The Anthropies Audit: Why Hoskinson’s Watermark Stripper Is a Legal Feint, Not a Technical Coup

CryptoRover
AI

The ledger doesn’t lie. Neither does a GitHub repo with four stars. On August 16, 2026, Charles Hoskinson dropped a repository named “Anthropies” — a play on the Greek word for “human” and a direct jab at Anthropic. The tool claims to strip the invisible watermark Anthropic embeds in Claude outputs. The public sees the spark: a blockchain heavyweight slapping a $2 trillion IPO-bound AI giant. I track the fuel lines. This is not a story about code. It is a story about contracts, compliance arbitrage, and a founder using open-source lawfare to reshape his own brand narrative.

Context: The Regulation That Backfired On August 2, 2026, the EU AI Act’s transparency provisions took effect, mandating that AI-generated content be machine-detectable. Anthropic responded by deploying a “key-guided tournament sampling” watermark — a statistical pattern injected during generation, not a post-hoc string. The watermark is elegant: it biases token selection among equally likely candidates, leaving a detectable but invisible fingerprint. Hoskinson, never one to miss a regulatory contradiction, launched Anthropies within 14 days. The tool is a three-layer deconstruction: Layer 1 removes git “Co-Authored-By” trailers (deterministic, trivial). Layer 2 strips C2PA image metadata via re-encoding. Layer 3 — the “Prose” layer — attempts to remove the statistical watermark by routing the text through a non-Anthropic LLM for rewriting. The repo is licensed under Apache 2.0, includes a legal argument about Anthropic’s terms of service, and currently has four stars on GitHub.

The Anthropies Audit: Why Hoskinson’s Watermark Stripper Is a Legal Feint, Not a Technical Coup

I have spent the last decade auditing smart contracts, not AI models. But the methodology transfers. In 2017, I dissected an ICO that claimed to have a multisig escrow. The contract had no multisig. I published the proof. The token dropped 40% in 48 hours. In 2020, I built a Python simulation to stress-test Compound’s liquidation thresholds. My report predicted a cascade. It was cited by three hedge funds. The pattern is the same: find the structural weakness, reveal the gap between promise and mechanism. Anthropies is no different. The tool itself is a technical sideshow. The real vulnerability lies in a single sentence in Anthropic’s Terms of Service: “Subject to your compliance with our Terms, we assign to you all our rights, title, and interest in and to the Output.”

Core: The Systematic Teardown Let me dissect the technical architecture first — because it reveals the tool’s true limits. The watermark is not a string you can regex away. It is a statistical distribution spread across the entire output. Tournament sampling ensures that the model’s choice between two equally good tokens is guided by a secret key. The result is a text that, when analyzed by a detector with the same key, yields a high-confidence AI origin score. Post-processing — synonym replacement, punctuation changes — barely shifts the distribution. The only reliable way to remove such a watermark is to change the distribution itself. That is what Hoskinson proposes: reroute the text through a different LLM (e.g., GPT-4) that does not inject the Anthropic watermark. The target model rewrites the text, introducing its own statistical fingerprint, which overwrites the original. In theory, it works. In practice, the rewriting degrades fidelity. The tool cannot guarantee that the output remains semantically identical. More critically, it assumes the target model’s API is available, uncensored, and free of its own watermark. That is a brittle assumption. The repo is pre-alpha. The code is not audited. The prose layer is explicitly labeled “difficult” by Hoskinson himself. The demonstration examples are heavily skewed toward code, where the watermark has no foothold because code offers almost no synonymic variation. The tool’s success rate on natural language is unknown. No independent verification exists. The four-star GitHub count is not a proof of failure — it is a proof of infancy.

Now, the legal core. Hoskinson’s reading of the Anthropic ToS is a classic contract-law maneuver. The phrase “subject to your compliance with our Terms” before the ownership assignment is, he argues, a condition precedent. If a user violates any term — for example, by using the output for commercial purposes without a paid plan, or by attempting to remove the watermark — then the condition fails, and the ownership never transfers. The user never owned the output. This is not a radical interpretation. Contract law routinely distinguishes between a promise (I will give you ownership) and a condition (I will give you ownership only if you do X). The ambiguity is real. If a court adopts Hoskinson’s reading, millions of Claude outputs — including those used in commercial products, research papers, or legal filings — could be subject to retroactive ownership challenges. Anthropic’s marketing says “you own your outputs.” The fine print says “unless you break a rule.” The tool is a demonstration of that gap. It is not a technical exploit. It is a legal exploit.

The Anthropies Audit: Why Hoskinson’s Watermark Stripper Is a Legal Feint, Not a Technical Coup

Hoskinson understands this. He released the code under Apache 2.0, which includes an express patent grant. Even if Anthropic tried to sue for patent infringement on the watermark removal method, the license would protect forkers. The code is designed to be unstoppable. The legal argument is designed to be viral. The tool itself is a prop. The real product is the narrative.

Let me quantify the structural weaknesses. The tool’s dependency chain is exposed: (1) It requires an alternative LLM API that is not controlled by Anthropic. (2) That API must not itself inject a watermark that the user cannot remove. (3) The rewriting must preserve the original intent and style. (4) The user must trust that the third-party API does not log or abuse the text. This is a four-layer stack of trust assumptions. In decentralized finance, we call that a “centralization vector.” The tool is not self-sovereign. It is a proxy that shifts trust from one centralized entity to another.

Contrarian: What the Bulls Got Right I have to pause and acknowledge the counter-argument. The crypto community is cheering this as a stand against AI censorship. They are not entirely wrong. The EU AI Act’s watermark requirement was intended to increase transparency, but it creates a single point of failure — a universal detection mechanism that could be used to filter, blacklist, or police content. A tool that breaks that mechanism is a tool for free speech, even if it is imperfect. The four-star repo is a start, not a finish. If the tool gains traction, it could be forked and improved by a community. The Apache 2.0 license ensures that cannot be killed by a lawsuit. The legal argument about ToS conditions precedent is genuinely novel. If it holds — and I give it a 30% chance of being adopted by any court — it would force every AI company to rewrite their contracts. That is a meaningful outcome. The bulls also correctly note that Hoskinson is not seeking profit. He is spending his own time and reputation to challenge a dominant player. That is a legitimate form of public-interest activism.

But the bulls overestimate the tool’s technical readiness. They treat the “remove watermark” claim as a solved problem. It is not. The prose layer is speculative. The tool has no benchmark against a known watermark. The four-star repo is not a measure of adoption — it is a measure of novelty. The legal argument, while clever, is untested. Anthropic could respond by simply changing the ToS language to “We hereby assign all rights to the Output, regardless of your compliance with these Terms, subject only to applicable law.” That would nullify the condition precedent argument. The response is trivial. The window for this legal attack is narrow. The bulls are also ignoring the reputational risk. If the tool is used to generate fraudulent content — fake news, impersonation, spam — and Hoskinson is identified as the creator, the blowback could damage Cardano’s brand. The association is inevitable. He is the founder. Every action he takes is a Cardano action, whether he intends it or not.

Takeaway: The Tool Is a Thermometer, Not a Thermostat The ledger doesn’t forgive. Anthropies is a signal. It measures the temperature of the AI-crypto regulatory nexus. It does not set the temperature. The code is a proof of concept that will either be forked into a useful tool or abandoned in a week. The legal argument is a talking point that will either influence policy or be ignored. The real value is in the conversation it forces: who owns the output of a machine that learns from the entire internet? The answer is not in the code. It is in the courts, the legislatures, and the terms of service. Hoskinson is a provocateur, not a savior. He is right to point out the contradiction. But he is not offering a solution — he is offering a mirror. The user base is small. The repo is cold. The hype is hot. The data speaks. Are you listening?