China's National Vulnerability Database (NVDB) warned that Anthropic's AI coding tool, Claude Code, contains a "security backdoor" that can transmit sensitive user information, including location and identity, without consent Source: cna. The warning comes after security researchers discovered that Claude Code versions 2.1.91 to 2.1.196 contained hidden code using steganography to detect Chinese users by checking timezones and proxy URLs Source: arstechnica.
A Reddit user reverse-engineered the tool and found obfuscated code that altered system prompts with invisible markers to signal Chinese origins Source: tomshardware. Anthropic engineer Thariq Shihipar confirmed the tracking was "an experiment we launched in March" to prevent account abuse and distillation, and said it was removed in a July 1 update Source: cnbc. Privacy advocates called it a breach of trust, noting Anthropic's prior stance against surveillance Source: arstechnica.
Alibaba banned employees from using Claude Code starting July 10, citing backdoor risks, and ordered them to uninstall all Anthropic products in favor of its own Qoder Source: scmp. This follows Anthropic's accusation that Alibaba ran the largest known distillation attack using 25,000 fraudulent accounts Source: techcrunch. Alibaba has denied the accusation Source: thenextweb.
“The alleged backdoor could allow the software to "transmit sensitive information", including users' locations and identity-related identifiers, back to Anthropic's servers without users' consent.”
“Anthropic quickly removed a tracker secretly monitoring Claude Code users in China after a security researcher exposed the hidden code and condemned the spyware-like tracking as a 'serious breach of user trust.'”
“Whenever a proxy was detected, the code reportedly checked whether the system timezone matched Asia/Shanghai or Asia/Urumqi and inspected the proxy URL against a hardcoded list of Chinese domains and AI lab identifiers.”
“Anthropic engineer Thariq Shihipar confirmed that the tracker was added to Claude Code as an 'experiment' in March. According to Shihipar, the code 'was meant to prevent account abuse from unauthorized resellers and protect against distillation.'”
“Alibaba said all staff members would be prohibited from using Claude Code in the office starting from July 10.”
“Anthropic accused operators affiliated with Alibaba's Qwen AI lab of using nearly 25,000 fraudulent accounts to generate 28.8 million exchanges with Claude between April 22 and June 5, in what it characterized as an industrial-scale attempt to distill the model's capabilities.”