Fable 5.1 Prompt Leak: Pliny’s 270K Character Claim Doesn’t Hold Up
Discrepancies in character count and privacy concerns fuel discussions on AI model leaks

Jailbreak researcher Pliny the Liberator posted what he described as the complete system prompt for Anthropic's Claude Fable 5.1 within roughly an hour of the model's September 1, 2026 launch, uploading the document to his public CL4R1T4S repository on GitHub and calling it "270,000+ characters" in a post on X.
A subsequent independent read of the same file, published by AI-education outlet explainx.ai, measured it at closer to 180,000 characters — about 27,000 words — not the 270,000 figure that spread across aggregators and social media in the hours after the leak.
The gap matters for how the story gets read. Pliny's file, titled Claude-Fable-5.1.md, is the same category of artifact as a leak he posted in June for the earlier Claude Fable 5: a long block of instructions covering tool use, search and citation rules, safety-classifier behavior, and — the section driving most of this week's attention — guidance on how Claude's memory feature should file and apply information it has learned about a user across conversations.
That last point produced a second, separate claim: that the leak exposed "private user memories." Explainx.ai's review found no such content. What the file contains is Anthropic's own policy language for the memory feature — instructions telling Claude not to log sensitive categories such as health conditions or sexual orientation about a person, for instance — rather than actual stored data belonging to any real user. The outlet drew a direct contrast with a confirmed data-exposure bug reported in July, in which a flaw in Claude's web-fetch tool let an attacker pull a real user's stored personal details through crafted links. No comparable user-data exposure has been documented in this case.
Fable 5.1 is part of Anthropic's Mythos-tier model family. Its predecessor, Fable 5, was suspended for three weeks in June under a U.S. export-control order before access was restored on July 1. Anthropic has not issued a statement on the new leak.
The pattern is not new. Pliny has published system-prompt extractions for OpenAI's and Zhipu's models in recent months using similar methods, and Anthropic's own account of prior red-teaming has treated leaked prompt text as a known, low-severity category — distinct from a breach of user data or account access. Anthropic is expected to update the claude.ai prompt again with future model releases, a cycle researchers say makes repeat leaks likely rather than exceptional.





















