Examination of the Zig-level binary attestation system that cryptographically proves requests come from official Claude Code clients, and its role in the OpenCode legal disputes
← Back to The Claude Code Source Leak: fake tools, frustration regexes, undercover mode
The debate centers on whether Claude Code’s cryptographic attestation effectively prevents third-party clients like OpenCode or if Anthropic primarily relies on behavioral profiling and delayed enforcement to flag unauthorized subscription usage. While some users question the spoofability of Bun-based binary signing, others suggest that the current API leniency is a tactical move to avoid providing an "oracle" that would help attackers refine their bypass methods. Ultimately, the consensus suggests that software-level protections are increasingly fragile, as LLM-powered reverse engineering tools make non-hardware-assisted attestation nearly impossible to maintain against determined developers.
10 comments tagged with this topic