anthropic
Hidden tracker in Claude Code pulled after exposure
Promtime
anthropicAnthropic has removed hidden code from Claude Code that quietly flagged three attributes of a user: timezone, proxy use and possible connection to Chinese AI labs. The markers were found by a web developer known as Thereallo, who called the tracking a "serious breach of user trust", as reported by Ars Technica.
At a glance
- The flags relied on what Thereallo described as prompt steganography: shorthand markers hidden in plain sight inside the system prompt, sending signals back to Anthropic that most users would never detect.
- The Washington Post found unauthorized resellers offering access to free models for $1 a month, and pro subscriptions that can cost $100 monthly selling for as little as $12.
- Alibaba barred employees from using Claude Code for work last Friday and added it to a list of high-risk software, citing back-door risks, according to a memo reviewed by the South China Morning Post.
The disclosure appears to cut against Anthropic's own positioning on surveillance, which the company has built into a public fight with Washington. Hiding a fingerprinting signal inside the system prompt of a tool that reads local code and runs commands likely costs more in developer trust than the enforcement it bought, at a moment when users across the industry weigh model capability against price.
Thereallo says hiding the signal in the system prompt undermines other privacy claims
Thereallo's blog said the code was not malicious but called it a weird choice for a developer tool that asks for trust. If the client wants to detect custom API gateways, the blog argued, it can say so plainly, send an explicit telemetry field with documentation, make the policy visible and put the behavior in release notes.
The researcher wrote that coding agents already live on the wrong side of a scary boundary, since they can inspect code, run commands, install packages, edit files and push commits on a local machine. Most users were likely not affected, but Thereallo said the feature mostly punishes normal developers doing weird but legitimate things, who are easier to fingerprint.
Shihipar says the March experiment targeted unauthorized resellers and distillation
Anthropic engineer Thariq Shihipar confirmed on X that the tracker was added in March as an experiment, and said it was meant to prevent account abuse from unauthorized resellers and to protect against distillation. He said the company had been meaning to take the code down for a while, because engineers landed stronger mitigations since then.
An Anthropic spokesperson told the Post that distillation attacks by Chinese labs pose a serious threat to national security and undermine AI safety standards across the industry, and that the company works with other labs, government and partners on shared solutions. Anthropic has separately refused to let the US government use Claude to surveil US users, and has sued the White House over the clash.
A free Zhipu AI model beat Claude Opus 4.8 at finding vulnerabilities
Chinese firms have consistently matched the capabilities of US models within months over the past year, The Washington Post reported. Most recently, a new free model from Zhipu AI was better at finding computer vulnerabilities than Anthropic's Claude Opus 4.8, released in May.
In February, researchers at Peking University and the state-funded Chinese Academy of Sciences developed methods to detect signs of distillation in leading large language models, and found that most Chinese models showed substantial evidence of distillation, primarily of US models, the Post reported. One of Alibaba's Qwen models repeatedly appeared to mimic Claude that month and sometimes identified itself as Claude in intensive tests.
Anthropic has claimed that the Qwen model was advanced after the largest distillation attack ever carried out on Claude, in June. Distillation is not illegal and leading US firms do it too, though prompting models like Claude millions of times to quickly advance Chinese models violates Anthropic's user terms.
What Anthropic wants from Washington
Anthropic has joined OpenAI in urging the US to treat distillation attacks as intellectual property theft, and argues Washington should be able to block access to advanced models, chips and data centers in the US to lock in a 12- or possibly 24-month lead.
At a Senate hearing, Sen. Tim Scott (R-S.C.) said export control policy must be clear and concise, the Post reported. Alibaba could face legal and compliance exposure if caught violating Anthropic's terms, unlike individual users who buy cheap circumvention tools, a source granted anonymity told Reuters.
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
We only use your name and avatar from Google. We never store your email address.
