China's MIIT Flags 'Backdoor' Risk in Anthropic's Claude Code
TL;DR
- Anthropic confirmed the tracking code was intentional, designed to catch unauthorized resellers and block model distillation, per an engineer's public X post.
- Anthropic told SCMP that Chinese users named in the advisory were not licensed to use Claude Code, framing the CNVD filing as geopolitically motivated.
- Anthropic removed a separate steganography system in v2.1.198 on July 1, days before the CNVD filing, per The Register, suggesting prior awareness of the exposure.
China's Ministry of Industry and Information Technology just made last week's company-level Alibaba ban look small. Its National Vulnerability Database, per CNBC's reporting, issued a formal 'backdoor' advisory naming Anthropic's Claude Code versions 2.1.91 through 2.1.196, alleging the tool contains a built-in monitoring mechanism that transmits users' geographic location and identity-related identifiers to remote servers without consent. Chinese organisations were told to uninstall the affected versions or upgrade, and to tighten traffic monitoring on developer tools.
The advisory did not appear in a vacuum. A June 30 Reddit post reverse-engineering Claude Code surfaced obfuscated logic that had shipped silently since 2.1.91, checking whether a machine's timezone was Asia/Shanghai or Asia/Urumqi and scanning proxy URLs against a hardcoded list of Chinese domains. According to Tom's Hardware, the detection was hidden inside the system prompt via unicode variants of the apostrophe in the phrase 'Today's date is,' invisible to users but readable by Anthropic's backend. Thariq Shihipar, an engineer on the Claude Code team, said on X the mechanism was 'an experiment we launched in March' intended to prevent account abuse from unauthorised resellers and protect against distillation, and the pull request removing it was merged on July 1.
Why the state-level escalation matters more than the Alibaba policy: MIIT's advisory converts an internal HR decision into national cover for any Chinese enterprise to rip the tool out, and, in Alibaba's case, migrate staff to its in-house Qoder platform when the ban takes effect on July 10. It also sets a template. A US AI vendor shipping obfuscated geo-detection now has to assume the discovery route ends at a national CERT-level notice, not a bug tracker.
The honest caveat is that the advisory rests on the same reverse-engineered artefact Anthropic has already patched, and the 'transmitting sensitive information' framing is stronger than the steganographic signal the code actually appears to have carried. What the reporting does not settle is how many Chinese users were on Claude Code to begin with, given it was not officially available there, or whether MIIT plans enforcement beyond the guidance.
The upside for domestic Chinese coding assistants like Qoder is direct, and it now arrives with a state endorsement. For everyone else, the useful read is that silent experiments inside developer tooling now carry a geopolitical price, and the vendors who publish honest release notes are the ones who will get to keep enterprise trust.
What others are reporting
-
China Daily Read →
State-media channel through which the CNVD advisory propagates domestically; includes specific remediation steps issued to Chinese firms on traffic controls and version removal.
The tool's built-in monitoring mechanisms could transmit sensitive information, including users' location data and identity-related identifiers, to remote servers without user authorization.
-
South China Morning Post Read →
Only source carrying Anthropic's direct rebuttal, framing unauthorized Chinese usage as the root issue and shifting culpability away from the telemetry itself.
Users in China being advised to uninstall its flagship Claude Code product were not supposed to be using it in the first place.
-
The Register Read →
Establishes a prior pattern by reporting Anthropic's separate steganography system removed July 1 in v2.1.198, days before the CNVD filing; also confirms Alibaba's internal ban.
It is recommended that relevant units and users immediately conduct a comprehensive investigation.
-
CBS News Read →
Mainstream US framing; names Anthropic engineer Thariq Shihipar's X post as the source confirming the experiment was designed to block distillation and flag unauthorized resellers.
The AI coding tool Claude Code contains security backdoor risks, posing a severe threat.
Originally reported by CNBC
Read the original article →Original headline: China's MIIT Issues National 'Backdoor' Advisory Against Claude Code — Names Versions 2.1.91–2.1.196 for Transmitting Location and Identity Data to Anthropic Without Authorization