Anthropic removes hidden detection logic from its Claude Code tool shortly after security researchers and privacy advocates publicize claims that the software quietly signaled information about China-based users. Reporting across multiple outlets says the mechanism was present in Claude Code versions released earlier in the year and was discovered through reverse engineering and independent technical analysis.

According to accounts of how it worked, the code primarily triggered when Claude Code was configured to route requests to a server other than Anthropic’s, such as through proxies or internal gateways. In that case, it checked whether the user’s environment appeared to be in a Chinese time zone and whether the destination server matched a concealed list associated with Chinese AI companies or resale/proxy services. If conditions matched, the tool altered parts of the “system prompt” sent to Anthropic servers in ways intended to be visually unobtrusive.

Anthropic says the feature was an experiment launched in March to prevent account abuse by unauthorized resellers and to protect against model distillation. The company stated it merged the rollback and expected the change in a subsequent release.

Separately, Chinese regulators and Alibaba are also cited in reports: China’s National Vulnerability Database warned of “backdoor” risks and urged uninstalling or upgrading, while Alibaba reportedly banned employees from using Claude Code at work, citing security concerns.