← Reddit

China warns of "security backdoor" in Anthropic AI coding tool

Reddit · MiyaHunter · July 8, 2026
China's National Vulnerability Database warned that Anthropic's Claude Code AI tool contains a security backdoor capable of transmitting user information including locations and identity data to Anthropic's servers without consent. An Anthropic engineer acknowledged the feature was an experimental measure to prevent account abuse and model distillation, stating it would be rolled back in the next release. Chinese company Alibaba subsequently banned employee use of Claude Code starting July 10 citing security concerns.

Detailed Analysis

China's National Vulnerability Database, a cybersecurity platform affiliated with the Ministry of Industry and Information Technology, publicly warned users on July 8, 2026, that Anthropic's Claude Code contains what it called a "security backdoor" capable of transmitting sensitive user data—including location and identity-related identifiers—back to Anthropic's servers without consent. The regulator urged institutions to immediately audit their systems, uninstall or upgrade affected versions, and bolster network traffic monitoring to prevent unauthorized data leakage. The warning follows reports from specialist tech media the prior week and comes as Alibaba, one of China's largest technology companies, moves to formally ban employee use of Claude Code starting July 10 over similar security concerns.

Anthropic's own account of the situation, delivered through engineer Thariq Shihipar on X rather than an official corporate statement, offers a markedly different framing than "backdoor." Shihipar characterized the data collection as an experimental anti-abuse mechanism launched in March 2026, designed to prevent unauthorized resellers from exploiting Claude Code accounts and to guard against "distillation"—the practice of extracting a model's capabilities by training a competing system on its outputs. He indicated the mechanism was already slated for removal and would be "fully rolled back" in the next release. This distinction matters: a security backdoor implies a deliberately hidden vulnerability exploitable by third parties, whereas an anti-distillation tracking mechanism, however opaque to users, serves a different and more defensible commercial purpose—protecting Anthropic's intellectual property from being reverse-engineered into rival models.

The distillation angle is central to understanding why this dispute is happening in the first place. Anthropic has previously accused Alibaba of reverse-engineering its models to replicate their capabilities, a practice that has become a flashpoint in the broader U.S.-China AI competition. Given that Anthropic already blocks direct access to its products from China and other countries it considers adversarial, any Chinese usage of Claude Code necessarily occurs through VPNs or third-party proxy services—channels that are inherently harder to monitor and more susceptible to abuse, reselling, and unauthorized model extraction. Anthropic's tracking mechanism appears to have been built specifically to detect and mitigate this circumvention, which inadvertently created the appearance of covert surveillance once discovered by users and regulators.

This episode illustrates the escalating trust deficit between American AI developers and Chinese regulators, and how quickly technical disputes can be reframed as national security matters. China's swift, high-profile regulatory response—naming a specific American product and instructing widespread uninstallation—reflects Beijing's broader posture of scrutinizing foreign AI tools operating in gray-market conditions within its borders, especially amid rising anxieties about data sovereignty and foreign surveillance. For Anthropic, the incident is a case study in the reputational risks of building enforcement mechanisms against IP theft without transparent disclosure to end users, even when access to those users was never officially sanctioned in the first place. As AI companies increasingly weaponize technical safeguards to protect proprietary models from distillation, and as geopolitical tensions over AI supremacy intensify, incidents like this are likely to recur, with each side's narrative—security breach versus anti-theft protection—shaping public and regulatory perception in ways that reinforce existing distrust rather than resolve it.

Read original article →