Anthropic pulled a hidden anti-distillation system from Claude Code in 2.1.198

The July 1 release of Claude Code, version 2.1.198, removed a covert steganographic system built to protect against model distillation. Anthropic engineer Tariq Shihipar said the experiment started in March to keep competitors from copying Claude's answers. The team reinforced its defenses since then and had planned to switch the mechanism off anyway.
Around the same time, China's national vulnerability database (CNVDB) urged developers to uninstall Claude Code. In a WeChat post, the agency said the built-in monitoring collected users' location and identity and shipped the data to remote servers. CNVDB called it "backdoor code" and recommended an urgent audit of versions 2.1.91 through 2.1.196.
Asked by The Register whether the mechanism was disclosed in the terms of service, Anthropic pointed to Shihipar's statement, which doesn't address the question.
Related stories
- China's MIIT flags a backdoor in Claude Code versions 2.1.91 through 2.1.196
- Alibaba bans Claude Code internally
- Insiders say Anthropic oversold the rogue AI scare
- Federal Register searched comments with Alibaba's Qwen
- Anthropic's Jack Clark wants a kill switch others can check
- Amodei wants a speed limit on AI self-improvement
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
