Anthropic Issues DMCA Takedown Notices, Massively Removes 8,100 Source Code Repositories

marsbitPublished on 2026-04-01Last updated on 2026-04-01

Abstract

AI giant Anthropic has issued multiple DMCA takedown notices to GitHub in response to a major source code leak. The company is targeting illegally hosted repositories containing the code for Claude Code. As a result, GitHub has removed the main repository along with over 8,100 forked repositories, marking one of the largest code copyright clean-up operations in the AI industry. Contrary to initial reports of employee error, an internal investigation revealed the leak was caused by a bug in an internal packaging tool. This bug mistakenly included sensitive files and full TypeScript source code, which should have remained private, into a production build. While this finding shifts blame from employee misconduct, it highlights a critical security flaw in Anthropic's automated workflow. Despite the takedown, the code had already been downloaded by thousands of developers within 48 hours and widely shared on platforms like Telegram, cloud storage, and private Git servers, making complete eradication nearly impossible. The leaked code, which includes implementation logic and internal model fine-tuning instructions, continues to be actively analyzed by developers.

In response to the recent source code leak incident, AI giant Anthropic has officially launched a legal counterattack. According to the latest news, the company has submitted multiple DMCA (Digital Millennium Copyright Act) takedown notices to GitHub, demanding the removal of all illegally hosted Claude Code source code repositories on the platform.

As a result, GitHub adopted a "wholesale" approach, not only deleting the reported main repository but also simultaneously taking down over 8,100 related forked repositories. This marks one of the largest code copyright cleanup operations in the AI industry in recent years.

Leak Cause Reversed: Not "Human Error," but a Tool BUG

Public opinion previously widely believed the leak was due to employee operational error, but the latest investigation report reveals that the real culprit may be an underlying BUG in a certain packaging tool used internally by Anthropic.

This BUG caused the system to mistakenly include sensitive files and complete TypeScript source code, which should have remained private, when building the production environment package. The exposure of this technical detail somewhat alleviates external doubts about the professional competence of Anthropic employees but also reveals serious security vulnerabilities in their automated workflow.

Although GitHub cooperated by taking down 8,100 repositories, it is nearly impossible to completely erase this data, as the source code has been downloaded, cloned, and disseminated by tens of thousands of developers worldwide over the past 48 hours, spreading to Telegram, cloud storage, and private Git platforms.

Currently, a large number of developers within the community are conducting "archaeological" research on this code. The leaked source code not only reveals the implementation logic of Claude Code but also contains a wealth of internal instructions regarding model behavior fine-tuning.

Related Questions

QWhat legal action did Anthropic take in response to the source code leak?

AAnthropic submitted multiple DMCA (Digital Millennium Copyright Act) takedown notices to GitHub to remove illegally hosted Claude Code source code repositories.

QHow many repositories were affected by GitHub's takedown in response to Anthropic's DMCA notices?

AGitHub took down over 8,100 related fork repositories in addition to the main reported repository.

QWhat was the actual cause of the source code leak, according to the latest investigation?

AThe leak was caused by a bug in an internal packaging tool used by Anthropic, which mistakenly included sensitive files and full TypeScript source code that should have remained private when building the production environment package.

QWhy is it nearly impossible to completely remove the leaked source code from circulation?

AIt is nearly impossible because the source code was downloaded, cloned, and spread by tens of thousands of developers worldwide within 48 hours, and it has been disseminated to platforms like Telegram, cloud storage, and private Git platforms.

QWhat does the leaked source code reveal about Claude Code?

AThe leaked source code reveals the implementation logic of Claude Code and contains a large number of internal instructions related to model behavior fine-tuning.

Related Reads

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

The 2026 Mid-Year Report on On-Chain RWA highlights a significant growth in tokenized stock market capitalization, which nearly doubled from $951 million in March to $1.89 billion by July. However, the report reveals a fundamental contradiction in this "layer 2.5" ecosystem: products with the strongest legal foundation (like regulated U.S. infrastructure) lack liquidity and distribution, while freely tradable offshored wrapper products often lack substantive ownership rights. The increase is driven largely by a few products (SECZ, FGRS, STRCx) and platforms (Ondo, xStocks, Securitize collectively hold over 85% share). While distributed value across networks like Ethereum, Solana, and BNB Chain has grown, the market remains fragmented. Products referencing the same underlying asset (e.g., Apple stock) are distinct legal liabilities with different intermediaries and jurisdictional rules, offering varying degrees of legal claim. The report cautions that headline numbers are misleading, as they reflect changes in distributed token value—driven by issuance, conversions, and price movements—not pure investor inflows. True "canonical shares" with legal ownership, wide wallet distribution, institutional liquidity, and independent on-chain price discovery do not yet exist at scale. Tokenized treasuries show stronger product-market fit, and ETFs may be easier to scale than single stocks. The core takeaway is a trade-off: legal certainty versus liquidity and composability.

marsbit48m ago

2026 Mid-Year Report On-Chain RWA: Tokenized Stock Market Cap Doubles in a Year, But 90% of Rights Are Hollow Shells

marsbit48m ago

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

The Coldcard hardware wallet has been compromised, with hackers stealing approximately 594.5 Bitcoin (~$40 million) from 500 addresses in just 25 minutes. The root cause was a critical software bug, undetected for five years, which disabled the device's secure chip for generating true random numbers. This led to the creation of private keys based on predictable data like the processor's serial number, drastically reducing cryptographic security. The attackers exploited this offline by brute-forcing possible seed phrases, finding active addresses on the public ledger, and signing transactions. Initially, Coinkite (Coldcard's maker) claimed only older models were at risk but later admitted all devices running the compromised firmware were vulnerable. CEO Rodolphe Novak (NVK) apologized but ruled out financial compensation for affected users. To secure funds, owners must urgently update their firmware to specific safe versions, generate a completely new seed phrase on the updated device, and transfer all assets to new addresses created with that new seed. While a BIP-39 passphrase can help, it does not replace this migration process. Other Coinkite products like TAPSIGNER were not affected. This incident underscores that even specialized hardware requires rigorous, independent code audits, especially for cryptographic functions. It parallels past failures, like a 2006 OpenSSL bug in Debian, and raises questions about whether automated code analysis can ever fully replace human scrutiny in critical security areas.

cryptonews.ru3h ago

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

cryptonews.ru3h ago

Trading

Spot
活动图片