In short
Post-mortem of the April 1, 2026 leak of Anthropic’s Claude Code, including a supply-chain attack and what the leak reveals about agent “harness” IP and secure agent design.
Guests/backgrounds
Daniel Whitenack, CEO at Prediction Guard; Chris Benson, principal AI and autonomy research engineer.
Key claims
- Claude Code’s real proprietary value is the agent harness (memory, tool orchestration), not the model weights.
- The leak combined two simultaneous failures: a malicious Axios package and an exposed .map file that enabled reconstruction of ~500,000 lines of proprietary code.
- The malicious Axios included a remote access trojan, compromising machines that updated/downloaded in a ~3-hour window.
Notable examples
- Timeline: DoD labeled Anthropic a supply-chain risk (Mar 3, 2026); preliminary injunction (Mar 26); earlier Claude Mythos leak (Mar 27).
- Researcher Chao Fan Xiu (Fried Rice) reconstructed the code; a clean-room rewrite repo rapidly hit 50k stars in ~2 hours and 100k soon after.
- Memory.md sharded memory + grep-like log verification; “strict write” hallucination prevention; anti-distillation decoys; uncover.ts file to hide AI authorship, criticized by open-source community.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOContext of Discussion
1:48 to 2:16
Explaining the significance of the April 1st date and connection to current events.
“2026 i guess last night or last night kind of into today was this perfect storm of uh leaking of Anthropic's Cloud Code code base and related vulnerabilities in toolchain of Cloud Code.”
Anthropic's Recent Challenges
2:16 to 3:40
Discussing Anthropic's challenges and its identification as a supply chain risk.
“What was, I mean, before we get into, I want to go through the timeline and kind of all the dynamics here.”
Introduction to Claude Code
3:40 to 5:00
Overview of Anthropic and its Claude Code as a significant tool for developers.
“And Anthropic appropriately went to a judge and got some relief on that legal situation with a whole bunch more to be played out that hasn't happened yet.”
Functionality of Cloud Code
5:00 to 6:50
Detailed look at the capabilities and impact of Cloud Code on coding practices.
“So constitutional AI, enterprise focus, safety, publishing their system prompts and other things and doing a lot of good research.”
Timeline of Events Leading to the Leak
6:50 to 8:45
Chronological events leading to the leak of Claude Code and related vulnerabilities.
“agent-driven development and has very much taken the software development world by storm, I would hardly talk to any developer that is not using Cloud Code, I guess is the way to put it.”
The Supply Chain Risk Designation
8:45 to 11:47
Exploring the implications of Anthropic being labeled a supply chain risk by the government.
“So both things happened at basically the same time.”
Reactions from the Technical Community
11:47 to 13:44
Discussion on how the technical community and customers are responding to the news.
“Certainly they had a supply chain risk internally, but their position as a company was more on the safety side.”
Ongoing Legal Developments
13:44 to 14:00
Updates on the legal process involving Anthropic and government interactions.
“And there's been a lot of risk mitigation in recent weeks from many, many, many organizations along those lines.”
Anthropic's Claude Code Leak Overview
14:00 to 17:36
An introduction to the issues surrounding Anthropic's Claude code leak and its implications.
“And And that process is still playing out.”
Supply Chain Vulnerability and Code Reconstruction
17:36 to 21:28
In-depth discussion of the supply chain vulnerability and how the code was reconstructed.
“I mean, there's some things to learn in terms of what not to do cybersecurity wise, but there's also some things to learn agentic development wise that are interesting from what we know.”
Show all 19 chapters
Intellectual Property and Agent Harness
21:28 to 24:10
Exploring the significance of the agent harness around AI models and its implications for IP.
“But still interesting to learn many things from those that have dug in.”
Memory Management in AI Agents
24:10 to 28:00
Details about Claude code's memory management strategies and their impact on AI performance.
“of the actual Opus model or whatever Claude Anthropic model Because all of the IP is in this agent harness around the model, which means I don't have to use an anthropic model.”
Understanding Memory Management in AI Agents
28:00 to 30:11
Learn about the memory management techniques in AI agents, including indexing and sharded information.
“Basically, it's only the pointers to where certain information is held.”
Architectural Innovations in Agent Development
30:11 to 33:18
Explore the architectural principles and innovations that are shaping agent development standards.
“So we're kind of seeing what is likely a turning point in mature agent development going forward.”
Ethical Concerns with AI Code Generation
33:18 to 36:23
Discuss the ethical implications and community backlash surrounding AI-generated code in open source.
“The thing that people have pushed back on quite a bit is there's actually this anti-distillation flag within Cloud Code that basically tries to...”
The Shift from Reactive to Proactive AI Agents
36:23 to 39:23
Understand the transition of AI agents from reactive to proactive models and its significance.
“And it's interesting to kind of, I guess, place this within the wider ecosystem and how agentic and autonomous systems are developing.”
Best Practices for Building AI Agents
39:23 to 42:01
Gain insights on best practices for memory management and supply chain risks in AI agents.
“And if you think about it, we've been talking about these harnesses and the infrastructure around it a lot more, as is everyone.”
Memory Management and Supply Chain Risks
42:01 to 43:03
Learn about the importance of memory management and the risks associated with agent harnesses.
“Number one, think about how you manage memory in your agents and be smart about it in that harness using kind of sharded memory and lookups.”
Engaging with the Audience
43:05 to 43:35
Discover how the hosts encourage audience feedback and engagement on AI topics.
“Well said, that's a good point to wrap up on.”
Transcript
Automatic transcript. May contain errors.0:02Welcome to the Practical AI Podcast, where we break down the real-world applications of artificial intelligence and how it's shaping the way we live, work, and create. Our goal is to help make AI technology practical, productive, and accessible to everyone. Whether you're a developer, business leader, or just curious about the tech behind the buzz, you're in the right place. Be sure to connect with us on LinkedIn, X, or Blue Sky to stay up to date with episode drops, behind-the-scenes content, and AI insights. You can learn more at practicalai.fm. Now, on to the show.
0:41Welcome to another episode of the Practical AI podcast. This is Daniel Whitenack. I am CEO at Prediction Guard, and I'm joined as always by my co-host, Chris Benson, who is a principal AI and autonomy research engineer. How are you doing, Chris? Doing good. How's it going today? Lots of cool stuff out there, isn't it? Oh my gosh. Lots of interesting, scary, intriguing, malicious things. So for context, if you're joining us at another point in time, listening to this in the future at some point, we're on April 1st, 2026, which is interesting. It's April Fool's Day. So what we're about to describe is not an April Fool's joke.
1:34Although I think there was a number of AI-related April Fool's like post, most tech companies post something. here and there but this was actually very much not a very much not a a joke as of today april 1st 2026 i guess last night or last night kind of into today was this perfect storm of uh leaking of Anthropic's Cloud Code code base and related vulnerabilities in toolchain of Cloud Code. And so, yeah, I mean, this is the most timely thing for us to talk about, Chris. What was, I mean, before we get into, I want to go through the timeline and kind of all the dynamics here. I mean, Anthropic was already dealing with some rather difficult things in relation to being identified as a supply chain risk by the U.S.
2:39government. But yeah, I mean, coming into this, what, yeah, what's your, how did this hit you? How did you learn about it? What, do you have your copy of Claude Code? I guess we shouldn't admit that one way or the other on this podcast. I don't know anything. Yeah, never, never speak. You know, the monkeys there, no see, no hear, no speak. Yeah, exactly. So if I did, I would never admit it. Yeah, I just, well, first of all, you know, in the, it's kind of background, like, Anthropics had a few interesting weeks here. Some challenges. Yeah, and they got a judge on their side. So if you're joining this later, or if you haven't followed, the United States Department Department of Defense that also likes to call themselves the Department of War, but that's not been approved by Congress, is, you know, kind of had this thing where they said we're no longer, because you're not doing exactly what we want, we're no longer going to let Anthropic be part of our supply chain.
3:41And Anthropic appropriately went to a judge and got some relief on that legal situation with a whole bunch more to be played out that hasn't happened yet. And so that alone had, you know, had been kind of an extraordinary story. But yeah, then apparently yesterday, and I woke up this morning ready for April Fool's jokes, you know, because as you pointed out, there's a lot of those, especially in this AI world. And when I first read it, I was like, first I saw the headlines in the newsreader and I'm like, oh, there's got to be no way, And then started reading, I was like, starting to feel like it might really have happened.
4:19Maybe this is just a coincidence. So, yeah. Yeah, maybe for those, I mean, many people have heard of Anthropic and Claude. For those, maybe that just to set the stage here. So Anthropic is an AI company founded in 2021 by former OpenAI executives. executives, sort of some of their focus as a company. Interestingly enough, as we're talking about the subject of security has been around AI safety, I guess, framed more as AI safety, not necessarily security for AI or AI for security, but AI safety. So constitutional AI, enterprise focus, safety, publishing their system prompts and other things and doing a lot of good research.
5:10But yeah, so they were founded in 2021. They have the Claude family of models, which now there's even TV ads about Claude. Hopefully many people in our audience are, of course, aware of this. Anthropic in 2021, Cloud Family and Models released, I don't know the timeline on the actual release of the tool, but they released Cloud Code, which is the topic of this discussion, which is amazing. I have to say is a spectacular tool and product and has enjoyed wonderful reception in the software development world. It's basically an agentic terminal-based coding agent assistant automation tool, whatever you want to call it.
6:02So you're in your computer, you're in your terminal, you can spin up Cloud. It works in your code base and you can have it do all sorts of things from running your tests, figuring out which tests fail, making the changes to fix those things. It can run bash commands. It can write whole software projects from scratch. Like it's very, this idea is very much the agentic autonomy forward view of software development. very much not the kind of GitHub co-pilot, although they've also implemented agentic things now. So I shouldn't, maybe that's not the greatest comparison, but the kind of traditional GitHub co-pilot model of the assistant in your IDE, which would help you kind of auto-complete things or maybe even answer questions.
6:49This is much more kind of autonomy, agent-driven development and has very much taken the software development world by storm, I would hardly talk to any developer that is not using Cloud Code, I guess is the way to put it. No, I think that's, I think that's, I don't think that's an overstatement at all. I think Cloud Code coming out, you know, I believe if I'm just for memory, it was in May of last year that it was released. And then in late November, Opus 4.5 was released. And so going into the December holiday season is kind of when people, Jaws were hitting the ground, including ours. It was the very first thing we were talking about into New Year's, obviously.
7:35And it is completely, in a very short amount of time, changed how people productively develop software now and the way that you do that and their workflows and stuff. So, I mean, it's I think it's one of those history we'll look back and go, that was kind of the moment where it really took off. And so, yeah, it's the leader, certainly. Yeah. And just to clear up the, or so timeline wise, well, I guess maybe we should say what the sort of what happened. Basically, if you downloaded Claude code during like a three hour ish time window in the past day or so, as we're recording this. Right. Then two things happen.
8:24One, you downloaded basically a bunch of proprietary IP from Anthropic that was kind of the agent harness and all the IP around Cloud Code revealing kind of how it works. And two, you downloaded a malicious version of a JavaScript package called Axios, which created a vulnerability on your computer. So both things happened at basically the same time. But there was a lot leading up to this. So maybe timeline-wise, it's worth mentioning that. We talked about like the adoption, you talked about the adoption of Claude Code, the release of the model. In terms of the problematic, we mentioned Anthropik's kind of been through the ringer recently.
9:13In late 2025, Anthropik acquired this BUN JavaScript runtime. So this was something that they were using, I think, within the project and or they integrated further. and that's relevant because that that javascript run runtime is the source of or a kind of key piece of why this leak happened so that was late 2025 not that long ago obviously things move fast um mark early march so march 3rd 2026 so about a month ago was when the department of war Department of Defense, designated Anthropic as a supply chain risk. This has been a topic of conversation and Anthropic going back and forth with the government not too long ago, so March 26, 2026.
10:16As you mentioned, Chris, Anthropic got a judge to grant Anthropic a preliminary injunction temporarily freezing this supply chain risk label. March 27th, the next day, there was a first leak, which wasn't the code leak, but talked about Claude Mythos, sort of a leaked blog post about, I mean, we hear this, I don't know, Chris, it seems like we hear this often where it's like, oh, the model is too dangerous to release because it's so powerful. It seems like we hear that every couple months and then it's released and, you know, we deal with it but um that was something that was sort of leaked on on march 27th so those are all like the the lead up to now i i guess it's interesting i mean uh this whole supply chain designation uh overlap with ai or anthropic being kind of primarily positioning itself almost as an AI safety company.
11:19There's kind of a dichotomy there, but then obviously they have integrated tools within their widely distributed project that had vulnerabilities in them, at least from the security side. So yeah, it's just a weird dichotomy of what in reality is the supply chain risk. And it's like layers upon layers of this where Anthropic was identified as that. Certainly they had a supply chain risk internally, but their position as a company was more on the safety side. I don't know. It's a lot of safety and security being thrown around and supply chain risk. So that was sort of the lead up, I guess, Chris, to where we're at.
12:04I don't know what the discussion's been like with practitioners that you've talked to. I would say from my perspective, just in talking with people a lot of the technical community is is kind of like oh why you know this is ridiculous anthropic being identified as a supply chain risk this is kind of ridiculous on the customer side like our customers who often work in regulated industries sometimes with some relation to the government are very much like oh the rug's been pulled out from under us, we were not thinking that Anthropic was going to be identified in this way. And they're sort of rethinking this sort of model vendor lock-in, the risk to themselves if they build everything on Anthropic.
12:54And then if one day the government can just say this is a supply chain risk and they have no way to pivot, that creates liability on their end. Yeah. And noting up front, since I work in the defense industry, that I'm only speaking for myself and no other organization. It's definitely, I mean, to your point there, it seemed very malicious, like the government said, you're going to do what we want, whether you like it or not. And this particular vendor said, no, we're not. And so this particular thing happened. So I think that has created that awareness that you spoke of throughout the entire, not only the AI industry, but I think many industries are recognizing that the rug can get pulled out very quickly.
13:45And there's been a lot of risk mitigation in recent weeks from many, many, many organizations along those lines. Now, in this particular case, as we pointed out, there was a judge came in and intervened on that. And And that process is still playing out. And I think my sense is that the government is kind of backing down from that anyway a little bit, which is probably good in the long term. It's not the kind of situation that is beneficial for anybody, I think. So, yeah, kind of rolling through this, but Anthropic, you know, when I talk to people, there's a mixture of kind of support and frustration there, you know, some of like even this is we tend to pick on open AI more often historically.
14:36And I'll acknowledge that. I'm the first person that has made some comments about them on the show and past episodes. but their codex is open source that is the competing thing and Claude's gotten a fair amount of criticism for not open sourcing so I've talked to a lot of developers just in groups today checking out in some cases just reading what other developers are saying and there's a certain amount of well they could have open sourced it up front and this is kind of what you get my suspicion is this will probably lead to open sourcing of that because now that the cat's out of the bag architecturally and there have been a number of efforts.
15:19There's one in particular who had already previously been working, a developer out there who had been working on trying to reverse engineer Claude code before this came out and had done some work along that lines. And that was one of the people that got ahold of the repo here last night. And what they did this time was instead of keeping that code out, and that was also shut down very rapidly through a legal request that's called a DCMA takedown in terms of not having that code out there. So this developer rapidly organized an effort to do a clean room rewrite of Claude code initially in Python, and there's also a concurrent effort to rewrite it in Rust.
16:07And the repo that both these efforts are together in hit, it was the fastest repo in history to surpass 100 ,000 stars on GitHub. They surpassed 50 ,000 stars in the first two hours the repo existed. So there's been a lot of attention here and a lot of people jumping in on it. So they're trying to get a Python version up and running immediately and with a rapid follow-up on a Rust version. All of this replaces the original, would essentially do a redo of the original TypeScript that was leaked, which was what Cloud Code was written in. So with the architecture being out of the bag, my expectation is that Anthropic will probably end up just open sourcing this because at this point, kind of why not?
17:00And at least that, you know, because you're not really losing anything at that point in terms of IP because the IP is already out there, whether it's appropriate or not. and uh and at least that kind of you know it kind of puts them open ai already did that it gets rid of a criticism without having lost anything given what happened so it's quite the soap opera in the world today um and i just kind of sitting back and watching and seeing what people are saying yeah and just i guess to uh circle back and dig into some of the details of actually what happened And then I think it'd be interesting that there are some things I think to learn from what was released.
17:38I mean, there's some things to learn in terms of what not to do cybersecurity wise, but there's also some things to learn agentic development wise that are interesting from what we know. So to give the specifics, what happened first was this supply chain. So basically two things happened simultaneously. A malicious version of the Axios library is published to MPM. This Axios library is kind of a third-party helper-type library used to make web requests. Cloud code depends on Axios. So, you know, basically at the same time Anthropic made their other mistake, they were basically through the dependence on this Axios library created the second problem.
18:45But the other thing that they did, in addition to their dependence on Axios, which Axios had this malicious version published at the same time, Anthropic accidentally left this basically a.map file in their repository of clod code. So basically this.map file generally helps debuggers map between kind of non-human readable JavaScript and files to human readable TypeScript. And so by leaving this.map file in the repository or in the package, it contained enough information that were you to want to, you could reconstruct like half a million lines of anthropic private closed source proprietary code, which is the main kind of guts and brain of the clod code package.
19:53Basically, if you're in that three hour window and you downloaded clod code or updated, you got at least where you could reconstruct those 500 ,000 lines of proprietary code. And you downloaded a malicious version of Axios, which contained remote access Trojan, which actually compromised your local machine. So kind of a perfect storm of things that happen. And there is a security researcher, Chao Fan Xiu, at Fried Rice on X that announced that he had reconstructed the source code. and as you mentioned Chris there was an open source repo then that kind of reconstructed this claw code repository which just elevated there were way more now I'm sure but you know tens and tens of thousands of forks also of this repo And that's kind of what we came into today.
21:09So we haven't talked about like the guts of that and what we discovered, but that was essentially the timeline of what happened. So I can at least say on this podcast that I did not update my cloud code or download it overnight. So unfortunately, I didn't get the$380 billion valuation proprietary code. But still interesting to learn many things from those that have dug in. And certainly still a lot going on on GitHub as we speak to reconstruct and leverage some of these ideas. Yeah, I think, I mean, yeah, I mean, you may not have gotten it, but the code is out there. many, many, many times over.
21:58People are not leaving. Back in that window, people are not leaving it on GitHub. I think everyone recognized that it was a big moment for Anthropic in a negative way. And so a lot of folks saved it offline. So it's out there. And that's why I said, I mean, I think Anthropic's best move would just be to go, we're open sourcing cloud code now and, you know, looking forward to community feedback to make it better. Yeah, yeah. And there's kind of, yeah, I guess there's an overall thing that we learn technically from this. And then there's specific things that are interesting to talk about. The overall thing I think to emphasize here is that actually it's not so much the, and we've suspected this for some time.
22:50And if you're a practitioner, you kind of know this by intuition. The model itself is not the relevant component that drives performance for these systems like Claude Code or OpenClaw, etc. There is a model that needs to be in these agentic systems. However, the real IP in these systems is actually not the model. It's this what's called the agent harness around the model, right? It's that orchestration of how is memory handled? How do you connect to tools? How do you persist things over sessions? How do you wake the agent up? How do you point to certain information? How do you give context? All of that is what we would call the agent harness.
23:40And it's really that kind of lines of code that was released by Anthropic, even though they didn't release the weights of their model, That's why I think this is so, it's one of the reasons why I think this is so interesting, Chris, is a year ago, we would have kind of been shocked and amazed if someone leaked model weights and that would be like, give us everything we need to know about their IP, right? We have the model weights, we can reconstruct it. We have their model. Here, it doesn't really matter if we have the model weights of the actual Opus model or whatever Claude Anthropic model Because all of the IP is in this agent harness around the model, which means I don't have to use an anthropic model.
24:23I could use whatever model I want. If I'm putting the right agent harness around it, I can do extremely powerful things, which is why this is such a leak and why it's so impactful, because that agent harness is where the IP is. Yeah, I think, you know, and in a broader context, we have actually been kind of saying what you just said in different words for a long time now. We've always pointed out that, you know, while, you know, modeling the functionality of different models has been increasing steadily, and we've been reporting on that as we go and talking about these models. but um you know we've said many many times it's still software it's still software architecture and the model is one component in a larger architecture and to your point much of the rest of the architecture is in this is in the harness that we're talking about and therefore that's why the ip is so critical um and especially when you consider the fact that once we crossed that threshold of kind of Opus 4.5 getting to a point where it was really flipping the entire developer world over on its side in terms of how people productively created software.
25:40And at this point, 4.6 came out early into the year, OpenAI has pushed forward with new models, and there will be many open source models coming out as well that are able to do every bit on that side. So it kind of points at The models are, as that progression goes, the models are becoming less and less important because there are going to be many of them that can do the same capability. And so these harnesses, as we move out, you know, in kind of where they're at now, but as they evolve into their edge harnesses and cloud harnesses and all sorts of different agent capabilities, this is huge. And this is a turning point.
26:17So if folks are not paying attention to that, I think they're kind of missing the story. I think reporting on the model is a time passed at this point to some degree. Yeah. And if we look then into Anthropics specific agent harness, there's a few high level things, which I don't think it's problematic for us to talk about here because everyone's talking about them everywhere. And essentially, this is widely known now, even though we're only a day into this. There's a few kind of key points of what makes the agent harness of clod code particularly powerful. The first of those being how it manages memory.
27:01You know, most or many AI agents, if you're not careful, depending on how you write them, they struggle with this kind of context entropy or memory drift or confusion where the more and more you add into the memory of the agent as it operates the the more junk is in there the more noisy it is the less effective the agent becomes and this is something that it seems like quad code is less prone to in in many ways and so revealed in the agent harness is there's kind of three levels or layers of the memory management within clod and i think this is interesting to talk about because it's practical for agent developers out there yeah for all of us which is the first thing is they have this memory dot md which basically is it is a it's constantly fed to the agent but it's not all the memory of the agent.
28:00Basically, it's only the pointers to where certain information is held. So it's kind of like an index or a pointer system to where information is. So you're not always loading in all information into the agent. You kind of have these pointers. So this is like an index to certain context information. Then there's sharded topical information. So rather than keeping everything together again there's this index but then there's these shards of discrete files that have certain types of information in it this prevents kind of again that noisy element of adding all memory into the agent but only loading kind of topic specific shards when those topic specific shards are relevant.
28:49And then the last piece is this kind of self-healing search mechanism to where you have essentially kind of, if you're familiar with Linux and grep, grep is a way for you to kind of search and scan logs so that the agent is actually configured such that it can verify actual information against the actual logs using a kind of optimized grep search rather than relying on its own generated summary. So it actually kind of self-searches this, you know, via this kind of almost like grep-like type of type of process so it's this searching it's the topic related shards and descriptive capability it's this topical index or contextual index in the memory.md that that is part of that memory hierarchy which i do think a lot of people struggle with it's kind of one of those points of disillusionment where i create an agent and i just keep loading it with more and more stuff and then it gets worse over time, which is counterintuitive and also sad.
30:10Yeah. I mean, and I think the learning, I mean, I think this is a big part of it is aside from whether, you know, what the future of CloudCode is going to be from a licensing standpoint and being, you know, having access to the code, I think these architectural concerns about things like memory management and other, you know, innovations and how they approach the various problems of agentic development will rapidly become very standard libraries across many languages, you know, where folks can start implementing that. So we're kind of seeing what is likely a turning point in mature agent development going forward.
30:51And so that's, you know, and you'll see the other players reacting to that. It'll be interesting to see what kind of changes we see in the industry coming up in the weeks to follow. Yeah, there's also a few, a couple other kind of general principles. And then one thing that's created a good bit of pushback against Anthropic from the open source community. So the other, like, to your point, Chris, what we can learn, what we can practically apply from this leak. um uh clod code also uses this strict right discipline type of principle um which is kind of a hallucination prevention so the idea is like your agent could say oh you've asked me to run the test okay i'm you know i am running tests and in the memory it's it's kind of represented that you ran the test, right?
31:46But under the hood in the actual system, maybe something errored out and you didn't actually run the test, right? Or maybe a file wasn't created or whatever happened. It didn't actually happen on the system, even if the agent said, I'm going to do this now and I did it. So they have this kind of strict write discipline idea where as you're developing your agent, you should only record to the memory of the agent when something happens, if you can verify against the environment, like the terminal or the API you're connecting to or the file system, that the thing actually happened. Not that the agent tried to do the thing, but that the thing actually happened and I verify it and then write it back to the memory.
32:29The other thing they have is a thing that I think is part of this memory management, I guess this idea of auto dream that for agents that run for very long periods of time, even days or weeks, kind of every 24 hours reviewing observations and insights and then kind of consolidating those into the kind of permanent facts of the memory such that you're not just continually increasing the size of that and leaking all sorts of noisy things into the memory. So you can tell it's kind of like that memory management, that harness, these layers, this architecture around it is very much the IP. The thing that people have pushed back on quite a bit is there's actually this anti-distillation flag within Cloud Code that basically tries to...
33:36So there's a couple of things. They have functionality and cloud code to number one, prevent people from trying to reverse engineer their harness by this anti-distillation, meaning they actually put fake stuff like fake tools into the into the chain of thought of the agent to throw you off the scent of trying to actually recreate what's what's actually going on. So it's very much a it's a totally decoy, fake tool injection, reasoning, masking ploy, which fair enough, you've got a proprietary thing, you know, go for it. I think the thing that maybe people were less happy about is this, there's a file uncover.ts, which basically is meant to hide, plot, or the AI's identity when it contributes to open source repos.
34:40So basically avoiding the kind of watermarking or any identification that things are AI generated. And the open source community has, let's say, had a bit of backlash against this because there's no transparent. Like it's basically an explicit attempt to hide AI generated code within open source contributions, which, yeah, which as the open source kind of likes transparency. And this is strictly non-transparent, right? Well, I mean, and when you really get to the heart of it, Anthropic has built its brand on safety and transparency, as noted at the top of the episode. And so when you're building, when you're differentiating yourselves against the other major players, and then something like that is found, it's one of those, I mean, this is purely speculative, but, you know, had we found that in OpenAI, people probably would have been like, Yeah, that's what I would have expected from them kind of thing.
Read the full transcript
35:49And just because of the general attitudes, whereas Anthropic, people are holding it to a higher standard based on that branding. And this is a moment where they fall flat on their face based on the discovery of that. So they've, I mean, it's not just an IP issue for the company. You know, it's also a brand perception and a trust issue within the larger developer community. So they have some fixing to do to put things right with the people that they are trying to serve. Yeah. Yeah. And it's interesting to kind of, I guess, place this within the wider ecosystem and how agentic and autonomous systems are developing.
36:36You've got CloudCode, which is a proprietary agentic development tool, but is still a reactive tool in the sense that it responds to your queries or specs or issues on GitHub and does things, right? It appears that as also part of this leak and what we learned about Anthropic, they're moving to this kind of product roadmap where they're moving away from the kind of current reactive version of Claude code to kind of running all the time or background maintenance, cron scheduling, refresh, etc. et cetera, type of model, which is very much more kind of OpenClaw based. So what's interesting is OpenClaw, which is an open source kind of agentic framework, also primarily interesting because of the agent harness around OpenClaw, just like the agent harness around Claude code makes it so interesting.
37:47But OpenClaw kind of has caused a lot of stir because it is kind of always running in the background and listening and has this kind of heartbeat mechanism to wake up and do things in the background. It does seem like Claude Code is moving that direction as well. And so I think if we were to look at kind of the comparisons here, Claude Code is currently reactive in similar ways to other assistants out there, but moving to the more proactive model, not in maybe the same exact way as OpenClaw, but, you know, more like OpenClaw where it's running 24-7 or as a daemon or has a kind of heartbeat or wake up mechanism.
38:34um also interestingly clod code and open claw are both kind of local um uh locally driven agents um one that has maybe more sovereignty associated with it in terms of your own control of it being open claw and one that's maybe uh has this proprietary element pushed off to the vendor and so I think that regardless if we're looking at the direction both from what we know now about Claude Code and what we've seen with OpenClaw get ready for the more proactive background agents that are going to be running all the time waking up on a heartbeat doing things for you and I think to your point Chris as well now that things have been leaked with Claude Code there's going to be a million open claw this and claw code this and things at the sort of Pandora's box opens.
39:33Yeah, it'll be interesting because, and, and, you know, as noted, we're already seeing that even today on day one, you know, or day two, I guess, coming, coming out of this with, but, you know, your point earlier about, it's all about the harness at this point, you know, Once upon a time, we were reporting on the models as they were coming out. And if you think about it, we've been talking about these harnesses and the infrastructure around it a lot more, as is everyone. And I think it really is a sign of the maturity coming in the industry. And I think this big oops from Anthropic will drive a lot of innovation out there in the open source community and maybe some closed source where people are taking ideas and trying to build their own companies off of that.
40:21And so I think we're seeing a little bit of acceleration happening right now coming out of this as people are writing clean room code based on what we've learned today. So it's an interesting moment. And I suspect as we work through this in the weeks to come, there will be some very interesting things that are popping out on GitHub and other places that we're going to want to address as well. I know for myself, I am keenly interested in going back to that implementation that we talked about a little while ago. Anyone that's listened knows that I'm into rust, especially for edge environments. And so I'm interested in how that rust line of development matures, as well as others that may be out there.
41:11So it's an interesting moment to spectate on these things. Yeah, I and maybe it's good as we as we close out here to also, yeah, encourage people to get get their get hands on. It's never been easier to get hands on with these tools and build intuition about how they work. and more is available in the open source world right now and can be under your control where you can try maybe if you're worried about security things or that sort of thing, create a sandbox environment and add in one of these agents and try some things. And if you're building agents out there, if you're AI practitioners, I think some of the just very clear guidance that we learn from all of this is, Number one, think about how you manage memory in your agents and be smart about it in that harness using kind of sharded memory and lookups.
42:13Maybe think about moving to a proactive strategy rather than a reactive strategy where you can kind of clean up memory so often every night or whatever it is, but have something working in the background that seems to be where things are headed. And also, as you're building this harness, there is very much the potential of supply chain risk within that agent harness, whether it's in the open source world or it's in the closed source world. that supply chain has risk associated with it, which is very much separate from the model risk. Which certainly there are things related to model risk and bias and blah, blah, blah, all those things.
42:55But the agent harness now has this kind of supply chain risk associated with it. So all good things to keep in mind as we interact with these tools. Well said, that's a good point to wrap up on. And looking forward to hearing folks out there on our social media channels, giving us a bit of feedback. Let us know what you're doing and how you're thinking about this as you bring it into your own development cycle and your own ideas. And if there's any really cool open source that you're seeing developing out of this, we'd love to hear about that and go take a look. Yeah, let us know. So thanks for clawing out all of the good topics, Chris.
43:41It was fun to have this discussion and hopefully leak it as soon as we can to the internet. We're going to leak it within days here. All right. Hey, we'll talk soon. Take care.
43:59All right. That's our show for this week. If you haven't checked out our website, head to practicalai.fm and be sure to connect with us on LinkedIn, X, or Blue Sky. You'll see us posting insights related to the latest AI developments, and we would love for you to join the conversation. Thanks to our partner, Prediction Guard, for providing operational support for the show. Check them out at predictionguard.com. Also, thanks to Breakmaster Cylinder for the beats and to you for listening. That's all for now, but you'll hear from us again next week.
44:33Thank you.
From the publisher
In this fully connected episode, Dan and Chris break down the Anthropic Claude Code leak, what went wrong and what it reveals about agentic systems, AI architecture, and AI safety. They also explore how the open source community is responding and why this moment could reshape how AI systems are built and secured.
Featuring:
Upcoming Events:
- Register for upcoming webinars here!




