◈ Full analysis, with sources
The Claude Fable 5 System Prompt Leak: The Full Story
All the details, no hype — who leaked it, exactly what got exposed, what happened next, and the lessons AI engineers should take away
120,000
characters
1,585
lines
24
hours — that's all it took, launch to leak
On June 9, 2026, Anthropic released Claude Fable 5 along with its companion model, Claude Mythos 5, and described them as its most capable publicly available models to date. Less than 24 hours later, on June 10, 2026, a researcher well known for extracting models' internal instructions, working under the name Pliny the Liberator, published what he described as the complete Fable 5 System Prompt — on X and in his GitHub repository called CL4R1T4S.
The file he posted runs to roughly 120,000 characters spread across 1,585 lines — far longer than any comparable leak from other AI models. The incident set off a wide debate in the developer community about what modern system prompts really look like, and about how well companies can actually protect this kind of information.
1
June 9, 2026 — Launch
Anthropic releases Claude Fable 5 and Claude Mythos 5 as the first models in the new "Mythos" tier.
2
June 10, 2026 — The leak
Pliny the Liberator publishes the full System Prompt file on X and GitHub, racking up more than 700K views within a few days.
3
June 11-12, 2026 — Jailbreak claims
Pliny announces a multi-agent jailbreak technique he calls "Pack Hunt", and Anthropic disputes the claims.
4
June 12, 2026 — Access suspended
A US export-control order blocks any foreign user from accessing Fable 5 and Mythos 5, and Anthropic disables both models worldwide because nationality can't be verified on the spot.
5
June 30 – July 1, 2026 — Restoration
The restrictions are lifted, and Anthropic fully restores access to both models.
What Was Exposed, in Detail
03
-
▸
Full size: 120,000 characters, 1,585 lines, roughly 27,000 tokens, spread across 72 named sections.
-
▸
Tool definitions: 18 complete tool definitions in JSON schema format — more than half the file, give or take, is devoted to describing tools and product logic, not behavior rules.
-
▸
Copyright rule: a hard cap of 15 consecutive quoted words from any single source, and after the first quote that source is "locked" against any further quoting.
-
▸
Knowledge cutoff: end of January 2026 — clearer than the guesses that had been floating around before.
-
▸
Where the identity line sits: the sentence "The assistant is Claude, created by Anthropic" doesn't show up until line 1,351 out of 1,585 — meaning identity comes last in the file, not first.
-
▸
Safety layer: a classifier system that routes highly sensitive requests to a weaker model (Opus 4.8) instead of refusing outright.
The Debate Over the Leak's Authenticity
04
-
▸
The leak is not 100% officially confirmed by Anthropic — the company hasn't verified the file line by line.
-
▸
The jailbreak claims that came with the leak are disputed; Anthropic stated that some of the outputs shown in the claim were never actually produced by Fable 5.
-
▸
The extraction methods themselves can introduce gaps or errors into the published text, so it's best to treat the file as "mostly accurate" rather than an official, authoritative text.
-
▸
June 12, 2026: the US Department of Commerce issued an export-control order blocking any foreign national from accessing Fable 5 and Mythos 5.
-
▸
The order's scope even covered Anthropic's own employees of foreign origin.
-
▸
Since every user's nationality couldn't be verified on the spot, Anthropic chose to temporarily disable both models entirely, for all users worldwide.
-
▸
The restrictions were lifted on June 30, 2026, and Anthropic restored full access on July 1, 2026.
Lessons for Prompt Engineers
06
-
▸
A modern System Prompt isn't a "written personality" — it's a complete operating manual for the model, closer to a product spec.
-
▸
More than half of any modern prompt is tool definitions and product logic, not behavior rules or "personality".
-
▸
Always assume your prompt could be exposed one day — keep any sensitive or secret information at the application layer, not inside the prompt itself.
-
▸
Log and watch for any "silent fallback" or hidden model switch, because it can happen with no clear notice to the user.
-
▸
Safety built entirely on pattern-matching classifiers is brittle — a determined attacker can work around it, so you need extra layers of protection.
Is the leak officially confirmed by Anthropic?
▾
No. The company hasn't fully confirmed the file line by line, and some of the outputs that came with the leak are disputed by both sides.
What's the difference between Claude Fable 5 and Claude Mythos 5?
▾
Exactly the same base model, but Fable 5 has a safety classifier layer that routes sensitive requests to a weaker model (Opus 4.8), while Mythos 5 is available without those restrictions to a limited set of approved organizations only.
Why did the US government temporarily cut off access to the model?
▾
Because of an export-control order issued on June 12, 2026 barring foreign nationals from accessing the model. Anthropic couldn't verify every user's nationality on the spot, so it disabled the model globally until the order was lifted on June 30.
Can I trust the leaked file 100%?
▾
No. Treat it as "mostly accurate as of its publication date" rather than an official, authoritative text, because the methods used to extract this kind of file can produce gaps or errors.
⚠
Heads up: This content is for news and educational purposes only, and it covers a real tech incident that was widely reported. We don't recommend using any company's leaked internal instructions to bypass safety measures built to protect users.