Monday, August 3, 2026

AI & Models

Anthropic suffers second data leak in one week

Anthropic accidentally exposed nearly 2,000 source code files in a software update, marking its second significant data leak in just one week.

Anthropic suffers second data leak in one week

On Tuesday, AI research and product company Anthropic pushed out version 2.1.88 of its Claude Code software package. Claude Code is a command-line tool for developers to use AI to write and edit code. During this software update, the company accidentally included a file that exposed nearly 2,000 source code files and more than 512,000 lines of code. This exposure revealed the architectural blueprints for one of Anthropic’s most important products. A security researcher named Chaofan Shou noticed the leak almost immediately and posted about the exposed files on X.

The incident represents the second significant data leak for Anthropic in a single week. Last Thursday, Fortune reported that the company had accidentally made nearly 3,000 internal files publicly available. Addressing the latest Tuesday leak, Anthropic stated, “This was a release packaging issue caused by human error, not a security breach.” These back-to-back leaks undermine the company’s public positioning. Anthropic has built its public identity around being a careful AI company that vocalizes the responsibilities of building AI technology, and it is currently in a dispute with the Department of Defense.

The files exposed on Tuesday did not contain the core AI model itself, but rather the software scaffolding—the supporting code structure around the AI model. This scaffolding includes the instructions that tell the model how to behave, what tools to use, and where its limits are. Developers who examined the leaked files quickly began publishing detailed analyses of the system. One developer described the leaked architecture as “a production-grade developer experience, not just a wrapper around an API.”

The exposure of Claude Code’s inner workings is notable because the tool has become formidable enough to unsettle rivals in the developer ecosystem. According to the WSJ, competitor OpenAI discontinued its video generation product Sora—pulling the plug on the tool six months after launching it to the public—to refocus its efforts on developers and enterprises. This shift by OpenAI to focus on developers and enterprises was reportedly driven partly by the momentum of Anthropic’s Claude Code.

Why it matters

Anthropic has built its reputation on being a careful, safety-conscious AI company. These back-to-back leaks undermine that identity and expose sensitive architectural blueprints for its key developer tools.