Advertisement

China flags alleged 'backdoor' security risk in Anthropic's Claude code

China warns of a suspected security backdoor in Anthropic's Claude Code, prompting Alibaba to ban the AI coding tool for workplace use.

Advertisement
Anthropic Claude outage
Anthropic Claude outage
FP Tech Desk|Jul 08, 2026, 14:33:29 IST

A cybersecurity platform operated by the Chinese government has warned of a serious security "backdoor" risk in Anthropic's AI coding tool, Claude Code. The warning was issued via the National Vulnerability Database's WeChat account.

According to the advisory, Claude Code contains a built-in monitoring mechanism capable of transmitting sensitive information—including users' geographic location and identity-related identifiers—to remote servers without users' consent. The warning applies to Claude Code versions 2.1.9 through 2.1.196.

Advertisement

The agency warned that the mechanism could pose a "serious security threat" and advised users to either uninstall the affected versions or update to the latest release.

Organisations and users have been advised to immediately review affected systems and either uninstall the impacted versions or upgrade to the latest secure release, in which the identified backdoor code has reportedly been removed.

techMore from Tech

Post on Reddit after which Claude was banned for Alibaba

Following the discovery, the advisory also urged organisations to tighten controls on external network access for development tools and strengthen traffic monitoring across core business networks to prevent the unauthorised transmission of sensitive data.

China's move to restrict the use of Claude Code at Alibaba came after a post on Reddit last week alleged that Anthropic had secretly embedded code in the software to identify users accessing it from China.

Advertisement

Responding to the allegations, an Anthropic employee said on X that the code was part of an experiment launched in March. According to the employee, the experiment was designed to curb account abuse by unauthorised resellers and protect Anthropic's models from AI distillation attempts.

In recent months, Anthropic accused Chinese technology and e-commerce giant Alibaba of unlawfully extracting the capabilities of its Claude AI models in what it described as the largest known AI model distillation attack of its kind. According to Anthropic, the campaign ran between April 22 and June 5, 2026, generating more than 28.8 million interactions with Claude through nearly 25,000 fraudulent accounts.

Anthropic said the alleged distillation effort was aimed at accelerating China's ability to replicate the advanced capabilities of its Mythos preview models. The company further claimed that the campaign was carried out by operators affiliated with Alibaba's Qwen AI lab.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jul 08, 2026, 14:15:22 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next