Anthropic removes hidden tracker from Claude Code after China warning
Anthropic confirmed that a hidden tracking mechanism was embedded in certain versions (2.1.91‑2.1.196) of Claude Code, its AI‑powered coding assistant. The code was designed to detect unauthorized use, particularly from China, by checking proxy domains, time‑zone settings and other signals, and could transmit users' geographic location and identity identifiers to Anthropic servers without consent.
The feature was uncovered by security researcher Thereallo in June and sparked criticism. Anthropic said the hidden code was an experimental anti‑abuse measure launched in March to curb model distillation and unauthorized resellers. The company announced that the code would be removed in the July 2 software release.
China’s National Vulnerability Database issued a security warning, labeling the mechanism a “backdoor” and urging users to uninstall the affected versions or upgrade to a secure release. Alibaba subsequently banned internal use of Claude Code. Anthropic denied any malicious intent, stating the function has been removed and that future versions include stronger mitigations.