On March 31, 2026, Anthropic accidentally shipped a sourcemap file in a Claude Code npm update, exposing 600k lines of source code. Key findings from the leak include: KAIROS, an undisclosed autonomous background agent mode that runs 24/7 without user prompting; anti-distillation mechanisms that inject fake tool definitions to
Table of contents
How It HappenedChaos and LegalityInside the Source CodeMarch 2026 Was a Security DisasterWhat Engineers Building Agents Should Take AwaySort: