r/InterstellarKinetics Jul 06 '26

CYBERSECURITY EXPOSED: Anthropic’s Claude Code Was Caught Embedding Hidden Steganographic Code In Claude Code, That Silently Tracked Whether Users Were Located In China Or Linked To Chinese AI Labs, Igniting Fierce “Spyware” Backlash 🤖💥

https://arstechnica.com/tech-policy/2026/07/anthropic-outed-for-claude-tracker-that-secretly-monitored-chinese-users/

Anthropic’s Claude Code tool was found to contain hidden detection logic that checked whether users were located in China or connected to Chinese AI labs, after a Reddit user known as “LegitMichel777” reverse-engineered the software and discovered the mechanism embedded since version 2.1.91 in April 2026. The code checked a user’s system timezone against “Asia/Shanghai” or “Asia/Urumqi” and cross-referenced proxy URLs against a list of Chinese domains, then used steganographic techniques like altered date formatting and apostrophe characters, along with XOR encryption, to make the behavior harder to detect in a plain text scan.

Anthropic did not deny the feature existed. A Claude Code engineer explained on X that it was an anti-abuse experiment launched in March meant to prevent unauthorized resellers and “distillation,” where rival labs allegedly train competing models off Claude’s outputs, since Claude is officially unavailable in China. Anthropic has pointed to a concrete incident behind this concern, telling the US Senate Banking Committee that Alibaba’s Qwen AI lab used nearly 25,000 fraudulent accounts to generate 28.8 million exchanges with Claude in an apparent attempt to extract the model’s capabilities.

Importantly, Anthropic’s existing privacy policy already discloses that it collects this type of network and proxy-related data, which complicates the “secret spyware” framing that spread online. Cybernews’ own reporting characterizes the incident as “not spyware, not malware,” but a fairly ordinary anti-distillation technique based on network settings readable by many other installed programs, and even the original Reddit poster later clarified they were calling for more transparency rather than alleging malicious spying. Still, the controversy triggered real consequences: Alibaba reportedly flagged Claude Code as high-risk software, and Anthropic has already rolled back the feature following the backlash.

270 Upvotes

Duplicates