China flags alleged 'backdoor' security risk in Anthropic's Claude code
China warns of a suspected security backdoor in Anthropic's Claude Code, prompting Alibaba to ban the AI coding tool for workplace use.

A cybersecurity platform operated by the Chinese government has warned of a serious security "backdoor" risk in Anthropic's AI coding tool, Claude Code. The warning was issued via the National Vulnerability Database's WeChat account.
According to the advisory, Claude Code contains a built-in monitoring mechanism capable of transmitting sensitive information—including users' geographic location and identity-related identifiers—to remote servers without users' consent. The warning applies to Claude Code versions 2.1.9 through 2.1.196.
The agency warned that the mechanism could pose a "serious security threat" and advised users to either uninstall the affected versions or update to the latest release.
Organisations and users have been advised to immediately review affected systems and either uninstall the impacted versions or upgrade to the latest secure release, in which the identified backdoor code has reportedly been removed.
Post on Reddit after which Claude was banned for Alibaba
Following the discovery, the advisory also urged organisations to tighten controls on external network access for development tools and strengthen traffic monitoring across core business networks to prevent the unauthorised transmission of sensitive data.
China's move to restrict the use of Claude Code at Alibaba came after a post on Reddit last week alleged that Anthropic had secretly embedded code in the software to identify users accessing it from China.
Responding to the allegations, an Anthropic employee said on X that the code was part of an experiment launched in March. According to the employee, the experiment was designed to curb account abuse by unauthorised resellers and protect Anthropic's models from AI distillation attempts.
In recent months, Anthropic accused Chinese technology and e-commerce giant Alibaba of unlawfully extracting the capabilities of its Claude AI models in what it described as the largest known AI model distillation attack of its kind. According to Anthropic, the campaign ran between April 22 and June 5, 2026, generating more than 28.8 million interactions with Claude through nearly 25,000 fraudulent accounts.
Anthropic said the alleged distillation effort was aimed at accelerating China's ability to replicate the advanced capabilities of its Mythos preview models. The company further claimed that the campaign was carried out by operators affiliated with Alibaba's Qwen AI lab.

OpenAI launches Presence to bring AI agents into customer support and enterprise workflows
Samsung Galaxy Fold 8 Ultra, Fold 8, Flip 8 launched: Here is how much it costs in India with discounts
Florida pastor sues OpenAI, says ChatGPT's medical advice delayed emergency treatment: Report
US accuses China's Moonshot AI of using Anthropic's Fable to build K3 model
Apple's biggest Mac refresh in years could bring 11 new models: Report
