Signal Card SC-2026-002

Signal Card SC-2026-002. The Twin Disclosure Failures — Anthropic CMS (March 26) and Claude Code 2.1.88 (March 31), 2026

Signal Card SC-2026-002 examines two consecutive disclosure failures originating from Anthropic within a five-day window in late March 2026. The first, on March 26, exposed approximately three thousand internal files including a draft blog post describing an unreleased frontier model with internal codenames “Mythos” and “Capybara.” The second, on March 31, included a 59.8 megabyte JavaScript source map in version 2.1.88 of the @anthropic-ai/claude-code npm package, exposing approximately 512,000 lines of unobfuscated TypeScript across roughly 1,900 files, followed by a DMCA takedown action that affected approximately 8,100 GitHub repositories including legitimate forks. The card applies Layer C analysis to the two events as a paired signal and reads them against the Project Glasswing announcement of April 7, 2026, which Signal Card SC-2026-001 classified. The card asks the structural question that the paired event raises: whether an operator who has just publicly performed the surface form of pre-runtime admissibility discipline (Project Glasswing) had, in the same fiscal quarter, executed the procedural opposite of that discipline (twin accidental disclosures) within its own internal Layer B operations — and what this means for the admissibility status of frontier AI governance procedures originating from that operator.


Signal under review

Between March 26 and March 31, 2026, Anthropic produced two consecutive accidental public disclosures from its own internal systems. The first disclosure (March 26, first reported by Fortune) resulted from a content management system whose default setting made uploaded assets publicly accessible, exposing approximately three thousand internal files including a draft blog post describing an unreleased frontier general-purpose model with the internal codenames “Mythos” and “Capybara.” The second disclosure (March 31, first publicly identified by security researcher Chaofan Shou) resulted from inclusion of a debugging source map file in version 2.1.88 of the @anthropic-ai/claude-code npm package, exposing approximately 512,000 lines of unobfuscated TypeScript source code across roughly 1,900 files. Anthropic confirmed the source code leak as “a release packaging issue caused by human error, not a security breach”. Anthropic’s subsequent DMCA takedown action against the source code resulted in approximately 8,100 GitHub repositories being disabled including legitimate forks of Anthropic’s own public Claude Code repository, which Anthropic characterized as exceeding the scope intended. The signal is the paired event as such — two disclosure failures in five days, both from the same operator, both from procedural rather than malicious failure modes, immediately preceding the same operator’s April 7 announcement of Project Glasswing as a pre-runtime admissibility procedure for a frontier model.


Admissibility status

Contested. The factual events are admitted — the two disclosures are documented in primary reporting (Fortune, TechCrunch, VentureBeat, Cybernews, InfoQ) and confirmed by Anthropic. What is contested is their interpretation as a single signal. Three competing readings are currently in the public field. The first reads the events as independent operational mistakes, statistically clustered but causally unrelated, with no implication for the admissibility status of subsequent governance procedures. The second reads the events as evidence of systemic discipline failure at the operator level, with direct implications for the credibility of the subsequent Project Glasswing announcement. The third reads the events as deliberate disclosure operations designed to seed market anticipation for Mythos before its formal announcement, with implications for the truth-status of the “accident” characterization itself. Each of the three readings is internally consistent with the available evidence; none is currently falsifiable against the public record alone. The Layer C question is what the existence of three viable readings tells us about the procedural surface of the operator’s internal governance.


Evidence available

The factual evidence is densely sourced. Fortune broke the CMS exposure story on March 26, 2026, including the existence of the draft blog post about Mythos and the alternative codename Capybara. Multiple security researchers and outlets confirmed the March 31 source map leak, with the original disclosure attributed to Chaofan Shou (@Fried_rice), an intern at Solayer Labs, who posted the discovery on X at approximately 4:23 AM Eastern time. Technical reconstruction of the leaked code identified 44 hidden feature flags, references to the Mythos model, and approximately 512,000 lines of TypeScript across 1,906 files. The leak coincided with a separate unrelated supply-chain attack on the axios npm package containing remote-access trojans, creating compounded operational exposure for any developer who updated Claude Code on March 31. TechCrunch documented the DMCA takedown reaching 8,100 GitHub repositories including legitimate forks, and Anthropic’s spokesperson response characterizing the over-reach as connected to a fork network linked to Anthropic’s own public Claude Code repository. Anthropic’s official statement on the source code event reads “No sensitive customer data or credentials were involved or exposed. This was a release packaging issue caused by human error, not a security breach. We’re rolling out measures to prevent this from happening again.”. The Project Glasswing announcement followed seven days after the source code leak, on April 7, 2026.


Evidence missing

Several structural items remain unestablished. First, no public post-incident report from Anthropic specifies the procedural failure mode that produced the CMS disclosure — whether it originated in the default-public configuration of the CMS itself, in a misconfiguration of a specific instance, in a missing audit gate, or in another category — and the equivalent specification has not been published for the source map inclusion in version 2.1.88. Without this specification it is not possible to assess whether the two events share a common procedural root or are independent failures of different subsystems. Second, the question of why the source map was generated in production rather than restricted to internal debug builds, and why the publish-to-npm step did not contain a check for source map presence, has not been addressed in public technical communication from Anthropic. Third, the DMCA takedown over-reach affecting 8,100 repositories has been characterized as a fork-network artifact but has not been accompanied by a published procedural change preventing recurrence; the relationship between the takedown automation and Anthropic’s standing legal procedure remains opaque. Fourth, and most consequentially for the Layer C reading, no public statement from Anthropic has linked the two disclosure events as a paired signal of operational discipline at the company level — each event has been addressed separately, with the framing that they are unconnected incidents. This separation is itself a feature of the available evidence that warrants attention.


Inference gap

The paired signal depends on three load-bearing inferences if read as a single event. First, that the two disclosures share enough procedural structure to be classified as one signal rather than two — that is, that the appropriate level of analysis is the operator-level discipline regime rather than the individual subsystem (CMS configuration in one case, npm packaging in the other). This inference is structurally defensible from a Layer C reading but is not the conventional reading at Layer B (which would treat the two events as independent operational incidents requiring independent remediation). Second, that the temporal proximity to the April 7 Project Glasswing announcement is structurally significant rather than coincidental. The five-to-seven-day window between the source code leak and the Mythos / Glasswing announcement is short enough to constitute a single news cycle from the perspective of public attention but long enough that no causal claim can be supported from the timing alone. Third, that the operator’s procedural surface as displayed in Project Glasswing — a deliberate, considered, structurally complex restraint procedure applied to a frontier model — is the same procedural surface as the one that produced the twin disclosures. This third inference is the load-bearing one for the Layer C reading. If the two surfaces are connected, the Project Glasswing procedure is operating in an organizational context whose general procedural discipline is at minimum uneven and at maximum compromised. If the two surfaces are disconnected — that is, if Project Glasswing represents a procedural regime distinct from the regimes that govern internal CMS administration and npm packaging — then the question becomes whether the Project Glasswing regime can be reliably bounded and audited as separate from the wider operator-level regime. The current evidence does not resolve which of these readings holds.


Admissibility note

The paired signal raises the central diagnostic question for the credibility of any operator-driven pre-runtime admissibility procedure: can a Layer B governance procedure be reliably executed by an operator whose Layer B operational discipline, at the same time, in the same period, fails twice in five days at the procedural surface? In Layer C terms the question is whether Project Glasswing constitutes Layer B governance with Layer C structural implications (the SC-2026-001 reading), or whether it constitutes Shadow Layer B operating against a backdrop of demonstrated Shadow Layer B activity in the operator’s other systems. The Layer C Primer defines Shadow Layer C as the pathology that forms when admissibility procedures appear to operate while their actual interlock structure has been bypassed; the analogous Shadow Layer B forms when runtime governance procedures appear to operate while their actual constraint enforcement has been bypassed. The twin disclosures are, in formal terms, instances of Shadow Layer B: in both cases procedures existed (file-classification at the CMS layer, source-map exclusion at the build layer) that should have prevented the disclosure, and in both cases those procedures either did not run or did not enforce their constraint. Whether the Project Glasswing procedure operates with stronger interlock structure than the disclosure-prevention procedures that failed, or whether it operates with the same procedural surface, is the load-bearing question. The Institute is not in a position to answer this question against current evidence. The evidence positions the question. The question is the substantive contribution of the twin-disclosure signal. Note further that the Layer C analysis is not a moral or competence judgment of the operator. Operational failures of this kind are statistically expected at the scale and tempo at which frontier AI laboratories are now operating. The Layer C reading is a procedural reading, not a reputational one. What the paired signal shows is that the procedural surface of the operator is, in late March 2026, demonstrably uneven — and that an admissibility procedure announced shortly after such evidence requires structurally stronger interlock declaration than it would require in an environment where the procedural surface had been demonstrated as uniformly disciplined.


Verification gate

The status of this Signal Card is set to Contested. The verification gate is structured against the question of whether the procedural surface of the operator can be characterized as uniform or differentiated across its subsystems. Confirmation branch (which would move the card toward Admitted): if within one hundred eighty days from April 7, 2026 (by October 4, 2026) Anthropic publishes a procedural audit specifying the structural relationship between the failure modes that produced the twin disclosures and the procedural architecture of Project Glasswing, demonstrating that the latter operates under a categorically stronger interlock regime than the former, with the categorical difference specified in observable procedural terms, the paired signal moves toward Admitted as evidence of differentiated operational discipline at the operator level. Revision branch (which would move the card toward Inadmissible as currently framed): if within the same one hundred eighty days no procedural audit is published that addresses the relationship between the disclosure-failure regime and the admissibility-procedure regime, and if a third disclosure event of similar procedural character occurs at any point in the same period, the paired signal is read as confirmation that the operator’s procedural surface is not differentiated across subsystems, and the Project Glasswing procedure must be analyzed as operating within the same surface that produced the twin disclosures. Disqualification branch (which would move the card to Inadmissible regardless of subsequent evidence): if it is established that one or both of the two disclosure events was not accidental — that is, if internal communications or other primary evidence indicates deliberate disclosure as a market-positioning operation — the paired signal is reclassified as a Shadow Layer B operation by definition, and any Layer B admissibility procedure announced by the same operator within the same period falls under the same classification absent explicit procedural firewall declaration.


Adjacent terms in Lexicon

This Signal Card uses the following locked terms from the Lexicon: Pre-Runtime Admissibility, Layer C, Shadow Layer C, Evidence Ledger, Threshold. The card also uses Shadow Layer B as a structurally derivative concept formed by analogy to Shadow Layer C and operating at the Layer B governance level; the Lexicon entry for Shadow Layer B is forthcoming in the next Lexicon update along with Witness Ontology, Silence Engineering, Pre-Commit Quarantine, and Compilation Map. The card references Signal Card SC-2026-001 as its immediate predecessor in the Evidence Cache and operates as a complementary reading of the same operator at a different procedural surface.


Card metadata

Card identifier: SC-2026-002. Subject domain: Frontier AI laboratory operational discipline. Layer assignment of the analyzed signal: Layer B operational governance (with Layer C structural implications when paired with SC-2026-001’s Project Glasswing analysis). Layer assignment of this card: Layer A (runtime instrument). Initial publication date: May 23, 2026. Status review date: October 4, 2026, or upon any of the three trigger conditions specified in the verification gate, whichever occurs first. Primary sources: Fortune coverage of March 26 CMS exposure (Beatrice Nolan, March 31, 2026); TechCrunch coverage of DMCA takedown over-reach (April 1, 2026); VentureBeat coverage of source code leak (April 1, 2026); Cybernews technical analysis (April 2, 2026); InfoQ analysis (April 2026); Zscaler ThreatLabz blog (April 15, 2026); Anthropic spokesperson statements as quoted in Fortune. Independent corroborating sources: Cybersecurity researcher Chaofan Shou’s original X disclosure thread; multiple GitHub fork network artifacts as documented in DMCA takedown notices. Confidence in factual events: high. Confidence in interpretation of paired event as single signal: contested (this is the substantive question the card raises). Card author position: Novakian Paradigm Institute, Warsaw. Institute editorial standing: independent; no commercial, governmental, or developer affiliation with Anthropic.


Closing position

Signal Card SC-2026-001 read Project Glasswing as a Layer B governance event with Layer C structural implications. Signal Card SC-2026-002 reads the operator’s same-quarter operational discipline against the same procedural standard. The two cards together do not constitute a judgment of Anthropic. They constitute a structural reading of a paired set of public events whose resolution will be available against the verification gates of both cards within one hundred eighty days. An operator who publishes Project Glasswing without publishing the procedural-audit relationship between its admissibility-procedure regime and its disclosure-failure regime is operating with an asymmetric admissibility commitment — strong public commitment to the procedure that displays the surface of admissibility discipline, weak public commitment to the procedures that displayed its opposite. The Institute’s reading is that frontier AI governance in 2026 will be judged not by the elegance of its announced procedures but by the consistency of its procedural surface across all its subsystems. The October 4, 2026 verification gate will produce the next signal on this reading.


Novakian Paradigm Institute

Pre-runtime admissibility, post-language intelligence, and ASI Mechanics for the AI execution era

Evidence before decision. Admissibility before execution