Breaking: August 16, 2026 — 14:32 UTC — Charles Hoskinson just released a free, open-source tool called Anthropies that claims to strip Anthropic’s AI watermark from Claude outputs. The GitHub repo has 4 stars. The code is 48 hours old. The legal argument baked into the README is more dangerous than the code itself.
This is not a tool. This is a contract-law attack dressed in Python.
Context: The Watermark That Was Meant to Protect You
Anthropic deployed its invisible watermark in early August 2026, right as the EU AI Act’s transparency provisions kicked in. The watermark uses key-guided tournament sampling — a statistical bias injected at token generation time. It’s not a hidden string; it’s a fingerprint in the probability distribution. Traditional synonym-substitution doesn’t touch it.
Hoskinson’s response: a three-layer open-source kit that he calls Anthropies — a play on “chaff” and “Anthropic.” The layers:
- Layer 1: Co-Authored-By — Strips git trailer metadata from code snippets. Deterministic, zero text alteration.
- Layer 2: C2PA Image — Re-encodes image metadata to remove C2PA credentials. Straightforward.
- Layer 3: Prose — The hard part. Routes Claude output through a non-origin LLM (e.g., GPT, Gemini) to rewrite the text, breaking the statistical watermark.
The tool’s architecture reveals a critical design constraint: it refuses to rewrite inside the same model family. If you ask it to re-encode a Claude output using Mistral, it works. If you try to use Claude itself to rewrite, it detects the origin and blocks the operation. This is technically honest — but it also means the tool is dependent on third-party API availability.
Core: The Code Is the Bait, the Contract Is the Trap
Let’s be clear about what this tool actually does well. Code carries almost no watermark signal — syntax constraints leave little room for statistical deviation. The tool’s demo on code is a cherry-pick. The real test — natural language prose — is what the repo itself calls “the difficulty layer.” No independent benchmarks exist. The GitHub star count (4) tells you exactly how many people have verified the claims.
But the technical layer is not the story. The story is in the legal framing.
Hoskinson’s X thread (August 16) zeroes in on a single phrase in Anthropic’s Terms of Service: “We assign to you all our rights, title, and interest in and to the Output. This assignment is subject to your compliance with our Terms.”
His interpretation: “subject to your compliance” is a condition precedent. If you violate the Terms — for example, by stripping the watermark — then the ownership assignment never triggers. The output was never yours. You’ve been using a borrowed asset.
This is a lawyer’s reading of a contract, not a developer’s. And it’s where the real weapon lies.
I’ve been in this game since 2017, when I audited the Parity multi-sig vulnerability and learned that open-source raids against centralized infrastructure rarely succeed without a legal flank. Hoskinson just built that flank. He licensed the tool under Apache 2.0 — which includes a patent grant — meaning Anthropic can’t use patent claims to kill forks. The tool is legally shield-walled.
Contrarian: The Tool Is a Trojan Horse for Cardano’s Narrative
Here’s what the market is missing: Anthropies is not about watermarks. It’s about Hoskinson repositioning Cardano’s brand from “slow, academic blockchain” to “the anti-censorship layer for AI.”
Look at the timing. Hoskinson has spent 2026 in a running battle with Ethereum advocates over technical credit. He’s been accused of being a troll. Now he’s pivoted to a fight that’s mainstream — AI governance — and he’s using the same toolkit: open-source code + legal argument + personal brand.
The tool itself is a demonstration asset. The real product is the narrative: “Cardano founder is the one who stood up to Big AI.” This is a classic playbook from the 2020 DeFi Summer, where I saw Yearn.finance use technical audits to attract institutional attention. Hoskinson is doing the same for AI policy.
But the contrarian truth: the tool’s effectiveness is inversely proportional to the market’s perception. The 4 stars suggest zero organic adoption. The legal argument is untested — no court has ruled on “condition precedent” in AI ToS. And the tool’s dependence on third-party LLM APIs means Anthropic could simply cut off access to those models via API policy changes.
The real risk is that the tool becomes a liability: if it’s used to flood the internet with undetectable AI-generated content, Hoskinson gets blamed, and the Cardano brand takes a hit. The same “David vs. Goliath” narrative that attracts attention can also attract regulatory scrutiny.
Takeaway: Watch the Terms, Not the GitHub Stars
Hoskinson’s move is a masterclass in asymmetric warfare. The code is a decoy. The real weapon is the contract interpretation. If even a single law professor cites his argument in a paper, it will force AI companies to rewrite their ToS — and that rewrite will be a tacit admission that the original terms were flawed.
For traders: This is not an ADA buy signal. The tool has zero impact on Cardano’s fundamentals. But it is a narrative seeding event. If the AI watermarm debate escalates, Hoskinson’s positioning as the “anti-censorship founder” will stick. That’s a six-month narrative, not a 48-hour pump.