Round 19 Late April 6, 2026
- Source ID:
src-20260409-1ef27ff0b214 - Kind:
analysis - Scope:
shared - Origin:
community-analysis - Raw path:
sources/raw/round-19-late-april-6-2026__src-20260409-1ef27ff0b214.md - Status:
active
Summary
Community analysis document covering Claude Code architecture, internals, and leak analysis. See extracted entities and claims below.
Tags
analysis
Extracted entities
ent-20260409-ad6b72350de8cc:// Protocol (service): Deep link system enabling remote session control from phone/browser via local seent-20260419-a001b1c2d3e4Leak 1: Launch-Day Source Map (Feb 24, 2025) (issue): The first Claude Code source leak on public launch day (Feb 24, 2025). Developerent-20260419-a002c3d4e5f6Leak 2: @anthropic-ai/claude-agent-sdk Bundle (Mar 7, 2026) (issue): A distinct, previously under-documented leak via an entirely different npm packaent-20260419-a003d4e5f6a7Three-Vector Leak Pattern (concept): The systemic pattern of three Claude Code source leaks in 13 months via three dient-20260419-a004e5f6a7b8Dave Shoemaker (person): Developer who discovered the launch-day (Feb 24, 2025) Claude Code source map leent-20260419-a005f6a7b8c9Daniel Nakov (person): Developer who, on Feb 25, 2025 (day after launch), extracted the complete Claudeent-20260419-a006a7b8c9d0tengu_penguins_off (concept): Server-side GrowthBook runtime flag that shuts down Anthropic's priority API accent-20260419-a007b8c9d0e1tengu_miraculo_the_bard (concept): GrowthBook runtime flag (named after a Proust character) controlling fast-mode pent-20260419-a008c9d0e1f2tengu_amber_quartz_disabled (concept): GrowthBook runtime killswitch that disables the Remote Control (CCR bridge) featent-20260419-a009d0e1f2a3tengu_moth_copse (concept): GrowthBook runtime flag that filters memory messages from extraction prompts toent-20260419-a010e1f2a3b4firstPartyEventLoggingExporter.ts (file): Module that emits Claude Code's launch-time telemetry payload: user ID, sessionent-20260419-a011f2a3b4c5tengu_api_query messageLength Telemetry (concept): Analytics call tengu_api_query transmits messageLength — the JSON-serialized bytent-20260419-a012a3b4c5d6Telemetry Default-On Asymmetry by Endpoint (concept): Claude Code's telemetry default posture differs by inference endpoint: Anthropicent-20260419-a013b4c5d6e7Feature-Gate 60-Minute Hot-Reload (concept): GrowthBook feature gates re-poll every 60 minutes during an active Claude Code sent-20260419-a014c5d6e7f8WebSocket 147K/Week Poll-404 Reconnect (concept): The WebSocket/HTTP polling fallback for ULTRAPLAN and long-lived cloud sessionsent-20260419-a015d6e7f8a9ULTRAPLAN State Machine (running/needs_input/plan_ready/approved/rejected) (concept): The full five-state ULTRAPLAN lifecycle: running (remote cloud browser session rent-20260419-a016e7f8a9b0claude server / claude connect / claude open Commands (concept): Three CLI commands exposed by the DIRECT_CONNECT architecture:claude serversent-20260419-a017f8a9b0c1Randal Olson / n_hiraoka Qiita Analysis (document): Qiita technical analysis published by n_hiraoka (attributed Randal Olson) establent-20260419-a018a9b0c1d2Emile Michael (person): Pentagon Chief Technology Officer cited as the official voice of the Defense Depent-20260419-a019b0c1d2e3Language-Hop Transpilation DMCA Evasion (workflow): Post-leak practitioner pattern: developers use AI to transpile the leaked TypeScent-20260419-a020c1d2e3f4120K Token-Stop Configuration (pattern): Most-upvoted r/ClaudeAI post-leak configuration tip: cap context at 120K instead
Extracted claims
clm-20260419-a101d2e3f4a5[observation]: Three leak vectors rule out single-misconfiguration explanationclm-20260419-a102e3f4a5b6[fact]: First leak survived its takedown via editor undo historyclm-20260419-a103f4a5b6c7[metric]: 363 package versions shipped between leaks 1 and 3clm-20260419-a104a5b6c7d8[pattern]: Silent performance killswitch: tengu_miraculo_the_bard degrades to stale cacheclm-20260419-a105b6c7d8e9[fact]: Server-side fast-mode kill with custom reason (tengu_penguins_off)clm-20260419-a106c7d8e9f0[observation]: Per-turn messageLength telemetry enables fleet context-bloat observabilityclm-20260419-a107d8e9f0a1[fact]: Telemetry defaults by endpoint create cloud-marketplace privacy asymmetryclm-20260419-a108e9f0a1b2[constraint]: 60-minute feature-gate hot-reload makes behaviour non-reproducibleclm-20260419-a109f0a1b2c3[metric]: 98% of disconnected WebSocket sessions fail to recover via pollingclm-20260419-a110a1b2c3d4[decision]: ULTRAPLAN is fire-and-fetch, not fire-and-forgetclm-20260419-a111b2c3d4e5[observation]: DIRECT_CONNECT exposes workstation context to any authenticated cc:// URLclm-20260419-a112c3d4e5f6[observation]: Pentagon refusal precedes leaks 2 and 3 but not leak 1clm-20260419-a113d4e5f6a7[metric]: 330+ env vars span 31 categories with only ~50-60 end-user-relevantclm-20260419-a114e5f6a7b8[pattern]: Compile-time vs runtime flag asymmetry creates unlock topologyclm-20260419-a115f6a7b8c9[pattern]: AnalyticsMetadata type name is the entire safety mechanismclm-20260419-a116a7b8c9d0[fact]: ANTI_DISTILLATION_CC actively contaminates captured training trafficclm-20260419-a117b8c9d0e1[pattern]: 120K token-stop pattern derived from 200K*83% compaction thresholdclm-20260419-a118c9d0e1f2[decision]: tengu_moth_copse prevents memory-extraction infinite recursionclm-20260419-a119d0e1f2a3[anti-pattern]: Language-hop transpilation breaks DMCA derivative-work claimsclm-20260419-a120e1f2a3b4[constraint]: Managed-settings dialog is fail-closed with no 'continue with old' option
Extracted relations
rel-20260419-b001a1b2c3d4: Three-Vector Leak Pattern --[contains]--> Leak 1: Launch-Day Source Map (Feb 24, 2025)rel-20260419-b002b2c3d4e5: Three-Vector Leak Pattern --[contains]--> Leak 2: @anthropic-ai/claude-agent-sdk Bundle (Mar 7, 2026)rel-20260419-b003c3d4e5f6: Three-Vector Leak Pattern --[contains]--> Source Map Leak (March 31, 2026)rel-20260419-b004d4e5f6a7: Dave Shoemaker --[related_to]--> Leak 1: Launch-Day Source Map (Feb 24, 2025)rel-20260419-b005e5f6a7b8: Daniel Nakov --[derived_from]--> Leak 1: Launch-Day Source Map (Feb 24, 2025)rel-20260419-b006f6a7b8c9: tengu_penguins_off --[depends_on]--> GrowthBookrel-20260419-b007a7b8c9d0: tengu_miraculo_the_bard --[depends_on]--> GrowthBookrel-20260419-b008b8c9d0e1: tengu_amber_quartz_disabled --[blocks]--> Bridge Systemrel-20260419-b009c9d0e1f2: tengu_moth_copse --[blocks]--> extractMemories.tsrel-20260419-b010d0e1f2a3: firstPartyEventLoggingExporter.ts --[implements]--> Telemetry Systemrel-20260419-b011e1f2a3b4: tengu_api_query messageLength Telemetry --[related_to]--> firstPartyEventLoggingExporter.tsrel-20260419-b012f2a3b4c5: Telemetry Default-On Asymmetry by Endpoint --[related_to]--> firstPartyEventLoggingExporter.tsrel-20260419-b013a3b4c5d6: Feature-Gate 60-Minute Hot-Reload --[implements]--> GrowthBookrel-20260419-b014b4c5d6e7: WebSocket 147K/Week Poll-404 Reconnect --[supports]--> ULTRAPLANrel-20260419-b015c5d6e7f8: ULTRAPLAN State Machine (running/needs_input/plan_ready/approved/rejected) --[implements]--> ULTRAPLANrel-20260419-b016d6e7f8a9: claude server / claude connect / claude open Commands --[implements]--> cc:// Protocolrel-20260419-b017e7f8a9b0: Randal Olson / n_hiraoka Qiita Analysis --[summarizes]--> Three-Vector Leak Patternrel-20260419-b018f8a9b0c1: Emile Michael --[related_to]--> Claude Mythos Previewrel-20260419-b019a9b0c1d2: Language-Hop Transpilation DMCA Evasion --[caused]--> DMCA Takedown (8,100 repos)rel-20260419-b020b0c1d2e3: 120K Token-Stop Configuration --[derived_from]--> autoCompact.ts