the careful AI company managed to expose its own source code — twice, in two separate incidents.

The most recent: security researcher Chaofan Shou discovered that Anthropic accidentally bundled approximately 2,000 source code files and over 512,000 lines of code inside a Claude Code software package (v2.1.88). The company confirmed it and issued a statement calling it "a release packaging issue caused by human error, not a security breach." That distinction may be technically accurate, but it doesn't help the optics. Just days earlier, Fortune reported that nearly 3,000 internal Anthropic files had been made publicly accessible, including a draft blog post about an unannounced model.

The timing is notable. Claude Code — the command-line developer tool at the center of the packaging incident — is one of Anthropic's most competitive products right now, formidable enough that rivals have taken notice. Having your most watched product become the vehicle for a self-inflicted embarrassment is not a great week. The "careful AI company" positioning was always going to be tested. This is one of those tests.

Comments

Get tomorrow's roundup. Free.

One email each morning. Sneakers, sports, culture, tech.

Link copied