Anthropic's Claude Code leak exposes Tamagotchi pet and always-on agent features
A source code leak in Anthropic's Claude Code 2.1.88 update exposed more than 512,000 lines of TypeScript, revealing unreleased features including a Tamagotchi-like pet interface and a KAIROS feature for background agent automation. Anthropic confirmed the leak was caused by a packaging error, not a security breach, and has since fixed the issue.
Anthropic's Claude Code Leak Exposes 512,000 Lines Including Unreleased Features
Anthropic's Claude Code 2.1.88 update accidentally included a source map file containing its full TypeScript codebase—more than 512,000 lines of code—which users quickly discovered and copied to public GitHub repositories. The leak has since amassed over 50,000 forks.
What the Leak Revealed
Users analyzing the code have identified several unreleased features:
Tamagotchi-style pet interface: A virtual pet that "sits beside your input box and reacts to your coding," according to Reddit users who reviewed the code.
KAIROS feature: Described as an "always-on background agent" capable of executing tasks autonomously on a user's behalf without explicit prompts.
Internal architecture details: The leak exposed Anthropic's memory architecture, AI bot instructions, and comments from developers. One engineer's note acknowledged that "memoization here increases complexity by a lot, and im not sure it really improves performance."
Anthropic's Response
Anthropric spokesperson Christopher Nulty stated: "Earlier today, a Claude Code release included some internal source code. No sensitive customer data or credentials were involved or exposed. This was a release packaging issue caused by human error, not a security breach. We're rolling out measures to prevent this from happening again."
The company fixed the issue shortly after discovery, but the code had already been mirrored publicly.
Security and Operational Impact
Arun Chandrasekhar, an AI analyst at Gartner, told The Verge that while the leak poses "risks such as providing bad actors with possible outlets to bypass guardrails," its long-term impact may be limited. He framed it as "a call for action for Anthropic to invest more in processes and tools for better operational maturity."
The leak does not appear to include API keys, credentials, or customer data—distinguishing it from a full security breach. However, it provides potential attackers with detailed knowledge of Claude Code's internals, including security controls and implementation details.
Context: Claude Code's Evolution
Anthropric launched Claude Code in February 2025 as an AI-powered coding assistant. The tool gained significant traction after Anthropic added agentic capabilities, allowing it to perform tasks autonomously. The company also released Cowork, a platform that integrates Claude Code with computer control capabilities.
What This Means
The leak accelerates public visibility of Anthropic's upcoming features by months, potentially influencing competitor roadmaps and user expectations. The Tamagotchi pet and KAIROS agent features suggest Anthropic is moving toward more interactive and autonomous coding assistance. However, the incident highlights operational vulnerabilities in deployment processes at major AI labs—a concern that extends beyond Anthropic to the entire industry. Organizations handling sensitive AI development will likely scrutinize their build and release pipelines more carefully.
Related Articles
Anthropic launches contract review tool in Claude for Small Business that flags risky clauses
Anthropic has released Claude for Small Business, a collection of 31 AI skills for Claude Cowork subscribers. The standout feature is /review-contract, which analyzes legal contracts and flags problematic clauses in approximately five minutes. The tool requires at minimum a $20/month Claude Pro subscription.
Security researchers use Anthropic's Mythos Preview to bypass Apple's M5 memory protection in 5 days
Security researchers at Calif used Anthropic's Mythos Preview model to develop a working macOS kernel memory corruption exploit on M5 silicon in five days, bypassing Apple's Memory Integrity Enforcement (MIE) system. The exploit chain targets macOS 26.4.1 and escalates from unprivileged local user to root shell using two vulnerabilities and several techniques.
Microsoft Cancels Claude Code Licenses, Pushes Developers to GitHub Copilot CLI
Microsoft is removing Claude Code access from its Experiences + Devices division by June 30, 2026, redirecting thousands of engineers to GitHub Copilot CLI instead. The decision follows six months of Claude Code proving more popular than Microsoft's own coding tool among internal developers.
Anthropic's Mythos Preview solves previously unsolvable cybersecurity test in updated checkpoint
A month after its initial release, a newer checkpoint of Anthropic's Mythos Preview became the first model to complete the UK AI Safety Institute's 'Cooling Tower' cyber range, solving it in 3 of 10 attempts. The model also completed 'The Last Ones' range in 6 of 10 attempts, surpassing OpenAI's GPT-5.5 and demonstrating capability improvements within a single model version.
Comments
Loading...