Anthropic exposed Claude source code through a packaging error
Anthropic accidentally exposed a significant portion of the source code for its Claude coding agent due to a packaging error during an internal release process. The leak included hundreds of thousands of lines of code, internal APIs and system design details. The incident was not the result of a cyberattack but of human error. Anthropic confirmed that no customer data, API keys or sensitive credentials were compromised, and that the issue was quickly contained after discovery.
What this means for your organisation
Most security programmes are built around external attack, yet the incidents that actually occur often begin with a mistake in a routine. A release process that packages more than it should is something any organisation writing its own software will recognise. The point is not that Anthropic made a mistake, but that the control has to live in the process rather than in whether an individual remembers correctly.
Berigo recommends
- Review what actually goes into your own release packages, and verify it automatically before publishing.
- Scan packages and artefacts for secrets as part of the build pipeline, not as a manual check.
- Keep internal and external release paths clearly separated, so a mistake in one does not publish outward.
- Add accidental exposure as its own scenario in the incident response plan, alongside attack.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch