A single missing configuration in a release pipeline turned Anthropic’s Claude Code into an open book. On March 31, version 2.1.88 of the Claude Code CLI tool shipped via npm with a 59.8 MB source map file that was never supposed to leave the building, exposing approximately 513,000 lines of unobfuscated TypeScript source code across 1,906 internal files.
Within hours, the code was mirrored to GitHub. Forks multiplied. And opportunistic actors spun up fake repositories laced with malware, targeting developers who came looking for the leaked source. Anthropic’s attempt at damage control, filing DMCA takedown requests, ended up disrupting roughly 8,100 GitHub repositories, many of which had nothing to do with the incident.
What actually happened
The exposure wasn’t a hack. Source map files are debugging tools that map compiled code back to its original source. They’re useful during development. They’re catastrophic when shipped to production.
Anthropic confirmed as much in its response, stating that the mishap was “a release packaging issue caused by human error, not a security breach.” The company emphasized that no sensitive customer data or credentials were compromised in the exposure.
The 11,241 messages referenced in early discussions around the incident appear to be connected to this broader software exposure. While some reports initially suggested user chat messages were leaked, Anthropic has pushed back on that characterization, noting that the figure is not substantiated by concrete evidence of customer conversation exposure. The number may instead reflect artifacts within the leaked codebase itself.
The DMCA mess made it worse
Anthropic’s DMCA response created its own secondary disaster. The roughly 8,100 repositories disrupted by takedown requests included projects with no connection to the leaked code.
The malware angle adds a more sinister dimension. Bad actors quickly created fake GitHub repositories mimicking the leaked Claude Code source, hoping developers would clone them without scrutiny.
Why crypto developers should care
The malware campaigns are the most immediate concern. Crypto developers who cloned what they thought was legitimate Claude Code source from GitHub may have introduced compromised dependencies into their own projects.
Anthropic also has direct historical ties to the crypto sector. The company received funding from FTX in 2022. The follow-on issues haven’t helped either. Reports of quality degradation in Claude Code responses surfaced in April 2026, and rumors about unreleased models like “Claude Mythos” have added noise to an already chaotic situation.
Crypto builders using AI-powered development tools should audit their dependency chains immediately, verify the provenance of any recently cloned repositories, and watch for indicators of compromise in their build environments.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
20









English (US) ·