The code didn't lie. But the terms of service did. Charles Hoskinson just dropped a grenade into the AI watermark debate, and it's not the tool you think it is. Meet Anthropies—a free, open-source script that claims to strip Anthropic's invisible watermark from Claude outputs. But here's the kicker: the real weapon isn't the code. It's the legal argument Hoskinson embedded in the README.
We didn't see this coming. I've been in the trenches since Fomo3D, watching on-chain behavior decode market manipulation. But this? This is a new kind of attack vector. Hoskinson isn't just building a bypass; he's exposing a contractual trap that could make every Claude user's 'ownership' of their AI-generated content null and void. And he's using Apache 2.0 to make sure no one can sue the fork away.
Let's rewind. The EU AI Act kicked in August 2, 2026, forcing model providers to watermark AI outputs. Anthropic responded with a clever 'tournament sampling' watermark—a statistical bias injected at generation time, not a visible stamp. But Hoskinson, fresh off a year of online feuds over 'who invented the parallel ledger,' saw an opening. He published Anthropies on August 16, 2026, with a three-layer decomposition: git trailer removal, C2PA metadata stripping, and—the hard part—prose rewriting via a non-origin LLM router.

The technical core is elegant but fragile. Layer 1 and 2 are trivial. Layer 3 is the beast. The problem? If you rewrite Claude's output using Claude itself, you just re-watermark it. So Anthropies detects the host model and refuses to run on watermarked models. It routes to an external, non-watermarked LLM instead. Clever, but it assumes such an endpoint exists and doesn't invisibly re-watermark. I've seen this pattern before—back in the DeFi Summer of 2020, when Uniswap v2's constant product formula was being reverse-engineered by copycats who relied on unverified oracles. The assumption was the same: 'the oracle will be honest.' Spoiler: it wasn't always.
But here's where the contrarian angle hits. The tool's effectiveness is wildly uneven. Code carries almost no watermark signal—Hoskinson himself admitted that in the codebase. So Anthropies works best on the least problematic use case. For prose—the very content the EU and Anthropic care about—the success rate is unknown. The code is a demo, not a solution.

The real story is the legal bomb. Hoskinson's README dissects Anthropic's terms of service: 'Subject to your compliance with our Terms, we assign to you all ownership of the Output.' The key phrase is 'subject to your compliance.' Hoskinson argues this is a condition precedent—meaning if you violate the terms (e.g., by stripping watermarks), the ownership never transferred to you in the first place. You never owned the text. You were just borrowing it.
This is a nuclear legal argument. I've seen service agreements weaponized before—during the Terra/Luna collapse, I watched how ToS loopholes let exchanges freeze withdrawals while users screamed 'my coins.' But this time, the loophole goes both ways. If Hoskinson is right, millions of Claude users have been operating under a false sense of ownership. Their AI-generated blog posts, code snippets, even medical reports—none of it legally belongs to them. And Anthropic's silence during its $2 trillion IPO roadshow? That's a tell. They can't answer without admitting the flaw.
The contrarian move: This isn't about watermarks. It's about who controls the means of verification. The AI watermark debate has been framed as 'detectability vs. privacy.' Hoskinson flips it to 'contractual ownership vs. perpetual control.' The tool is just a proof-of-concept for a much larger vulnerability: if you can't prove you own the output, you can't prove you didn't plagiarize, you can't sell it, you can't license it. The watermark isn't just a tag; it's a chain of title that the model provider still holds the key to.
I've been tracking this space since the BlackRock ETF prospectus analysis in early 2024, where I noticed a subtle clause about 'staking revenue sharing' that no one else saw. This is the same skill: reading the fine print where the real power lies. Hoskinson is doing the same. He's not an AI researcher—he's a crypto lawyer with a GitHub account. And his precedent could ripple through the entire industry.
The takeaway: Watch Anthropic's response (or lack thereof). If they stay silent, the IPO narrative gets a crack. If they sue, the legal discovery will expose the true scope of the ownership trap. If they change their ToS, they admit the flaw. This is a game of chicken, and Hoskinson just threw the steering wheel out the window. The next 90 days will determine whether 'watermark stripping' becomes a legal business or a technical footnote. But one thing is clear: the code didn't lie. The terms did. And now everyone knows.