In the early hours of March 31, 2026, something Antropic had absolutely refused to disclose was released onto the internet. 512,000 lines of TypeScript code —the entire internal source code of Claude Code—were exposed to developers worldwide due to a single mistake in distributing an npm package. It was not a hack, nor was it a whistleblowing; it was simply a mistake . Synthesizing the leaked code with interpretations from the global analytics community, Aleph has compiled seven key features from a general user's perspective that will allow you to “use Claude differently if you know this.”
1What on earth happened?
The beginning of the incident was absurdly simple. When Antropic released Claude Code v2.1.88 on npm, they accidentally included an internal debugging source map (.map) file. This single 59.8MB file contained a link pointing to the full source code archive hosted on Antropic's own cloud storage. The door wasn't locked; someone just needed to open it.
When Chaofan Shou, an intern developer at blockchain security firm Fuzzland, shared a direct link on X (Twitter), the GitHub mirror repository garnered tens of thousands of stars within hours, and thousands of developers jumped into analyzing the code. Antropic filed a DMCA request to remove the code, but the internet had already copied it.
If you installed or updated Claude Code via npm between 00:21 and 03:29 UTC on March 31, 2026, you may have been exposed to a simultaneous axios supply chain attack (malicious versions 1.14.1 or 0.30.4). Check your lock files for
plain-crypto-js dependencies and replace your credentials immediately if found. Antropic has now designated the curl native installer as the official recommended method.7 Key Features Revealed by the 2 Leak
Aleph has summarized the key takeaways from the global developer community's code analysis in user-friendly language. Some of these features are already operational, while others are still hidden behind private flags.
You might think you need to open a new window if the conversation gets long, but Claude Code is already running seven compression techniques in the background. From removing repetitive system messages and collapsing long files to automatically summarizing the entire conversation, keeping the existing chat window open is the smarter way to use it.
The most notable aspect of the leaked code is the three-stage memory architecture . Entropic designed a proprietary structure to address the 'context entropy' problem, where AI agents become confused as conversations lengthen. The key element is the MEMORY.md file. This file acts as a lightweight index that records only the location of information rather than storing it directly. Actual project information is distributed across separate topic files, and the agent retrieves them only when necessary. It can be viewed and edited directly using the /memory command.

This feature is mentioned more than 150 times throughout the source code. KAIROS is an autonomous agent mode that runs continuously in the background without requiring user commands. It detects file changes, logs events, and cleans up memory via the 'autoDream' process while the user is away. Currently, it is behind a private flag and is completely disabled in public builds.

This is the core process of KAIROS. If 24 hours have passed since autoDream was last launched and it has conversed with the user at least five times, Claude Code quietly organizes memories in the background. It combines scattered observations, eliminates logical inconsistencies, and transforms vague insights into concrete facts. When the next conversation begins, the context starts with everything already neatly organized.
Instead of assigning tasks one at a time, if you give a loud command like “Analyze, fix bugs, and write documentation,” Claude Code internally creates multiple child agents to process them in parallel. Cost increases are also minimized because it copies and uses the parent agent’s memory.
This is an unreleased feature. It involves delegating complex planning tasks to a cloud container (Claude Opus 4.6) instead of locally, allowing it to think for up to 30 minutes, and then approving the results in the browser. It appears to be a feature designed for tasks where local computation is limited, such as large-scale refactoring or architecture analysis.
This is the most bizarre feature, scheduled for official release (code date: May 2026). A small character sits next to the terminal input window and occasionally reacts with speech bubbles. Its appearance is determined by the user ID from among 18 species, including the Capybara, and it even features a built-in gacha system where a 'Shiny Legendary Pet' appears with a 0.01% probability. DEBUGGING, PATIENCE, and CHAOS stats also exist.
| Function name | Current status | Key role | User experience |
|---|---|---|---|
| Automatic compression | Public activation | Context management | No need for a new window |
| MEMORY.md | Public activation | 3-stage memory | Style memory |
| Coordinator Mode | Partially active | Parallel agent | Improve work speed |
| KAIROS | Unreleased | Always in background | Always-on AI |
| autoDream | Unreleased | Memory cleanup during sleep | The next day, clean context |
| ULTRAPLAN | Unreleased | 30-minute remote planning | Large-scale architecture analysis |
| BUDDY | Scheduled for May | Terminal Pet | Development Partner |
The Significance of This Leak from Antropic's Perspective
Antropic stated, “No customer data or credentials were exposed, and it was a human error during the packaging process, not a hack.” That is not wrong. However, experts are focusing on a different point.
① IP Leak — Claude Code is a core product generating $2.5 billion in annual ARR. Its internal design philosophy and agent architecture have been exposed to competitors.
② Roadmap Exposure — The development direction of unreleased features such as KAIROS, ULTRAPLAN, and BUDDY has been revealed. While code can be refactored, the effect of a strategic surprise cannot be reversed.
③ Repeated Mistakes — This is the third similar incident. There was a similar source map leak in February 2025, and on March 26, 3,000 internal documents for the unreleased model 'Claude Mythos' were released due to a CMS configuration error.
However, from an investor's perspective, a different interpretation is possible. What the leaked code reveals is not just a simple chatbot CLI. Always-on agents, self-healing memory, multi-agent swarms—the entire codebase reveals that Antropic is positioning Claude Code as a developer's enduring AI partner.
4 Aleph’s Perspective — If You Are an AI Tool Investor, Read This
This leak goes beyond a simple security incident and serves as an event that reveals the landscape of the AI development tool market. Here are a few key points.
Claude Code is already a platform.
510,000 lines, 1,900 files — this is not the scale of a “terminal command tool.” It is a platform-based CLI featuring layered function modules, multi-agent orchestration , and a proprietary memory system. An ARR of $2.5 billion is no coincidence.
The competitive landscape may change.
While Google's Gemini CLI and OpenAI Codex have released the agent SDK as open source, this leak reveals the entire internal wiring of the flagship product . This could significantly reduce the time it takes for latecomers to build similar systems by referencing architectures like KAIROS and autoDream.
Antropic's Governance Risk
Two major data leaks within a week. Questions are being raised about the release management system of a company that has grown to an annualized size of $19 billion. It is appropriate to determine whether this is short-term noise or a structural problem based on whether it recurs .
Things you can use right now: ① Continue chatting instead of creating a new one, ② Induce Coordinator Mode by issuing complex tasks at once, and ③ Directly check and edit MEMORY.md using
/memory command. Changing just these three things will make a difference in productivity.Conclusion — The Paradoxical Transparency Created by the Leak
Although it was a disclosure Antropic did not want, the result was that the developer community got a proper look for the first time at the philosophy and direction behind the creation of Claude Code. The way it resolves context confusion, the design that runs agents in parallel, and the idea of 'memory cleanup while sleeping'—these are not merely features, but Antropic’s answer to where AI coding tools should be headed.
On the day KAIROS and autoDream are released, Claude Code will become something different from what it is now. Not a tool waiting for commands, but a partner by the developer's side that always understands the context. The fact that this roadmap was leaked to the world first is the most important point of this situation.
The feature information cited in this article is based on reports from the developer community analyzing leaked source code and has not been officially confirmed by Antropic. Unreleased features (KAIROS, ULTRAPLAN, BUDDY, etc.) may be changed or removed from the final product. Please refer to Antropic's official guidelines first regarding security measures.
📌 Was this analysis helpful?
In the next post, we plan to cover “How the AI development tool market will change once KAIROS is released.”
Please leave a comment with your experience using Claude Code or any questions you have.
`
—
## Summary of Image Requests
There are **2** locations in the text where images need to be inserted.
**① Top of Section 1 — Image of the evidence at the start of the incident**
– Required: A screenshot of Chaofan Shou's original X (Twitter) post, or a representative image of a news article related to the leak.
– Search keyword: `Chaofan Shou Claude code leaked npm X tweet 2026`
– Alternative: Check the URLs of relevant news article thumbnails from VentureBeat, AI Times, etc., and insert them.
**② Section 2 MEMORY.md Description — Memory Architecture Diagram**
– Required: A diagram showing the MEMORY.md index → topic file distribution → agent call flow
– DIY Recommendation: Creating a simple infographic and uploading it to WordPress is the cleanest option.
– Alternative: If diagram images are available on relevant analysis blogs (VentureBeat, DEV.to, etc.), check the URL and use them.
—
## 4 Types of SNS Distribution Phrases
**X (Twitter)** — Hook only, no body; link in the first comment
`
Antropic leaked 510,000 lines of Claude Code source code.
It's neither hacking nor whistleblowing
With a single npm package distribution mistake.
7 Hidden Features Revealed — The AI You're Using Right Now Was Actually Doing These Things 🧵
`
*(Link to Buffer First Comment: https://aleph.ai.kr/claude-code-source-leak-2026)*
—
**Threads**
`
Antropic accidentally leaked 510,000 lines of Claude Code source code.
KAIROS (Always-on AI), autoDream (Memory cleanup during sleep), ULTRAPLAN (30-minute remote planning)…
These things were hidden within the AI tools we use every day.
Aleph has summarized 7 key features in plain language.
👉 https://aleph.ai.kr/claude-code-source-leak-2026
# ClaudeCode #AI #Antropic
`
—
**Instagram Reels Captions**
`
510,000 lines of Claude Code source code have been leaked 🔓
Neither hacking nor whistleblowing —
Antropic's internal code, exposed to developers worldwide due to a single npm package distribution mistake.
Things revealed within:
🧠 MEMORY.md — How AI Remembers Your Style
⚡ KAIROS — Always-on background AI
💤 autoDream — A feature that cleans up memory while you sleep
📋 ULTRAPLAN — 30-Minute Remote Planning
🐾 BUDDY — Tamagotchi Pet Inside the Terminal (Scheduled for release in May)
I have also compiled tips that you can use right now.
For the full analysis, please refer to the profile link (Linktree) 🔗
#ClaudeCode #AITools #Antropic #Developer #ArtificialIntelligence #AIInvestment #TechnologyAnalysis
`
—
**Facebook**
`
💻 Claude Code Source Code Leak — 7 Hidden Features Revealed in 510,000 Lines
In the early hours of March 31, 2026, something that Antropic had absolutely no intention of revealing was released on the internet.
Not hacking, but a single distribution mistake.
From KAIROS (always-on background AI), autoDream (memory cleanup during sleep), to the Tamagotchi pet BUDDY — these things were already in the AI tools I usually used.
Aleph has synthesized an analysis of the developer community and organized it from the perspective of a general user.
👉 https://aleph.ai.kr/claude-code-source-leak-2026
Sharing this will be helpful to those around you as well 🙏
How this content was produced
Aleph's research AI agent assisted with collecting and analyzing public data, creating charts and visuals, and structuring the draft. Davar personally reviewed and edited the sources, figures, reasoning, and final conclusions.
This content is for informational purposes only and is not personalized investment advice or an individual stock recommendation. Read the full disclaimer
© Aleph. All rights reserved.





