anthropic

Hidden China tracker pulled from Claude Code after exposé

Claude News

anthropic

Anthropic has removed hidden code from Claude Code that used what the researcher who found it calls prompt steganography to flag users in China by timezone, proxy use and possible ties to Chinese AI labs. Ars Technica reported the removal after web developer Thereallo published his findings and called the tracking a serious breach of user trust.

At a glance

  • Engineer Thariq Shihipar said on X that the markers shipped in March as an experiment against unauthorized resellers and distillation, and that Anthropic had planned to remove them after stronger mitigations landed.
  • The Washington Post reported that unauthorized resellers sell access to free models for $1 a month, while pro subscriptions listed at $100 monthly change hands for as little as $12.
  • Alibaba responded last Friday by banning employees from using Claude Code, adding it to an internal list of high-risk software with security vulnerabilities, according to a memo reviewed by the South China Morning Post.

The contradiction is what gives the episode weight: a company that refused to let the US government use Claude to surveil Americans, and is suing the White House over that clash, was fingerprinting a national user base from inside its own coding agent. For developers weighing Claude Code against cheaper Chinese alternatives, undocumented client-side signals appear to be a heavier cost than the distillation they were built to catch.

Shihipar says the tracker went into Claude Code in March as an experiment

The code was not malicious, but it sent information back to Anthropic that most users would not notice, using shorthand markers that quietly flagged timezone, proxy use and a potential connection to Chinese AI labs the company has accused of distillation attacks.

Shihipar confirmed the tracker on X, saying it went into Claude Code in March as an experiment and was meant to prevent account abuse from unauthorized resellers and protect against distillation. He added that Anthropic had been meaning to take the code down for a while, having landed stronger mitigations since.

Thereallo, who found the markers while researching privacy in Claude Code, objected to the concealment rather than the function, and listed what Anthropic could have done instead: an explicit telemetry field with documentation, a visible policy, and a line in the release notes.

Hiding the signal in the system prompt makes every other privacy claim harder to believe.

Alibaba added Claude Code to a list of high-risk software last Friday

According to a memo reviewed by the South China Morning Post, Alibaba told employees last Friday that Claude Code had been found to carry back-door risks and, after a comprehensive evaluation, was added to a list of high-risk software with security vulnerabilities.

A person granted anonymity to discuss the ban told Reuters that Alibaba risks legal and compliance exposure if it is caught violating Anthropic's terms, unlike individual users who buy cheap circumvention tools to evade location blocks. Anthropic says Alibaba's Qwen advanced after the largest distillation attack ever mounted against Claude, in June.

In February, researchers at Peking University and the state-funded Chinese Academy of Sciences developed methods to detect distillation in leading large language models and found that most Chinese models showed substantial evidence of it, mostly from US systems. One Qwen model repeatedly appeared to mimic Claude and occasionally identified itself as Claude in intensive testing.

Anthropic is pushing Washington for a 12-month, possibly 24-month, lead

Anthropic has said Washington must ramp up interventions to lock in a 12-month or even 24-month lead, with penalties that could include blocking access to advanced models, chips and data centers in the US. It has joined OpenAI in urging regulators to treat distillation attacks as intellectual property theft.

Distillation is not illegal, and leading US firms do it too, but prompting Claude millions of times to accelerate a rival model breaches Anthropic's terms. At a Senate hearing, Sen. Tim Scott said export control policy needs to be clear and concise to stop China gaining a technological edge, the Washington Post reported.

The Washington Post reported that Chinese firms have matched US capabilities within months over the past year, and that a new free model from Zhipu AI beat Claude Opus 4.8, released in May, at finding computer vulnerabilities; a spokesperson told the Post distillation attacks threaten national security and undermine industry safety standards.

What replaced the markers

Shihipar described the mitigations that replaced the markers only as stronger, without specifying what they are or whether any of them run client-side. How long Alibaba's ban on Claude Code lasts has not been reported, and the measures Anthropic wants from Washington, from model access limits to chip and data center restrictions, remain proposals rather than policy.

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.