AI

Congress Just Asked Anthropic the Question It Can’t Answer.

This is the fifth chapter of Laterstack’s ongoing coverage of Anthropic’s collision with the U.S. government. Previous chapters: The Pentagon blacklisting. Silicon Valley’s amicus coalition. The hearing. The “Orwellian” injunction.

On April 2, Rep. Josh Gottheimer (D-NJ) wrote to Anthropic CEO Dario Amodei demanding an explanation for the company’s second major security breach in five days. The letter cited national security risks, questioned why Anthropic had rolled back internal safety protocols, and referenced prior intelligence indicating that a CCP-backed group had previously attempted to compromise Claude.

Five days earlier, on March 31, Anthropic accidentally published the complete source code for Claude Code, its flagship developer tool, to the npm package registry. 512,000 lines of TypeScript across roughly 2,000 files, exposed because of a misconfigured Bun source map. The company rolled back the release, but the code was already cached, forked, and spreading.

That came just three days after March 28, when Anthropic left 3,000 unpublished files in a public database, including references to its unreleased Mythos model.

Two leaks. Five days. And then the supply chain attacks started.

By April 2, trojanized GitHub repositories posing as “leaked Claude Code source” were distributing Vidar infostealer and GhostSocks malware. At least two repos hit 793 forks and 564 stars before detection. That same night, malicious versions of axios (one of npm’s most popular packages with 100+ million weekly downloads) appeared between 00:21 and 03:29 UTC. The trojanized package dropped a remote access trojan that called home to a command server within two seconds of installation. Microsoft Threat Intelligence attributed the attack to Sapphire Sleet, a North Korean state actor. Claude Code lists axios as a direct dependency. SANS called it “among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package.”

Then Anthropic made it worse. The DMCA takedown they filed against GitHub repositories sharing the code accidentally removed 8,100 repositories, including legitimate forks of Anthropic’s own public Claude Code repo. Boris Cherny, Anthropic’s head of Claude Code, said: “Our deploy process has a few manual steps, and we didn’t do one of the steps correctly.” That sentence applies to more than the DMCA.

The weaponization speed is the story. Anthropic leaked source code on a Monday night. By Wednesday morning, there were established malware campaigns with hundreds of forks exploiting the exposure. That gap is measured in hours, not weeks.

Gottheimer’s letter asks the right question the wrong way. The congressman wants to know why Anthropic rolled back safety protocols and whether the leaks create national security risks. These are legitimate questions. But framing this as “Anthropic is reckless” misses the structural problem.

Anthropic built its entire brand on being the safety-first AI company. That positioning got them blacklisted by the Pentagon, which wanted compliance, not caution. It got them sued by the government. It got them defended by Silicon Valley competitors who recognized that if the Pentagon could punish one company for prioritizing safety, every company was exposed.

Now the safety brand is cracking. Not because Anthropic suddenly became careless. Two accidental leaks in five days suggests a systemic issue in their deployment and data hygiene processes, but it’s not malice. The crack is in the narrative. The company that positioned itself as the responsible steward of dangerous technology just demonstrated, twice, that it can’t secure its own codebase.

Who benefits from this. OpenAI, which has carefully positioned itself as the Pentagon-friendly alternative. Every enterprise customer evaluating Anthropic now has a new risk factor to weigh. Defense-oriented AI startups like Edgerunner and Palantir that train on classified data in secure environments, the exact opposite of accidentally publishing source code to npm. And the Pentagon, which spent months arguing that Anthropic couldn’t be trusted with sensitive infrastructure. The leaks don’t prove the Pentagon was right about the blacklisting. But they make it harder to argue the Pentagon was wrong about the risk assessment.

Who loses. Anthropic’s IPO timeline just got more complicated. Institutional investors pricing a $350-380 billion valuation with a potential Q4 2026 listing are now asking questions about operational security that didn’t exist two weeks ago. The broader AI safety movement loses credibility because its most prominent institutional advocate just demonstrated that “safety-first” doesn’t extend to basic code deployment hygiene. And every enterprise customer running Claude in a sensitive environment is recalculating their risk exposure.

Gottheimer’s letter mentions the upcoming Mythos model. He’s worried about what happens when a more powerful model ships from a company that accidentally publishes its current model’s source code. That’s a fair concern. But the deeper question is whether “safety” was ever the right frame for what Anthropic is actually doing.

Anthropic is an AI company trying to build the most powerful models possible while convincing the public and the government that it’s doing so responsibly. The Pentagon wants those models without the safety restrictions. Congress wants the safety restrictions without the security failures. Enterprise customers want both. And Anthropic, caught between all three, keeps tripping over its own infrastructure.

“No customer data was exposed” is doing a lot of heavy lifting in Anthropic’s response. As if that’s the bar. 512,000 lines of proprietary source code, including anti-distillation defenses and unreleased feature flags, hit the public internet. North Korean state actors had a weaponized supply chain attack running within hours. GitHub repos distributing malware under Anthropic’s name racked up nearly 800 forks before anyone caught it. And the company’s position is that this wasn’t a security breach because no customer credentials leaked.

That framing ignores what actually matters. Enterprise customers aren’t just evaluating whether their data was exposed today. They’re evaluating whether Anthropic’s operational security is reliable enough to trust with tomorrow’s data. Every CISO renewing a Claude contract is now running a risk assessment that didn’t exist two weeks ago. Consumer confidence erodes the same way. If the company that markets itself as the careful one can’t manage its own deploy pipeline, what does “careful” mean?

The policy implications are worse. Congress is already asking whether AI companies can be trusted to self-regulate safety. Anthropic was the industry’s best argument that the answer was yes. Two leaks in five days, a DMCA blunder that nuked 8,100 repos, and a safety pledge quietly downgraded to “nonbinding” in the same quarter. That’s the ammunition every AI regulation advocate just got handed for free. The next time someone in Congress proposes mandatory security audits for frontier AI companies, Anthropic’s own track record will be Exhibit A.

Anthropic did not respond to a request for comment.