The market’s attention is split between ETF flows and AI governance. Bitcoin tests $68k, and everyone is watching the ETH/BTC ratio. But the real signal is a crusty GitHub repo with four stars. Charles Hoskinson just dropped a tool called Anthropies. It strips Anthropic’s watermark from Claude outputs. It’s not a breakthrough. It’s a warning. And the warning is about ownership, not technology.
Hoskinson’s move lands at a specific regulatory junction. The EU AI Act’s transparency requirements kicked in on August 2, 2026. Anthropic rolled out an invisible watermark using tournament sampling—a selection bias mechanism that embeds a detectable statistical pattern into the text. It’s elegant. It’s hard to remove. And it’s now the target of a personal crusade from the Cardano founder.
Anthropies is a free, open-source tool under Apache 2.0. It attacks the watermark in three layers: Layer 1 strips git co-authored trailers, Layer 2 removes C2PA image metadata, and Layer 3—the hard one—rewrites prose through a non-origin LLM. The key insight: rewriting inside the watermarked model re-applies the watermark. So the tool routes to a third-party model, assuming that endpoint doesn’t add its own watermark. That’s a big assumption.
We didn’t expect a code repository to become a legal battering ram. But that’s where we are. Hoskinson’s real weapon is a contract law argument. Anthropic’s ToS states that output ownership transfers “subject to your compliance with our Terms.” Hoskinson reads this as a condition precedent—if you violate the terms (e.g., by stripping the watermark), ownership never transferred. This cuts to the core of the AI output ownership debate. If the argument holds, millions of Claude users may not own their text.
Let’s get technical. The watermark uses tournament sampling: among equally likely tokens, it picks the one that aligns with a secret key. This creates a statistical signature across the entire text. Traditional post-processing—synonym swaps, punctuation tweaks—doesn’t work. The signal is distributed. Hoskinson’s approach is a “non-origin rewrite”: feed the text to a different LLM, let it rephrase, and hope the new distribution drowns the old signal. That works for code, where syntax is rigid and watermarks have little room. For prose, it’s uncertain. The tool admits prose is the “difficult layer.”
Based on my own audits of LLM output pipelines, the most overlooked friction is the dependency on external routing. Anthropies cannot operate inside the watermarked model’s ecosystem. It must call an external LLM. That external LLM may change its API, add its own watermark, or simply refuse. The tool’s technical honesty is admirable—it’s clear about its limits—but it also signals that the tool is not a silver bullet. It’s a proof of concept.
The code is what reveals the real story. Hoskinson chose to demonstrate the tool on code examples because code carries almost no watermark signal. The syntactic structure leaves little room for statistical bias. So the tool works best where the problem is smallest. For natural language, the effectiveness is unknown. This selection bias matters. It suggests Hoskinson is not confident about prose performance, but he’s banking on the legal narrative to carry the weight.
Yields don’t lie, but contracts do. The contract on AI output is about to be rewritten. The contrarian angle here is that the tool’s legal impact will outlive its technical utility. Anthropic is preparing for a $2 trillion IPO. They will not respond to a four-star GitHub repo. But Hoskinson’s “condition precedent” reading is a live grenade. If legal scholars pick it up, it could force every AI company to clarify their ownership language. The cost of compliance revision is real. The market hasn’t priced that in.
From a market perspective, this event is pure narrative. ADA did not move. The tool has no token, no fee, no liquidity. The liquidity is in the attention. Hoskinson is repositioning himself from “Cardano founder” to “AI governance critic.” That brand shift may have downstream effects: developers who care about AI sovereignty might look at Cardano’s smart contract layer. But that’s a long shot. The immediate market impact is zero.
Risk assessment: the tool is safe to use—no fund loss, no private key exposure. The risks are conceptual. If the tool is used for large-scale content fakery, Hoskinson’s reputation could suffer. The legal argument, if adopted, could backfire: AI companies will simply tighten their ToS, making ownership even more explicit and less contestable. The tool’s design also creates a dependency on third-party LLMs that could be cut off. The single point of failure is Hoskinson himself. He controls the repo. Without a community fork, the tool dies if he loses interest.
Ecosystem implications: the tool sits at the intersection of AI and crypto, but it doesn’t integrate with any blockchain. It’s a standalone Python script. However, the Apache 2.0 license includes a patent grant, which prevents Anthropic from using patents to block forks. This is a deliberate legal shield. It turns the tool into a public good that cannot be legally suppressed. That’s a pattern: “open source + legal argument + technical tool” as a template for activism. It may be replicated.
Regulatory takeaway: the EU AI Act assumes watermarks are detectable and persistent. Anthropies challenges that assumption. If the tool gains traction, regulators may need to mandate more robust watermarking or explicitly criminalize removal. That would be a net negative for the crypto ethos of permissionless innovation. But for now, the tool is legal. The EU hasn’t regulated user-side removal.
The chart whispers; the order book screams. The order book for this event is silent. No volume, no volatility. The real action is in the legal briefs and the X threads. Hoskinson is betting that the court of public opinion is more powerful than the court of code. He may be right. But the market will not care until the contracts change.
Takeaway: This tool will not stop Anthropic’s IPO. It will not shift ADA’s price. It will not make your AI-generated content undetectable. What it will do is accelerate the conversation about who owns the output of a machine. The next bull run will price in regulatory clarity. This is the opening salvo. Watch the contracts, not the code.

