‘There was a manual deploy step that should have been better automated’: Claude Code creator confirms cause of massive source code leak
Over half a million lines of Claude Code source code was leaked, with the company attributing the blunder to human error
Boris Cherny, creator of Anthropic’s Claude Code tool, has revealed the cause of a leak that saw 500,000+ lines of source code exposed online.
In a post on X, Cherny said “mistakes happen” amid reports the leak was an accident on the part of an Anthropic employee.
“As a team, the important thing is to recognize it’s never an individual’s fault - it’s the process, the culture, or the infra,” he said.
In this instance, Cherny noted there was a “manual deploy step that should have been better automated”.
“Our team has made a few improvements to the automation for next time, a couple more on the way,” he added.
The leak marks the second for the AI provider in the space of a week. Reports from Fortune on 26 March revealed information pertaining to an upcoming AI model launch were found in a publicly accessible data cache.
Files reviewed by Fortune showed the company is working on a new model, dubbed ‘Claude Mythos’, which a spokesperson said represents a “step change” in capability and could pose cybersecurity risks.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
What happened with the Claude Code leak?
Reports of a potential leak first emerged online on Tuesday 31 March, with security researcher Chaofan Shou claiming that source code was leaked through a map file in the company’s npm registry.
The leak prompted a flurry of activity online, with data backed up to a GitHub repository that was forked thousands of times, per reports from Techradar.
A Cloudflare storage bucket is believed to have contained 1,900 TypeScript files with upwards of 500,000 lines of code, as well as details on built-in tools and slash command libraries.
Anthropic has confirmed the incident and attributed the leak to human error, corroborating Cherny’s comments that steps have been taken to prevent a similar situation in future.
"A Claude Code release included some internal source code. No sensitive customer data or credentials were involved or exposed," a spokesperson told ITPro.
"This was a release packaging issue caused by human error, not a security breach. We're rolling out measures to prevent this from happening again.
Claude Code has rapidly become one of Anthropic’s most popular tools since launching, helping automate code generation tasks for software developers.
Figures touted in the wake of a recent funding round for Anthropic show Claude Code’s run-rate revenue has reached more than $2.5 billion. While exact figures on user numbers are unclear, active weekly users are believed to have doubled since 1st January amid soaring popularity.
Indeed, recent analysis from Techcrunch found the tool - along with Claude Cowork - are now massive drivers of paid subscriptions at the firm.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
The identity recovery gap: confident on paper, exposed in practiceAI-accelerated attacks weaponize the IAM ecosystem, moving faster than defenders can respond — making identity recoverability a top priority in restoring data and AI trust.
-
Dynatrace acquires observability firm Arize in $915m dealNews The move will see Arize’s AI evaluation capabilities combined with Dynatrace’s production monitoring technology across the AI development lifecycle
-
Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agentsInter-agent collaboration is a serious cause for concern, says security expert
-
Cyber criminals are selling discount AI tokens on underground forumsNews Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access
-
1Password teams up with Anthropic to give Claude access to your credentialsNews A new ‘zero-exposure’ security framework allows agents to use stored credentials in the 1Password vault
-
The agents you use to beef up cybersecurity could be turned against you – ‘Friendly Fire’ attacks can manipulate OpenAI and Anthropic models into running malicious codeNews Research shows agents can be fooled into executing malicious code while performing security reviews of third-party software
-
Flaws in some of the most popular AI coding tools left developers wide open to attackNews Malicious repositories can trick advanced AI agents into silently breaking out of their workspace sandboxes
-
Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victimsNews Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware
-
‘These sorts of post-compromise techniques used to be restricted to actors with the technical knowledge to carry them out’: Anthropic warns AI is helping lower the bar for up-and-coming hackersNews AI is making it harder to differentiate between high and low-skilled actors
-
Claude users beware, hackers are using a fake website to dupe developers and deliver malwareNews 'Beagle' is deployed through a Dynamic Link Library (DLL) sideloading chain, and gives attackers remote access to the system