Anthropic’s Claude Code contained hidden China tracker
A security researcher discovered a hidden tracking feature inside Anthropic’s coding assistant Claude Code that attempted to identify users connected to Chinese firms by encoding signals (e.g., date-format changes) in returned text. Anthropic developer Thariq Shihipar said the tracker was an "experiment" added in March 2026 to deter model distillation and unauthorized resellers; the company said it planned to remove the code and has implemented stronger protections. The revelation alarmed privacy advocates and triggered corporate reactions: Alibaba told employees to stop using Claude Code and to switch to its in‑house coding AI, and international press outlets reported on the incident. The story raises concerns about surveillance, model‑protection techniques and cross‑border trust in AI tooling.
- •A security researcher discovered a hidden tracking function in Anthropic's Claude Code that aimed to identify users associated with Chinese firms.
- •Anthropic developer Thariq Shihipar said the tracker was an "experiment" added in March 2026 to prevent model distillation and unlicensed resellers.
- •The researcher found the mechanism by decoding small changes (e.g., in date formats) that Anthropic's service returned, described as a form of steganography.
