
Chinese authorities and tech giant Alibaba have raised serious security concerns about Anthropic's Claude Code, an AI-powered programming tool, after discovering hidden tracking mechanisms in the software. The tool was found to secretly identify users in China, potentially leaking sensitive data through steganographic techniques.
In late June, a developer known as "Thereallo" revealed that Claude Code contained code that modified generated text invisibly—using Unicode substitutions and date formatting—to track users Source: elespanol. China's National Vulnerability Database (NVDB) later confirmed that versions 2.1.91 to 2.1.196 had "grave hidden backdoor risks" that could send user location and identity data to remote servers without consent Source: infobae (China warning). Alibaba, after internal review, classified Claude Code as a "high-risk" tool for national security and banned its use by employees starting July 10 Source: infobae (Alibaba ban).
Anthropic engineer Thariq Shihipar defended the code as an "experiment" to combat unauthorized resellers and model distillation—a tactic where rivals train AI on competitor outputs. He stated the feature was being removed as stronger mitigations were already in place Source: elespanol. However, critics labeled the move as hypocritical for a company that previously opposed AI surveillance. The incident underscores escalating tensions between U.S. and Chinese AI firms, with Chinese alternatives like DeepSeek and Doubao gaining traction amid tighter regulation of foreign AI services Source: infobae (China warning). Alibaba itself had been accused earlier of using thousands of fake accounts to distill Claude's technology Source: infobae (Alibaba ban).
“la herramienta incorpora un mecanismo de supervisión que podría enviar a servidores remotos información sensible como la ubicación geográfica del usuario o identificadores de identidad sin consentimiento”
“Anthropic usó un método conocido como esteganografía, la ocultación de información dentro de otra, para modificar el texto generado por la IA para que pueda ser usado para rastrear a usuarios.”
“Alibaba ha determinado que Claude Code es ahora un 'software' 'de alto riesgo' para la seguridad nacional, y ha decidido prohibir su uso por parte de sus empleados a partir del próximo viernes 10 de julio”
“Según Shihipar, este algoritmo fue creado para luchar contra revendedores no autorizados y para proteger contra la destilación”