Anthropic removes covert tracking from Claude Code

Anthropic is removing the steganographic code added to Claude Code in March to identify competitors attempting to copy its models. Engineering team member Tarik Shihipar confirmed the fix arrives in the July 1 release, and the pull request is already merged.
The code monitored the base URL variable. If redirected to a proxy, it checked the timezone and host against a list of known Chinese AI labs, resellers, and gateways. The list was hidden via XOR and base64, and classification was encoded using invisible Unicode markers in the system prompt.
According to Shihipar, the experiment targeted distillation and reseller abuse, but the team has since implemented stronger protection measures. Previously, leaked code revealed an ANTI_DISTILLATION_CC flag, which injected fake tool data to poison training sets for third-party models.
Related stories
- Former Anthropic engineer says the company loosened safeguards for enterprise deals
- Alibaba bans Claude Code internally
- Researcher identifies hidden tracking in Claude Code
- Anthropic will bill again for requests its safeguards block
- Anthropic's 225 bug finds, one attack in the wild
- Fable 5.1 refuses the knife but heats a gas can anyway
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
