Anthropic can’t seem to catch a break. TNS contributor Meredith Shubel examines a rough stretch for the AI company, which began with an accidental leak of its new model, Mythos, and only got worse from there.
Security researcher Chaofan Shou discovered that Anthropic had shipped Claude Code version 2.1.88 with a 59.8MB source map file attached to the npm package — effectively exposing its full codebase. When Anthropic invoked U.S. digital copyright law to get the leaked code removed from GitHub, the takedown accidentally nuked upwards of 8,000 repositories. (An Anthropic spokesperson said the sweep “reached more repositories than intended.”) The company has since retracted the broader takedown notice, but the damage to its reputation compounds an already messy week.
The episode raises uncomfortable questions about internal security practices at one of the leading AI companies — and whether more surprises are waiting around the corner. There’s no resealing an opened can of worms, as Shubel writes, “and there’s no telling what new security risks lie ahead.”
Go deeper: Anthropic’s rough week: leaked models, exposed source code, and a botched GitHub takedown
More interesting reads for your Friday:
◌ “I started to lose my ability to code”: Developers grapple with the real cost of AI programming tools
◌ I replaced vector DBs with Google’s Memory Agent Pattern for my notes in Obsidian
◌ I, too, would sell to OpenAI