
Anthropic has come under fresh scrutiny after a major code leak revealed internal details of its AI tool, Claude Code.
Just days earlier, Fortune reported that the company had mistakenly exposed around 3,000 files, including a draft post about an upcoming model. Known internally as "Mythos' or "Capybara," the model was said to be highly advanced and potentially risky from a cybersecurity standpoint.
The latest incident exposed nearly 500,000 lines of code across 1,900 files. Anthropic confirmed that "some internal source code" became public during a "Claude Code release," adding that no sensitive data was involved and the issue was due to human error.
Even though the core AI model was not leaked, experts say the exposed code could still reveal important internal workings. A cybersecurity expert told Fortune that developers may now be able to extract useful insights from the codebase.
While the main AI model remains secure, experts warn the leaked code could expose important internal systems. A cybersecurity expert told Fortune that it may help developers understand internal processes.
Used by large companies, Claude Code depends not only on AI models but also on a system that guides how the AI works. This "harness" controls behaviour and connects the AI to tools, and it is this system that has been leaked.
Experts warn the leak could allow rivals to study the system and create competing tools. It may also lead to open-source versions based on the exposed code.
Researcher Roy Paz said the leak also hints at a new advanced model, possibly more powerful than current versions. Anthropic currently offers models like Opus, Sonnet and Haiku, but the new system may go beyond them.
According to Roy Paz, the leak suggests that Anthropic is working on a more advanced model, likely stronger than its current offerings such as Opus, Sonnet and Haiku.
According to reports, the leak happened when incorrect files were uploaded to NPM. "a single misconfiguration or misclick suddenly exposed the full source code," said Paz.
He also warned that such leaks could reveal internal systems and APIs, making it easier for attackers to understand and exploit the technology.
This is not the first such incident. In February 2025, Anthropic accidentally exposed Claude Code's source code in a similar error, raising concerns about its safeguards.
The incident has caught the internet's attention, with users sharing strong reactions.
One user said, "Was it purposeful to leave the 3000 documents buried where someone would find them?"
Another wrote, "The 'just sitting open' part hits different when you realise most breaches aren't sophisticated attacks, they're someone forgetting to flip a private toggle."