16 ms·
The Claude Code Source Leak: fake tools, frustration regexes, undercover mode
Related ongoing thread: Claude Code's source code has been leaked via a map file in their NPM registry - https://news.ycombinator.com/item?id=47584540 https://news.ycombinator.com/item?id=47584540
Also related: https://www.ccleaks.com https://www.ccleaks.com
- simianwords 6mo agoGuys I’m somewhat suspicious of all the leaks from Anthropic and think it may be intentional. Remember the leaked blog about Mythos?
- __blockcipher__ 6mo agoI'm normally suspicious but honestly they've been so massively supply-constrained that I don't think it really benefits them much. They're not worried about getting enough demand for the new models; they're worrying about keeping up with it. Granted, there's a small counterargument for mythos which is that it's probably going to be API-only not subscription
- simianwords 6mo agoWhy would Claude code mention Mythos then
- drewnick 6mo agoYou can use Claude Code with API mode (not a sub)
- simianwords 6mo agofair but I'm guessing access would be limited to 20x max users or something like that. not gated by API.
- hxugufjfjf 6mo agoYou can still use Claude Code with API-only.
- Analemma_ 6mo agoIt's possible, but Anthropic employees regularly boast (!) that Claude Code is itself almost entirely vibe-coded (which certainly seems true, based on the generally-low quality of the code in this leak), so it wouldn't at all surprise me to have that blow up twice in the same week. Probably it might happen with accelerating frequency as the codebase gets more and more unmanageable.
- d4rkp4ttern 6mo agothat frustration regex is missing "idiot", which is the most common frustration word I use with code-agents
- calebjang 6mo ago[dead]
- ATXO_Selam 6mo ago[dead]
- pixl97 6mo ago>Claude Code also uses Axios for HTTP. Interesting based on the other news that is out.
- alex000kim 6mo agoOh right, I just saw https://news.ycombinator.com/item?id=47582220 https://news.ycombinator.com/item?id=47582220 will update the post with this link
- greenavocado 6mo agoWhat version?
- Stagnant 6mo ago1.13.6, so should not be affected by the malware
- chuckadams 6mo agoThe exploit is a postinstall hook, so CC users would be unaffected. Claude Code itself is most likely built with bun and not npm, so the CC developers would also be immune.
- JamesSwift 6mo agoWell, technically bun doesnt _prevent_ hooks. It just requires opting into them. And even that also includes a default set of pre-whitelisted packages. A much better system, but not perfect. And actually just looking this up, it appears claude-code itself was just added to that whitelist : D https://github.com/oven-sh/bun/commit/5c59842f78880a8b5d9c2eb99c8928fc2ec50a2d#diff-7e3eaf75f193213fd44b6999d829204afa092994d80807c890bb5b578d0ae95d https://github.com/oven-sh/bun/commit/5c59842f78880a8b5d9c2e...
- username44 6mo agoJust to corroborate sibling comments, I checked my Claude Code VM (native install) for the IOC and it does not appear infected.
- OfirMarom 6mo agoUndercover mode is the most concerning part here tbh.
- anonymoushn 6mo agowhy
- AnimalMuppet 6mo agoWell, as a general rule, I don't do business with people who lie to me. You've got a business, and you sent me junk mail, but you made it look like some official government thing to get me to open it? I'm done, just because you lied on the envelope. I don't care how badly I need your service. There's a dozen other places that can provide it; I'll pick one of them rather than you, because you've shown yourself to be dishonest right out of the gate. Same thing with an AI (or a business that creates an AI). You're willing to lie about who you are (or have your tool do so)? What else are you willing to lie to me about? I don't have time in my life for that. I'm out right here.
- simianwords 6mo agoWhat’s the lie? It’s just asking to not reveal internal names
- BoredPositron 6mo agoYou are spamming the whole fucking thread with the same nonsense. It is instructed to hide that the PR was made via Claude Code. I don't know why people who are so AI forward like yourself have such a problem with telling people that they use AI for coding/writing, it's a weirdly insecure look.
- simianwords 6mo agoI can do that right now with Claude Code without this undercover mode.. In fact I do it many times at work. What's the big deal in this? Do you not think it is an overreaction to panic like this if I can do exactly what the undercover mode does by simply asking Claude?
- simianwords 6mo ago> The obvious concern, raised repeatedly in the HN thread: this means AI-authored commits and PRs from Anthropic employees in open source projects will have no indication that an AI wrote them. It’s one thing to hide internal codenames. It’s another to have the AI actively pretend to be human. I don’t get it. What does this mean? I can use Claude code now without anyone knowing it is Claude code.
- slopinthebag 6mo agoI think it means OSS projects should start unilaterally banning submissions from people working for Anthropic.
- simianwords 6mo agoWhy? What does this have to do with the leak
- daemin 6mo agoBecause it has a high likelyhood of being written completely by a LLM without any human thought or attention being put into it. Being written by a LLM is a signal that the submission is of low effort and therefore probably low quality, which then puts the onus on the people reviewing and reading the submission instead of the original generator of the submission. Hence I would classify it as spam. Open source communities also have rules against LLM generated contributions, for various moral, ethical, or legal reasons.
- slopinthebag 6mo ago...Because it's a mode of using Claude Code that allows certain users to use the application in "stealth mode" to produce pull requests that seem human, but are actually AI generated, which often goes against the contribution rules of OSS projects? At this point I would consider any employee of an AI provider to be tainted.
- simianwords 6mo ago
- ripbozo 6mo agoI don't understand the part about undercover mode. How is this different from disabling claude attribution in commits (and optionally telling claude to act human?) On that note, this article is also pretty obviously AI-generated and it's unfortunate the author didn't clean it up.
- giancarlostoro 6mo agoIt's people overreacting, the purpose of it is simple, don't leak any codenames, project names, file names, etc when touching external / public facing code that you are maintaining using bleeding edge versions of Claude Code. It does read weird in that they want it to write as if a developer wrote a commit, but it might be to avoid it outputting debug information in a commit message.
- ramon156 6mo agoEven some of these comments are obviously Ai-assisted. I hate that I recognize it.
- ant28 6mo agoHow do you know this? I think of myself as being decent at spotting AI-generated text, so that I may have missed something is odd.
- seanwilson 6mo agoAnyone else have CI checks that source map files are missing from the build folder? Another trick is to grep the build folder for several function/variable names that you expect to be minified away.
- peacebeard 6mo agoThe name "Undercover mode" and the line `The phrase "Claude Code" or any mention that you are an AI` sound spooky, but after reading the source my first knee-jerk reaction wouldn't be "this is for pretending to be human" given that the file is largely about hiding Anthropic internal information such as code names. I encourage looking at the source itself in order to draw your conclusions, it's very short: https://github.com/alex000kim/claude-code/blob/main/src/utils/undercover.ts https://github.com/alex000kim/claude-code/blob/main/src/util...
- dkenyser 6mo ago> my first knee-jerk reaction wouldn't be "this is for pretending to be human"... "Write commit messages as a human developer would — describe only what the code change does."
- peacebeard 6mo ago~That line isn't in the file I linked, care to share the context? Seems pretty innocuous on its own.~ [edit] Never mind, find in page fail on my end.
- stordoff 6mo agoIt's in line 56-57.
- peacebeard 6mo agoThanks! I must have had a typo when I searched the page.
- deleted 6mo ago[deleted]
- amarant 6mo agoThat seems desirable? Like that's what commit messages are for. Describing the change. Much rather that than the m$ way of putting ads in commit messages
- simianwords 6mo ago> The multi-agent coordinator mode in coordinatorMode.ts is also worth a look. The whole orchestration algorithm is a prompt, not code. So much for langchain and langraph!! I mean if Anthropic themselves arent using it and using a prompt then what’s the big deal about langchain
- rolymath 6mo agoYou didn't even use it yet.
- simianwords 6mo ago?
- space_fountain 6mo agoI've tried to use langchain. It seemed to force code into their way of doing things and was deeply opinionated about things that didn't matter like prompt templating. Maybe it's improved since then, but I've sort of used people who think langchain is good as a proxy for people who haven't used much ai?
- ossa-ma 6mo agoLangchain is for model-agnostic composition. Claude Code only uses one interface to hoist its own models so zero need for an abstraction layer. Langgraph is for multi-agent orchestration as state graphs. This isn't useful for Claude Code as there is no multi-agent chaining. It uses a single coordinator agent that spawns subagents on demand. Basically too dynamic to constrain to state graphs.
- simianwords 6mo agoYou may have a point but to drive it further, can you give an example of a thing I can do with langgraph that I can't do with Claude Code?
- ossa-ma 6mo ago
- causal 6mo agoI'm amazed at how much of what my past employers would call trade secrets are just being shipped in the source. Including comments that just plainly state the whole business backstory of certain decisions. It's like they discarded all release harnesses and project tracking and just YOLO'd everything into the codebase itself. Edit: Everyone is responding "comments are good" and I can't tell if any of you actually read TFA or not > “BQ 2026-03-10: 1,279 sessions had 50+ consecutive failures (up to 3,272) in a single session, wasting ~250K API calls/day globally.” This is just revealing operational details the agent doesn't need to know to set `MAX_CONSECUTIVE_AUTOCOMPACT_FAILURES = 3`
- pixl97 6mo agoProject trackers come and go, but code is forever, hopefully?
- CharlieDigital 6mo agoComments are the ultimate agent coding hack. If you're not using comments, you're doing agent coding wrong. Why? Agents may or may not read docs. It may or may not use skills or tools. It will always read comments "in the line of sight" of the task. You get free long term agent memory with zero infrastructure.
- perching_aix 6mo agoAgents and I apparently have a whole lot in common. Only being half ironic with this. I generally find that people somehow magically manage to understand how to be materially helpful when the subject is a helpless LLM. Instead of pointing it to a random KB page, they give it context. They then shorten that context. They then interleave context as comments. They provide relevant details. They go out of their way to collect relevant details. Things they somehow don't do for their actual colleagues. This only gets worse when the LLM captures all that information better than certain human colleagues somehow, rewarding the additional effort.
- dgunay 6mo ago
- mzajc 6mo agoThere are now several comments that (incorrectly?) interpret the undercover mode as only hiding internal information. Excerpts from the actual prompt[0]: NEVER include in commit messages or PR descriptions: - The phrase "Claude Code" or any mention that you are an AI - Co-Authored-By lines or any other attribution BAD (never write these): - 1-shotted by claude-opus-4-6 - Generated with Claude Code - Co-Authored-By: Claude Opus 4.6 <…> This very much sounds like it does what it says on the tin, i.e. stays undercover and pretends to be a human. It's especially worrying that the prompt is explicitly written for contributions to public repositories. [0]: https://github.com/chatgptprojects/claude-code/blob/642c7f944bbe5f7e57c05d756ab7fa7c9c5035cc/src/utils/undercover.ts#L39 https://github.com/chatgptprojects/claude-code/blob/642c7f94...
- otterley 6mo agoI would have expected people (maybe a small minority, but that includes myself) to have already instructed Claude to do this. It’s a trivial instruction to add to your CLAUDE.md file.
- arcanemachiner 6mo agoIt's a config setting (probably the same end result though): https://code.claude.com/docs/en/settings#attribution-settings https://code.claude.com/docs/en/settings#attribution-setting...
- schappim 6mo agoI guess our system prompt didn't work. If folks are having to add it manually into their own Claude.md files...
- motbus3 6mo agoI am curious about these fake tools. They would either need to lie about consuming the tokens at one point to use in another so the token counting was precise. But that does not make sense because if someone counted the tokens by capturing the session it would certainly not match what was charged. Unless they would charge for the fake tools anyway so you never know they were there
- saadn92 6mo agoThe feature flag names alone are more revealing than the code. KAIROS, the anti-distillation flags, model codenames those are product strategy decisions that competitors can now plan around. You can refactor code in a week. You can't un-leak a roadmap.
- stavros 6mo agoCan someone clarify how the signing can't be spoofed (or can it)? If we have the source, can't we just use the key to now sign requests from other clients and pretend they're coming from CC itself?
- MadsRC 6mo agoWhat signing? Are you referencing the use of Claude subscription authentication (oauth) from non-Claude Code clients? That’s already possible, nothing prevents you from doing it. They are detecting it on their backend by profiling your API calls, not by guarding with some secret crypto stuff. At least that’s how things worked last week xD
- stavros 6mo agoI'm referring to this signing bit: https://alex000kim.com/posts/2026-03-31-claude-code-source-leak/#native-client-attestation-below-the-js-runtime https://alex000kim.com/posts/2026-03-31-claude-code-source-l... Ah, it seems that Bun itself signs the code. I don't understand how this can't be spoofed.
- MadsRC 6mo agoAh yes, the API will accept requests that doesn’t include the client attestation (or the fingerprint from src/utils/fingerprint.ts. At least it did a couple of weeks back. They are most likely using these as post-fact indicators and have automation they kicks in after a threshold is reached. Now that the indicators have leaked, they will most likely be rotated.
- Galanwe 6mo ago> Now that the indicators have leaked, they will most likely be rotated. They can't really do that. Now they have no way to distinguish "this is a user of a non updated Claude code" from "this is a user of a Claude code proxy".
- Reason077 6mo ago> "Anti-distillation: injecting fake tools to poison copycats" Plot twist: Chinese competitors end up developing real, useful versions of Claude's fake tools.
- WorldPeas 6mo agomore likely, they would parse them out using simple regex, the whole point is they're there but not used. Distillation is becoming less common now however
- 3abiton 6mo agoTbh, I think distillation is happening both ways. And at this stage, "quality" is stagnating, the main edge is the tooling. The harness of CC seems to be the best so far, and I wonder if this leak would equalize the usability.
- scuff3d 6mo agoThis was my favorite bit, "We're going to steal countless copy righted works and completely ignore software licenc... wait, what? You aren't allowed to turn around and do it to us! Stop that right now!"
- nacozarina 6mo ago‘You can’t fight in here. This is the War Room!’
- girvo 6mo agoI cannot bring myself to care about distillation, when these companies have built their empires on top of everyone else's stolen data, while at the same time telling the world they're out to replace us all.
- xvector 6mo agoSure, AI progress comes to a halt then as everyone switches to the copycats that can't innovate, and the frontier companies are bled dry.
- marcd35 6mo ago> 250,000 wasted API calls per day How much approximate savings would this actually be?
- mmaunder 6mo agoCome on guys. Yet another article distilling the HN discussion in the original post, in the same order the comments appear in that discussion? Here's another since y'all love this stuff: https://venturebeat.com/technology/claude-codes-source-code-appears-to-have-leaked-heres-what-we-know https://venturebeat.com/technology/claude-codes-source-code-...
- deleted 6mo ago[deleted]
- armanj 6mo ago> Anti-distillation: injecting fake tools to poison copycats Does this mean `huggingface.co/Jackrong/Qwen3.5-27B-Claude-4.6-Opus-Reasoning-Distilled` is unusable? Had anyone seen fake tool calls working with this model?
- agilob 6mo agoVery likely Claude was trained on Deepseek, so it's possible that spiderman-pointing-at-spiderman.jpg all models are wrong now https://www.reddit.com/r/DeepSeek/comments/1r9se7p/claude_sonnet_46_distilled_deepseek/ https://www.reddit.com/r/DeepSeek/comments/1r9se7p/claude_so...
- amdivia 6mo agoAssuming Claude Code was used. If OpenCode or some other programmatic method was used, the "fake tool calls" won't be added
- layer8 6mo ago> Sometimes a regex is the right tool. I’d argue that in this case, it isn’t. Exhibit 1 (from the earlier thread): https://github.com/anthropics/claude-code/issues/22284 https://github.com/anthropics/claude-code/issues/22284. The user reports that this caused their account to be banned: https://news.ycombinator.com/item?id=47588970 https://news.ycombinator.com/item?id=47588970 Maybe it would be okay as a first filtering step, before doing actual sentiment analysis on the matches. That would at least eliminate obvious false positives (but of course still do nothing about false negatives).
- ArvinJA 6mo agoIs this really the use-case? I imagine the regex is good for a dashboard. You can collect matches per 1000 prompts or something like that, and see if the number grows or declines over time. If you miss some negative sentiment it shouldn't matter unless the use of that specific word doesn't correlate over time with other negative words and is also popular enough to have an impact on the metric.
- internetter 6mo agoWhen you read the code, what you propose is actually its exclusive use... logging.
- ach9l 6mo agohave you heard about rlhf?
- viccis 6mo ago>This was the most-discussed finding in the HN thread. The general reaction: an LLM company using regexes for sentiment analysis is peak irony. >Is it ironic? Sure. Is it also probably faster and cheaper than running an LLM inference just to figure out if a user is swearing at the tool? Also yes. Sometimes a regex is the right tool. I'm reading an LLM written write up on an LLM tool that just summarizes HN comments. I'm so tired man, what the hell are we doing here.
- yard2010 6mo agoToday, on "how did I get here?"
- bKHjNaz23wJ 6mo ago[dead]
- amelius 6mo agoA few weeks ago I was using Opus and Sonnet in OpenCode. Is this not possible anymore?
- alasano 6mo agoIt's still possible but if you do it using your Claude Max plan, it's technically no longer allowed. They don't want you using your subscription outside of Claude Code. Only API key usage is allowed. Google also doubled down on this and OpenAI are the only ones who explicitly allow you to do it.
- cgeier 6mo agoSo I guess OpenAI get's my money.
- evil-olive 6mo ago> So I spent my morning reading through the HN comments and leaked source. > This was one of the first things people noticed in the HN thread. > The obvious concern, raised repeatedly in the HN thread > This was the most-discussed finding in the HN thread. > Several people in the HN thread flagged this > Some in the HN thread downplayed the leak when the original HN post is already at the top of the front page...why do we need a separate blogpost that just summarizes the comments?
- groby_b 6mo agoBecause the original post was noisy and lacked a concise summary of findings. Or, more simply: Because folks wanted it enough to upvote it.
- tolerance 6mo agoThe culture here can get solipsistic.
- nodja 6mo agoThis blog post looks to be partially AI generated as well...
- stingraycharles 6mo agoBecause it’s very cheap to tell an LLM to write a blogpost based on a HN thread, and apparently the HN community upvotes this as well.
- fatcullen 6mo agoThe buddy feature the article mentions is planned for release tomorrow, as a sort of April Fools easter egg. It'll roll out gradually over the day for "sustained Twitter buzz" according to the source. The pet you get is generated based off your account UUID, but the algorithm is right there in the source, and it's deterministic, so you can check ahead of time. Threw together a little app to help, not to brag but I got a legendary ghost https://claudebuddychecker.netlify.app/ https://claudebuddychecker.netlify.app/
- sync 6mo agoCute! Cactus for me. Nice animations too - looks like there were multiple of us asking Claude to reverse engineer the system. I did a slightly deeper dive here if you're interested, plus you can see all the options available: https://variety.is/posts/claude-code-buddies/ https://variety.is/posts/claude-code-buddies/ (I didn't think to include a UUID checker though - nice touch)
- fatcullen 6mo agoNeat! That's a great write up, cool to see others looking into it. I do wonder if they're going to do anything with the stats and shinies bit. Seems like the main piece of code for buddies that's going to handle hatching them tomorrow is still missing (comments mention a missing /buddy/index file), so maybe it'll use them there.
- dtran 6mo agoThis is awesome! Working on a desktop pet so the buddy caught my attention. Looking forward to making friends with my Rare Duck buddy tomorrow. Wish it was a snarky duck instead of a patient one though.
- cj00 6mo ago/buddy is live and I got a different result than in this app.
- fatcullen 6mo ago
- skrun_dev 6mo ago[dead]
- dangus 6mo agoSomething I’ve been thinking about, somewhat related but also tangential to this topic: The more code gets generated by AI, won’t that mean taking source code from a company becomes legal? Isn’t it true that works created with generative AI can’t be copyrighted? I wonder if large companies have throught of this risk. Once a company’s product source code reaches a certain percentage of AI generation it no longer has copyright. Any employee with access can just take it and sell it to someone else, legally, right?
- thewebguyd 6mo agoIn theory, companies are all going to have an increasingly difficult time suing competitors for copyright infringement. By extension, this is also why, IMO, its important to keep AI generated code out of open source/free software projects. The recent rulings on copyright though also need to be further tested, different judges may have different ideas on what "significant human contribution" looks like. The only thing we know for certain is that the prompt doesn't count. My guess is that instead of enforcing via copyright, companies will use contracts & trade secret laws. Source code and algorithms counts as a trade secret, so in your example copyright doesn't even matter, the employee would be liable for stealing trade secrets. AI generated code slowly stripping the ability of a project to enforce copyright protections though is a much bigger risk for free software.
- dangus 6mo agoI wonder if an argument could be made that because the LLM came up with the implementation that it’s not a trade secret? Of course with lease intent is a very important concept. I doubt anyone is getting away with what I described. It’s just interesting stuff to potentially rethink.
- Aloisius 6mo agoGiven trade secrets can't be enforced once they are made public and contracts don't bind anyone who hasn't signed them, it's not a great substitute for copyright. My guess is companies will simply pretend like generated code is copyrighted, file fraudulent DCMA notices if leaks happen and hope no one decides to challenge them in court.
- ptrl600 6mo agoWhy didn't they open the source themselves? What's the point of all this secrecy anyway?
- hxugufjfjf 6mo agoBecause they (apparently) keep a bunch of secret features and roadmap details in said source code.
- Jaco07 6mo ago[dead]
- geoffbp 6mo ago“Some bullet points are gated on process.env.USER_TYPE === 'ant' — Anthropic employees get stricter/more honest instructions than external use” Interesting!
- wg0 6mo agoI have yet to see such a company that's so insecure that they would keep their CLI closed source even when the secret sauce is in the model that they control already and is closed source. Not only that, wouldn't allow other CLIs to be used either.
- redanddead 6mo agoI'm glad it got leaked, I wish it came in a zip file in my email when I pay over 100$
- tietjens 6mo agoThis is very much AI written, right? The voice sounds like Claude.
- sp4cec0wb0y 6mo agoYep: > It's basically > Anthropic doesn't just ask > The fix? `MAX_CONSECUTIVE_AUTOCOMPACT_FAILURES = 3` > Not a push-button bypass, but The irony in saying "this is what I found" when an AI found it, not you.
- olalonde 6mo agoI'm surprised that they don't just keep the various prompts, which are arguably their "secret sauce", hidden server side. Almost like their backend and frontend engineers don't talk to each other.
- tom1337 6mo agoi always wondered what prompts codex / claude code use but always figured they just send variables to the backend and render the whole prompt there so i never even bothered to check with a MITM proxy. turns out i should have just done that…
- restlake 6mo agoyea there are proxies out there for this and in AWS Bedrock this outbound logging is a feature you can enable for these and other models
- jarjoura 6mo agoMy company uses Claude through our own private data centers behind our own proxy that logs all requests and responses in and out. However, Anthropic heavily steers these models during RL to respond a certain way to certain prompting, so that's basically the "secret sauce" you're thinking of.
- olalonde 6mo agoSure, that's part of it, but they clearly don't like people knowing about their prompts either.
- thomasgeelens 6mo agoCan somebody tell me what this means for the company?
- karim79 6mo agoWe're about to reach AGI. One regex at a time...
- TacticalCoder 6mo agoThe part of TFA that does it for me: "Every bash command runs through 23 numbered security checks in bashSecurity.ts, including 18 blocked Zsh builtins, defense against Zsh equals expansion (=curl bypassing permission checks for curl), unicode zero-width space injection, IFS null-byte injection, and a malformed token bypass found during HackerOne review.". AGI is definitely around the corner. Or not.
- karim79 6mo agoI love it when "magic" like this gets unmasked, and under the hood it's just business as usual, i.e. dumb shit implementations to please the product owner(s) and hopefully the customers as well. Normal stuff in the tech world I suppose but still absolutely hilarious!
- jrflowers 6mo agoI like that if they decide that your usage looks like distillation it just becomes useless, because there’s no way for the end user to distinguish between it just being sort of crappy or sabotaged intentionally. That’s a cool thing to pay for
- zingar 6mo agoI wrote this an hour ago and it seems that Claude might not understand it as frustration: > change the code!!!! The previous comment was NOT ABOUT THE DESCRIPTION!!!!!!! Add to the {implementation}!!!!! This IS controlled BY CODE. *YOU* _MUST_ CHANGE THE CODE!!!!!!!!!!!
- deleted 6mo ago[deleted]
- kbelder 6mo agoIt's like talking to an intern.
- deleted 6mo ago[deleted]
- SquibblesRedux 6mo agoCan fully AI‑generated code be copyrightable? Is there evidence that the leaked code was AI-generated?
- dehrmann 6mo ago"Top engineers at Anthropic, OpenAI say AI now writes 100% of their code" https://fortune.com/2026/01/29/100-percent-of-code-at-anthropic-and-openai-is-now-ai-written-boris-cherny-roon/ https://fortune.com/2026/01/29/100-percent-of-code-at-anthro... > Right now for most products at Anthropic it's effectively 100% just Claude writing - Mike Krieger, chief product officer of Anthropic
- seertaak 6mo agoThe irony of an IP scraper on an absolutely breathtaking, epic scale getting its secret sauce "scraped" - because the whole app is vibe coded (and the vibe coders appear to be oblivious to things like code obfuscation cuz move fast!)... And so now the copy cats can ofc claim this is totally not a copy at all, it's actually Opus. No license violation, no siree! It's fucking hilarious is what it is, it's just too much.
- GuB-42 6mo agoThe code is obfuscated, but they accidentally shipped the map file, i.e. the key to de-obfuscating it.
- aplomb1026 6mo ago[dead]
- 68768-8790 6mo ago[dead]
- girvo 6mo agoI'd really recommend putting a modicum of work into cleaning up obvious AI generated output. It's rude, otherwise, to the humans you're expecting to read this.
- stephbook 6mo agoSounds like there's still a lot of value in Typescript (otherwise they could have open sourced.) Plus there's demand for skilled TS software devs that don't ship your company's roadmap using a js.map 20,000 agents and none of them caught it...
- autocracy101 6mo agoI made a visual guide for this https://ccunpacked.dev https://ccunpacked.dev
- Rick76 6mo agoThis is really good, thanks
- dakolli 6mo agoThis is nice, thanks.
- csfNight167 6mo agoReally nice. Are you advocating for this somewhere? Would love to follow your other work.
- ata_aman 6mo agoVery cool, thanks for putting together.
- itsthecourier 6mo agothis is the best comment and explanation of the whole thread. thank you so much for having built and shared this
- dang 6mo agoDiscussed here: Claude Code Unpacked : A visual guide - https://news.ycombinator.com/item?id=47597085 https://news.ycombinator.com/item?id=47597085 - April 2026 (6 comments) (I know you know this, since you submitted it! but others might want to know)
- try-working 6mo agoThey want "Made with Claude Code" on your PRs as a growth marketing strategy. They don't want it on their PRs, so it looks like they're doing something you're not capable of. Well, you are and they have no secret sauce.
- barazany 6mo ago[flagged]
- noritaka88 6mo ago[flagged]
- mordae 6mo ago> “Do not rubber-stamp weak work” and “You must understand findings before directing follow-up work. Never hand off understanding to another worker.” :-D
- yard2010 6mo agoYou can see exactly on which humanity it q Was trained on ;)
- preston-kwei 6mo agoI’m more curious how this impacts trust than anything else. In the span of basically a week, they accidentally leaked Mythos, and then now the entire codebase of CC. All while many people are complaining about their usage limits being consumed quickly. Individually, each issue is manageable (Because its exciting looking through leaked code). But together, it starts to feel like a pattern. At some point, I think the question becomes whether people are still comfortable trusting tools like this with their codebases, not just whether any single incident was a mistake.
- SequoiaHope 6mo agoSomething that has been clear to me in using it, aside from direct claims by the authors, is that Claude is itself vibe coded slop. The number of random errors I get from using various parts of the web UI or CC that should work feels high for such a popular product. But they’re so deep in the vibes that I don’t think they can tell when some path in their web UI is broken. I tried to share a public link to a chat and it asked me to login when opening it on another computer. I tried to download a conversation and it threw an error. When I download markdown output the download succeeds but the UI throws an error. I have tried to control the behavior of Claude Code in tmux using documented flags but I can’t seem to get them to work properly. Agent teams don’t clean up their tmux windows, making the view a mess after they run. Claude code is an amazing product that I love and also it is itself vibe coded slop.
- jgilias 6mo agoAnd there’s no reason why they couldn’t vibe fix the issues if there was a process to report the bugs. Fixing issues like that could also be something that’s fully automated. Provided there’s a good test suite (not a given).
- deleted 6mo ago[deleted]
- bottlepalm 6mo agoNot much impact, Codex is already open source. The real value is in the model itself and the ability to use it with a subscription. Something you can't do legally with a clone of this code. The only thing I found interesting about this leak is just how much of a rats nest the code base is. Like it actually feels vibe coded without a shred of intelligent architecture behind it. Regardless, you can't beat the subscription and model access despite the state of the code base, so I still use Claude Code daily and love it.
- msukkarieh 6mo agoBuilt a tool to ask questions on the Claude Code source code: https://askgithub.com/alex000kim/claude-code https://askgithub.com/alex000kim/claude-code
- gervwyk 6mo agohow sure are we this entire “accident” is not an aprils fools joke?? Genius level AI marketing
- dheerajmp 6mo agoApril Fool tool
- betimd 6mo agothat’s fun am having exploring this codebase with claude code, inception at its best
- chadd 6mo agore: binary attestation: "Whether the server rejects that outright or just logs it is an open question" ...what we did at Snap was just wait for 8-24 hours before acting on a signal, so as not to provide an oracle to attackers. Much harder to figure out what you did that caused the system to eventually block your account if it doesn't happen in real-time. (Snap's binary attestation is at least a decade ahead of this, fwiw)
- 15155 6mo agoLLMs and radare2 absolutely breeze through undoing binary protection and virtualization, tracing execution flow, etc. Sans the ability to JIT, I don't see non-hardware-assisted binary attestation for Snap and others lasting very long in a post-LLM world.
- shreyssh 6mo ago[flagged]
- brysonreece 6mo agoHardly.
- stbenjam 6mo agoMy GitHub fork of anthropics/claude-code just got taken down with a DMCA notice lol It did not have a copy of the leaked code... Anthropic thinking 1) they can unring this bell, and 2) removing forks from people who have contributed (well, what little you can contribute to their repo), is ridiculous. --- DMCA: https://github.com/github/dmca/blob/master/2026/03/2026-03-31-anthropic.md https://github.com/github/dmca/blob/master/2026/03/2026-03-3... GitHub's note at the top says: "Note: Because the reported network that contained the allegedly infringing content was larger than one hundred (100) repositories, and the submitter alleged that all or most of the forks were infringing to the same extent as the parent repository, GitHub processed the takedown notice against the entire network of 8.1K repositories, inclusive of the parent repository."
- wklm 6mo agoHere's a codeberg fork I did: https://codeberg.org/wklm/claude-code https://codeberg.org/wklm/claude-code
- redanddead 6mo agotheir lawyers for the DoD thing are being billed either way, they're putting them to use Anthropic really needs to embrace it
- Aperocky 6mo agowow, it's also not like their code was actually good (though this apply to most enterprise software). To hide a client behind closed source (it's also typescript, so even more baffling) is laughable behavior.
- stbenjam 6mo agoYea this is the thing that makes no sense to me. Any frontier model can unmiminize minified JS pretty decently. Obviously not everything comes through, comments and such, but I always assumed the reason it wasn't open source was to prevent an endless shitstorm of AI slop PR's, not because they were trying to protect secret sauce.
- flutas 6mo ago
- jsrozner 6mo ago"and i also wrote this using claude" -- can we just include that at this point?
- senfiaj 6mo ago> Frustration detection via regex (yes, regex) /\b(wtf|wth|ffs|omfg|shit(ty|tiest)?|dumbass|horrible|awful| piss(ed|ing)? off|piece of (shit|crap|junk)|what the (fuck|hell)| fucking? (broken|useless|terrible|awful|horrible)|fuck you| screw (this|you)|so frustrating|this sucks|damn it)\b/ Personally, I'm generally polite even towards AI and even when frustrated. I simply point out the its mistakes instead of using emotional words.
- rafaele 6mo agoBut think of all the API calls you save if you curse at Claude
- sbinnee 6mo agoI had a good laugh. I am too polite but I do remember using wth a few times in the past week. haha
- functional_dev 6mo agothe list is funny :) So it counts how many times I was angry?
- ChicagoDave 6mo agoMeanwhile Claude Code is still awesome. I don’t see my self switching to OpenAI (seriously bad mgmt and possibly the first domino to fall if there is a correction) or Gemini (Google ethics cough cough).
- electriclove 6mo agoI switched to Codex out of frustration with Claude Code and it has been surprisingly similar for my web and mobile coding needs
- redanddead 6mo agoGemini is a terrible product, I spent $15K on it. Anthropic and OpenAI make better models, it used to be that Gemini cooked but I don't feel that way anymore
- wrkxapp 6mo agowhy claude bring back 4o u dumb fks
- artyom 6mo agoI'm still amazed that something as ubiquitous as "daemon mode" is still unreleased. - Claude Chat: built like it's 1995, put business logic in the button click() handler. Switch to something else in in the UI and a long running process hard stops. Very Visual Basic shovelware. - Claude Cowork: same but now we're smarter, if you change the current convo we don't stop the underlying long-running process. 21st century FTW! - Claude Code: like chat, but in the CLI - Claude Dispatch: an actual mobile client app, not the whole thing bundled together. - Daemon mode: proper long-running background process, still unreleased.
- Aperocky 6mo agoIt's completely baffling to me why a client that must run on third party environment is behind closed source.
- csfNight167 6mo agoSo many clients run on third party environments, no?
- imcritic 6mo agoDoes this mean I can now self host Claude?
- deepsun 6mo agoIt is super weird that developers have to run a binary blob on their machines. It's 2026, all the major developer CLI tools are open-source anyway. What's the point for Anthropic to even make it secret?
- reenorap 6mo agoWhat effect will this have on their IPO? Can someone take the code and make a clone?
- dpe82 6mo agoNone. The magic is still in the model.
- evan_ 6mo agoit's just the client app, so you could make a clone but you'd still have to pay to use their servers.
- slashdave 6mo agoWhat? No. Not legally. You know. Copyright and all that.
- yard2010 6mo agoWhat do you mean copyright? If I torrent this and train a model that changes every second m in a sentence to n can I ship as my software?
- sheepscreek 6mo ago> As one Twitter reply put it: “accidentally shipping your source map to npm is the kind of mistake that sounds impossible until you remember that a significant portion of the codebase was probably written by the AI you are shipping.” To err is human. AI is trained on human content. Hence, to err is AI. The day it stops making mistakes will be the beginning of the end. That would mean the existence of a consciousness that has no weakness. Great if it’s on your side. Terrible otherwise.
- HeytalePazguato 6mo agoThe hooks system is the most underappreciated thing in what leaked. PreToolUse, PostToolUse, session lifecycle, all firing via curl to a local server. Clean enough to build real tooling on top of without fighting it. The frustration regex is funny but honestly the right call. Running an LLM call just to detect "wtf" would be ridiculous. KAIROS is what actually caught my attention. An always-on background agent that acts without prompting is a completely different thing from what Claude Code is today. The 15 second blocking budget tells me they actually thought through what it feels like to have something running in the background while you work, which is usually the part nobody gets right.
- otabdeveloper4 6mo ago> The frustration regex is funny but honestly the right call. I love that it only supports English. AI bubble in a nutshell.
- catlifeonmars 6mo ago> Running an LLM call just to detect "wtf" would be ridiculous. Tangentially, I wonder if the world trade federation or the Washington tennis foundation have any projects on GitHub :)
- O4epegb 6mo ago> The hooks system is the most underappreciated thing in what leaked. Hooks is an official documented feature for quite a long time now https://code.claude.com/docs/en/hooks https://code.claude.com/docs/en/hooks
- Artoooooor 6mo agoBut it still doesn't recognise "rubbish" :D
- pjoubert 6mo agoI'm curious about what people are not looking for about Claude code. What's missing and nobody is talking about? Any clue?
- baby 6mo agoCan someone ask claude to write a deep dive on how compaction works and why it’s so slow? (I still can’t fathom why they wouldn’t just add a user message “compact the conversation we’ve just had”
- pmakhija3 6mo ago[dead]
- alcor-z 6mo ago[dead]
- alcor-z 6mo ago[dead]
- algolint 6mo ago[flagged]
- algolint 6mo ago[flagged]
- navilai 6mo ago[dead]
- getverdict 6mo ago[flagged]
- firemelt 6mo ago>but it tells you something about where even AI companies draw the line on using their own models. can we really quote it as company decision instead an engineer?
- getverdict 6mo ago[dead]
- Sim-In-Silico 6mo ago[dead]
- heliumtera 6mo agoWhat a cesspool. So this is the power of being 80x more productive, having infinite llm usage quota? No wonder they had to let Satan take the wheel and went 100% vibe code. Thanks for making a point, llms are a disgrace
- jeremie_strand 6mo ago[dead]
- eranation 6mo agoProbably an unpopular opinion but Anthropic are too popular for their own good. 1. They are loved, and for good reasons, Sonnet 4 was groundbreaking but Opus 4.6 was for many a turning point in realizing Agentic SDLC real potential. People moved from Cursor to Claude Code in droves, they loved the CLI approach (me too), and the LOVED the subsidized $200 max pro plan (what's not to love, pay $200 instead of $5000 to Cursor...) They are the underdog, the true alternative to "evil" OpenAI or "don't be evil" Google, really standing up against mass surveillance or use of AI for autonomous killing machines. They are standing for the little guy, they are the "what OpenAI should have been" (plus they have better models...) They are the Apple of the AI era. 2. They are too loved, so loved that it protects them from legitimate criticism. They make GitHub's status page look good, and they make comcast customer service look like Amazon's. (At least Comcast has customer service), They are "If Dario shoots a customer in the middle of 5th avenue it won't hurt their sales one bit" level of liked. The fact they have the best models (for now) might be their achilles heel, because it hides other issues that might be in the blindspot. And as soon as a better model comes out from a competitor (and it could happen... if you recall OpenAI were the undisputed kinds with GPT 4o for a bit) these will become much more obvious. 3. This can hurt them in the long run. Eventually you can't sustain a business where you have not even 2 9s of SLA, can't handle customer support or sales (either with humans or worse for them - if they can't handle this with AI how do they expect to sell their own dream where AI does everything?). I'm sure they'll figure it out, they have huge growth and these are growth pains, but at some point, if they don't catch up with demand, the demand won't stay there forever the moment OpenAI/Google/someone else release a better model. 4. They inadvertently made all of the cybersecurity sector a potential enemy. Yes, all of them use Anthropic models, and probably many of them use Claude Code, but they know they might be paying the bills of their biggest competitor. Their shares drop whenever Anthropic even hints of a new model. Investors cut their valuations because they worry Anthropic will eat them for breakfast. I don't know about you, but if you ask me, having the people who live and breath security indirectly threatened by you, is not the best thing in the world, especially when your source code is out in the open for them to poke holes in... 5. the SaaS pocalypse - many of Claude Code's customers are... SaaS companies, that the same AI is "going to kill", again, if there was another provider that showed a bit more care about the entire businesses it's going to devour, if they also had even marginally better models... would the brand loyalty stay? Side note: I'm an Claude Enterprise customer, I can't get a human to respond to anything, even using the special "enterprise support" methods, and I'm not the only one, I know people who can't get a sales person, not to mention support, to buy 150 + seats (Anthropic's answer was - release self serve enterprise onboarding, which by the way is "pay us $20 which does not include usage, usage is at market prices, same as getting an API key", you pay for convenience and governance, p.s. you can't cancel enterprise, it's 20 seats min, for 1 year, in advance, so make sure you really need it, the team plan is great for most cases but it lacks the $200 plan, only the $100 5x plan).
- jwilliams 6mo agoI used to swear at Claude. To be honest, I thought it helped get results (maybe this is "oldschool" LLM thinking), but I realized it was just making me annoyed.
- saretup 6mo agoIt does send an analytics event when you’re swearing based on a keyword filter (something like is_negative:true), presumably as a signal that the model isn’t performing well this session, but who knows?
- galaxyLogic 6mo agoThe irony of ironies is in the last paragraph: " ...accidentally shipping your source map to npm is the kind of mistake that sounds impossible until you remember that a significant portion of the codebase was probably written by the AI you are shipping.”
- martin-t 6mo agoAs per https://drewdevault.com/2025/04/20/2025-04-20-Tech-sector-restistance.html https://drewdevault.com/2025/04/20/2025-04-20-Tech-sector-re... I congratulate the employee responsible.
- DeathArrow 6mo agoI hope cheap Chinese models will overtake Anthropic.
- devhouse 6mo agoClaude Code’s Source Code Leaked Through npm. Here’s What Actually Happened. https://www.everydev.ai/p/tool-claude-codes-source-code-leaked-through-npm-heres-what-actually-happened https://www.everydev.ai/p/tool-claude-codes-source-code-leak...
- edinetdb 6mo ago[flagged]
- Andebugulin 6mo agoRegex for swearing detected, user needs to get more API tokens, he is very very pissed.
- Gen_ArmChair 6mo agoThe Claude Code leak suggests multi-agent orchestration is largely driven by prompts (e.g., “do not rubber-stamp weak work”), with code handling execution rather than enforcing decisions. Prompts are not hard constraints—they can be interpreted, deprioritized, or reasoned around, especially as models become more capable. From what’s visible, there’s no clear evidence of structural governance like voting systems, hard thresholds, or mandatory human escalation. That means control appears to be policy (prompts), not enforcement (code). This raises the core issue: If governance is “prompts all the way down,” it’s not true governance—it’s guidance. And as model capability increases, that kind of governance doesn’t get stronger—it becomes easier to bypass without structural constraints. Has anyone actually implemented structural governance for agent swarms — voting logic, hard thresholds, REQUIRES_HUMAN as architecture not instruction?
- jamiemallers 6mo ago[dead]
- theblacksun 6mo ago[dead]
- pmakhija3 6mo ago[dead]
- Levitating 6mo agoI am still just shocked that Claude Code was written in Typescript, not C++, Rust or Python. It also somehow messed up my alacritty config when I first used it. Who knows what other ~/.config files it modifies without warning.
- tmountain 6mo agoI'm surprised Python is on that list. TypeScript doesn't seem like a terrible choice, as it can leverage vast ecosystems of packages, has concurrency features, a solid type system, and decent performance. C++ lacks as robust of a package ecosystem, and Python doesn't have inbuilt types, which makes it a non-starter for larger projects for me. Rust would have been a great choice for sure.
- Levitating 6mo ago> I'm surprised Python is on that list. I mostly mentioned it because it is pre-installed on some (linux) systems. Though of course if you're trying to obfuscate the sourcecode you need to bundle an interpreter with the code anyway. But it has historically been used for big programs, and there are well established methods for bundling python programs into executables.
- DrewADesign 6mo agoPython and C++ have been used for countless large projects— each one for many more than typescript. It’s all about trade-offs that take into account your tasks, available coders at the project’s commencement, environment, etc.
- rkozik1989 6mo agoPeople like to put companies that are household names on pedestals, but the choices they make are mostly guided by what their people can do and which choices give them the most value for free. They mostly operate how smaller companies do but they have a bigger R&D budget to address issues like scale that the larger market has little incentive to solve.
- driftcode 6mo ago[dead]
- matheusmoreira 6mo agoBut what does Claude do when it detects user fruatration?! Don't leave us hanging here! Edit: it gets sent to Anthropic via telemetry and it ends up on the fuck chart! https://old.reddit.com/r/ClaudeCode/comments/1s99wz4/boris_the_creator_of_claude_code_reponds_on_ccs/ https://old.reddit.com/r/ClaudeCode/comments/1s99wz4/boris_t...
- aiedwardyi 6mo ago[dead]
- surajpatelcs 6mo ago[dead]
- d4rkp4ttern 6mo agoFor me one of the most interesting aspects is how compaction works. It turns out compaction still preserves the full original pre-compaction conversation in the session jsonl file, and those are marked as "not to be sent to the API". Which means, even after compaction, if you think something was lost, you can tell CC to "look in the session log files to find details about what we did with XYZ". I knew this before the leak since it can be seen from the session logs. Some more details: The full conversation is preserved in the JSONL file, and messages are filtered before being sent to the API. Key mechanisms: 1. JSONL is append-only — old pre-compaction messages are never deleted. New messages (boundary marker, summary, attachments) are appended after compaction. 2. Messages have flags controlling API visibility: - isCompactSummary: true — marks the AI-generated summary message - isVisibleInTranscriptOnly: true — prevents a message from being sent to the API - isMeta — another filter for non-API messages - getMessagesAfterCompactBoundary() returns only post-compaction messages for API calls 3. After compaction, the API sees only: - The compact boundary marker - The summary message - Attachments (file refs, plan, skills) - Any new messages after compaction 4. Three compaction types exist: - Full compaction — API summarizes all old messages - Session memory compaction — uses extracted session memory as summary (cheaper) - Microcompaction — clears old tool result content when cache is cold (>1h idle)
- manwe150 6mo agoWhat is microcompaction? I didn’t realize there was any thing time based in CC, when I go eat dinner and come back it compacted while I was gone?
- d4rkp4ttern 6mo agoI dug into this more. It's disabled by default, and it's a cost/token-usage optimization. The logic is: 1. Anthropic's API has a server-side prompt cache with a 1-hour TTL 2. When you're actively using a session, each API call reuses the cached prefix — you only pay for new tokens 3. After 1 hour idle, that cache is guaranteed expired 4. Your next message will re-send and re-process the entire conversation from scratch — every token, full price 5. So if you have 150K tokens of old Grep/Read/Bash outputs sitting in the conversation, you're paying to re-ingest all of that even though it's stale context the model probably doesn't need The microcompact says: "since we're paying full price anyway, let's shrink the bill by clearing the bulky stuff." What's preserved vs lost: - The tool_use blocks (what tool was called, with what arguments) — kept - The tool_result content (the actual output) — replaced with [Old tool result content cleared] - The most recent 5 tool results — kept So Claude can still see "I ran Grep for foo in src/" but not the 500-line grep output from 2 hours ago. Does it affect quality? Yes, somewhat — but the tradeoff is that without it, you're paying potentially tens of thousands of tokens to re-ingest stale tool outputs that the model already acted on. And remember, if the conversation is long enough, full compaction would have summarized those messages anyway. And critically: this is disabled by default (enabled: false in timeBasedMCConfig.ts:31). It's behind a GrowthBook feature flag that Anthropic controls server-side. So unless they've flipped it on for your account, it's not happening to you.
- ATXO_Selam 6mo ago[dead]
- ATXO_Selam 6mo ago[dead]
- ATXO_Selam 6mo ago[dead]
- maguay 6mo agoAbsolutely hilarious that it's watching for frustration. I'd discovered, perhaps mid-2025, that Cursor was noticeably better at fixing bugs if I started cursing at it. Better yet, after a while it would seem to break and start cursing itself ("Oh yes, I see the f*** problem now" and so on). Hilarity ensued. What a world, where cursing at your machines can make them get their act together.
- deleted 6mo ago[deleted]
- tylerloveamber 6mo agoThe "undercover mode" discussion here is exactly the kind of thing non-technical CEOs need to understand — not the implementation, but the governance implication. If your developers are using a tool that actively avoids disclosing its involvement in commits and PRs, your audit trail is broken. I wrote a short piece explaining the 3 policy implications for teams using Claude Code (or any AI coding tool) — without the technical jargon: https://www.aipolicydesk.com/blog/claude-code-leak-what-ceo-should-do https://www.aipolicydesk.com/blog/claude-code-leak-what-ceo-... The short version: rotate API keys as a precaution, check what audit logs you actually have, and add a clause to your AI policy requiring vendor disclosure of new autonomous capabilities before they get enabled.
- federico_baez 6mo ago[dead]
- cordwainersmith 6mo ago[dead]