A GitHub repository with four stars. One developer. A tool that claims to strip the watermark from the most advanced AI system in the world. On August 16, 2026, Charles Hoskinson released Anthropies—a free, open-source utility to remove Anthropic's invisible watermark from Claude outputs. The market yawned. Four stars suggests zero adoption. But the data tells a different story: the repository is not the product. The real asset is the legal argument embedded in the code.
Context: The Tool and Its Trigger
Anthropic's watermark is not a simple string appended to text. It is a "key-guided tournament sampling"—a statistical bias injected at generation time. Among equally valid tokens, the model selects the one that aligns with a secret key. The result is a detectable pattern across the entire output, not a fixed tag. The European Union's AI Act, which came into effect on August 2, 2026, requires such transparency. Anthropic complied. Hoskinson responded.
Anthropies operates in three layers. Layer 1 removes the "Co-Authored-By" git trailer from code. Layer 2 strips C2PA metadata from images. Layer 3 tackles prose—the hardest target. Instead of rewriting within the same model (which would re-stamp the watermark), the tool routes the text to a third-party LLM via an "orchestrate" mode. It refuses to execute on Claude or Bard. This is a deliberate, self-imposed constraint. The code is licensed under Apache 2.0, which includes a patent grant. Hoskinson has legally sealed the tool against patent-based takedowns.
Core: The On-Chain Evidence Chain
Based on my experience auditing on-chain data during the 2022 winter stress test, I learned to look for the signal hidden in the noise. The signal here is not the code—it is the contractual argument. Hoskinson's analysis of Anthropic's terms of service is the core insight. The terms state: "Output ownership is transferred to you subject to your compliance with our Terms." Hoskinson interprets this as a condition precedent. If the user violates any term—for example, by stripping the watermark—the condition is never satisfied. Ownership never transfers. The user never actually owned the output. This is not a technical vulnerability; it is a legal one.
Tracing the ghost coins back to the genesis block. The origin of the problem is the terms themselves. Anthropic claims to give users ownership, but attaches a broad, continuously updated compliance requirement. This creates a paradox: the user must obey all terms to own the output, but the terms include prohibitions against circumvention. If the user circumvents the watermark, they breach the terms. Therefore, they never owned the output in the first place. The tool is a live demonstration of this contradiction. Every rewrite is a scar on the ledger—a record of the breach.
The liquidity pool is a mirror, not a reservoir. The tool's effectiveness reflects the market's misunderstanding. The code layer is trivially easy because code has low watermark signal. The prose layer is uncertain. The tool may degrade text quality. Hoskinson himself called it a "warning," not a utility. The real liquidity is in the legal narrative, not in the technical capability.
Contrarian: Correlation ≠ Causation
The market sees a David vs. Goliath story. A lone developer takes on a soon-to-be $2 trillion IPO. But the tool's adoption is near zero. Four stars after one day is not a movement. The contrarian angle: the tool's limited effectiveness may be intentional. If the tool worked perfectly on prose, it would be a weapon for mass content fraud. Hoskinson would face backlash. By limiting its success to code, he avoids that risk while still making the legal point.
Every transaction leaves a scar on the ledger. The legal argument itself has a scar. The "condition precedent" interpretation is not settled law. Courts may treat the clause as a promissory condition rather than a condition precedent. If so, breach of terms does not retroactively void ownership; it only gives Anthropic a right to sue. The argument is plausible but unproven. The market may overestimate its impact. Furthermore, Anthropic's silence during IPO preparation is strategic. A response would validate the attack. Silence allows the narrative to fade.
Another blind spot: the tool's reliance on a third-party LLM for rewriting. If that model is also watermarked, the output reacquires a detectable pattern. The tool does not check for that. It assumes the external route is clean. This is a fragile assumption.
Takeaway: The Next-Week Signal
The article's narrative will likely plateau unless Anthropic responds. The key signal to watch is legal: will Anthropic update its terms to explicitly state that ownership transfers unconditionally? If they do, the legal argument collapses. If they don't, the uncertainty lingers. The tool's GitHub stars are irrelevant. The real battle is in the contract language. The data suggests that the four-star warning is a smoke signal, not a fire. But smoke can still choke a sleeping giant.
Whales don't trade against the trend. The trend is toward tighter AI regulation. The tool's existence may accelerate that trend by exposing the gap between regulatory intent and contractual reality. The next week will tell us whether Anthropic breaks its silence. Until then, the ledger remains scarred, and the ghost coins wait at the genesis block.