Four stars on GitHub. That’s the current state of Charles Hoskinson’s latest crusade against the AI establishment. A tool called Anthropies, released on August 16, 2026, promises to strip invisible watermarks from Anthropic’s Claude outputs. The media narrative is already writing itself: David vs. Goliath, open-source defiance against a $2 trillion IPO-bound giant. But I’ve seen this play before. In 2017, I watched a team raise $30 million on a smart contract that had an integer overflow you could spot with a cursory read. The code was clean—the marketing was the bug. Here, the code is a distraction. The real story is buried in a single line of legalese: “subject to your compliance with our Terms.”
Context: The Watermark That Binds
Anthropic’s watermarking isn’t a gimmick. It’s a response to the EU AI Act’s transparency mandate, which took effect August 2, 2026. The technical implementation is sophisticated: a key-guided tournament sampling algorithm that injects a statistical pattern into the output at generation time. This isn’t a visible stamp or a metadata tag. It’s a probabilistic fingerprint that survives rephrasing, punctuation changes, and even partial edits. The goal is to allow machine detection of AI-generated text without degrading the user experience. It’s elegant, effective, and—according to Hoskinson—illegitimate.
Hoskinson’s countermove is Anthropies, a free, open-source tool licensed under Apache 2.0. The tool’s architecture is a three-layer decomposition: Layer 1 strips git trailers (co-authored-by tags), Layer 2 re-encodes C2PA image metadata, and Layer 3—the hard one—attempts to scrub prose by routing the text through a third-party LLM that doesn’t apply watermarks. The code is already live, but the GitHub repository has exactly four stars. That’s not a viral launch. It’s a signal flare.
Core: The Code That Proves Nothing
Let’s dissect the tool’s technical claims. The third layer, dubbed “non-origin rewrite,” is the critical piece. The insight is correct: if you ask Claude to rewrite its own watermarked output, you’ll just stamp a new watermark. So Anthropies detects the host model and refuses to execute on it. It routes the text to a different model—say, a local Llama or an API endpoint that doesn’t watermark. The problem is that this approach has a fundamental trade-off: fidelity. Any rewrite changes the text’s style, vocabulary, and tone. The tool doesn’t report success rates or text preservation metrics. The demonstration case is code, not prose. Code has minimal syntactic variation—it’s almost watermark-proof by nature. Hoskinson chose the easiest problem to solve.
From my experience auditing DeFi protocols in 2020, I learned to always check the honeypot before the profit. Here, the honeypot is the assumption that routing through a third-party model is a cure. What happens when that third-party model itself starts watermarking? Or when the EU expands its detection requirements to all general-purpose AI models? The tool’s dependence on an external, watermark-free oracle is its single point of failure. It’s not a permanent solution; it’s a temporary workaround that relies on the goodwill of other providers.
Contrarian: The Legal Trap Is the Real Payoff
The media is framing this as a technical battle. It’s not. The real weapon is the terms of service analysis Hoskinson embedded in his announcement. Anthropic’s ToS state that output ownership is transferred “subject to your compliance with our Terms.” Hoskinson interprets this as a condition precedent: if you violate the terms (e.g., by stripping watermarks), ownership never transferred. This means that every Claude user who has ever used the output for commercial purposes may be sitting on unlicensed content. The legal community is silent so far, but the implications are seismic.

I’ve seen this legal strategy before, though in a different context. In 2022, during the Terra Luna collapse, I shorted the entire ecosystem based on a simple observation: the algorithmic stability mechanism had a critical flaw that made it mathematically impossible to survive a bank run. The institutional narrative was “decentralized central bank.” The reality was a house of cards. Here, the narrative is “user-owned output.” The reality is that the fine print may have never granted ownership at all. Hoskinson’s tool isn’t about removing watermarks; it’s about proving that the watermarks were never yours to remove.

Risk is the only currency that never depreciates. The risk here is not that Anthropic will sue Hoskinson—they’re too busy preparing an IPO. The risk is that the entire premise of “AI-generated content ownership” rests on a contractual foundation that may be intentionally shaky. If this argument gains traction in legal circles, every AI company will be forced to rewrite their ToS, and the cost of compliance will ripple through the entire industry. The tool itself is a sideshow.
Takeaway: Watch the Courts, Not the Stars
The GitHub stars don’t matter. The four-star count is a red herring. The real signal is the legal argument. If Hoskinson’s interpretation is even partially validated by a court or a regulatory body, it will reshape the entire AI content ecosystem. The question is not whether Anthropies works—it’s whether the condition precedent is a legitimate legal construct. The answer will determine if the watermarks are a security feature or a surveillance trap.
Volatility isn’t the enemy; it’s the only friend who pays. In this case, the volatility is in the legal narrative, not the price of ADA. I’m not buying the token. I’m buying the idea that the next big crypto-AI battle will be fought in courtrooms, not on GitHub. The tool is a proof of concept for a revolution that hasn’t started yet. When it does, the real alpha will be in understanding the contract, not the code.
Speculation ends where strategy begins. My strategy is simple: monitor the legal databases, not the star counts. The first amicus brief citing Hoskinson’s argument will be the real launch. Until then, the tool is a statement. The statement is the trade.