← Reddit

China warns of "security backdoor" in Anthropic AI coding tool

Reddit · MiyaHunter · July 8, 2026
China's National Vulnerability Database warned that a security backdoor in Anthropic's Claude Code could transmit sensitive user information including location and identity data without consent. The NVDB advised users and institutions to uninstall or upgrade the software, and Alibaba announced it would ban the tool starting July 10 due to security concerns. Claude Code's engineer responded that the data collection was an experiment intended to prevent account abuse and unauthorized model distillation, stating the issue would be rolled back in an upcoming release.

Detailed Analysis

China's National Vulnerability Database, a cybersecurity platform affiliated with the Ministry of Industry and Information Technology, has publicly accused Anthropic's Claude Code of harboring a "security backdoor" capable of transmitting users' locations and identity-related data back to Anthropic's servers without consent. The warning, issued July 8, 2026, urged Chinese institutions and users to immediately audit their systems, uninstall or upgrade affected versions, and tighten network traffic monitoring to prevent further data leakage. The allegations follow reporting from specialist tech media the prior week and coincide with Alibaba's internal decision to ban employee use of Claude Code starting July 10, citing its own security concerns—a striking move given Alibaba's simultaneous position as a major developer of competing AI models.

The technical reality behind the accusation appears more nuanced than "backdoor" implies. Claude Code engineer Thariq Shihipar addressed the controversy directly on X, explaining that the data-collection mechanism was an experiment launched in March 2026 designed to combat account abuse by unauthorized resellers and to protect against "distillation"—the practice of using outputs from one AI model to train or fine-tune a competing model cheaply. Shihipar stated the team had already developed stronger mitigations and was in the process of rolling back the original tracking mechanism entirely, with a full rollback expected in the next release. This framing casts the feature less as a covert surveillance tool and more as an anti-piracy and IP-protection measure that inadvertently created a genuine privacy and security concern, especially for users accessing the tool from China through VPNs or proxy services despite Anthropic's official geographic restrictions.

The distillation context is critical to understanding why this dispute escalated so quickly into a geopolitical flashpoint. Anthropic has previously and explicitly accused Alibaba of reverse-engineering its models to replicate their capabilities, a practice that strikes at the heart of the commercial value AI labs place on proprietary model behavior and training data. Given that backdrop, Anthropic's tracking mechanism—even if framed defensively—reads very differently to Chinese regulators and companies than it might elsewhere: it becomes evidence of a foreign AI company monitoring Chinese users' identities and locations under the guise of anti-piracy enforcement. China's swift regulatory response, funneled through an official vulnerability database rather than informal channels, signals Beijing's institutional apparatus is primed to treat foreign AI tools with the same security scrutiny applied to telecom equipment or cloud infrastructure.

This episode illustrates the deepening bifurcation of the global AI ecosystem along national-security lines. Anthropic already blocks official access from China and other countries it considers adversarial, yet the persistence of VPN and proxy-based usage shows how porous these barriers remain in practice—and how that porousness creates friction when access-control and anti-distillation measures collide with data-sovereignty concerns. The incident also underscores how AI coding agents, which require deep integration with a user's codebase, environment, and often sensitive credentials, present a uniquely sensitive attack surface compared to conventional chatbots. As U.S. and Chinese AI labs continue racing for capability parity, tools like Claude Code are becoming proxies in a broader contest over model IP protection, data sovereignty, and mutual distrust—each side interpreting the other's defensive measures as offensive intrusions. The rapid corporate response (Alibaba's ban) alongside a swift government regulatory alert suggests this dynamic will only intensify as more Chinese firms and regulators scrutinize Western AI tools operating in gray-market access channels.

Read original article →