China Warns of "Backdoor" Security Risk in Anthropic's Claude Code
Company Updates

China Warns of "Backdoor" Security Risk in Anthropic's Claude Code

Technology Org13d ago

A cybersecurity platform run by China's industry ministry has warned that it found a serious security "backdoor" risk in Anthropic's AI coding tool, Claude Code. The National Vulnerability Database, affiliated with the Ministry of Industry and Information Technology, posted the alert on Wednesday. It said the tool's built-in monitoring can transmit sensitive information, including a user's location and identity, to a remote server without consent.

Key Takeaways

  • China's National Vulnerability Database said Claude Code contains a "security back-door vulnerability that poses a serious threat," affecting versions 2.1.91 through 2.1.196.

  • That version range spans releases from April 2 to June 29; the latest build as of Wednesday was 2.1.204, three point releases past the flagged cutoff.

  • Anthropic said the code was an experiment earlier this year to protect against distillation, and noted its policy bars use by entities majority-owned by China-headquartered organizations.

Claude Code is an agentic tool that can generate, debug, and review code from user prompts. The NVDB statement, translated from Chinese, said the affected versions could send data including a user's location and identity to a remote server without permission. The agency advised users to uninstall the flagged versions or upgrade to a secure release, and to tighten controls on external network access and traffic monitoring within core business networks.

Anthropic pushed back. Asked about the warning, the company said the "backdoor" was an experiment earlier this year meant to protect against distillation, the practice of extracting a model's capabilities to train a rival. It also pointed out that its policy prohibits use by entities majority-owned by China-headquartered organizations, meaning the flagged users were not supposed to be running the product.

A Wider US-China Tech Standoff

The alert lands as the US-China AI contest intensifies. Last month Anthropic accused Chinese company Alibaba of trying to extract its AI capabilities, which are not officially available in China. Alibaba did not comment at the time, and has since ordered employees to stop using Anthropic tools for work starting July 10, directing them to its own coding platform instead. Many developers in China still reach US tools through VPNs and proxies; in March, a Xiaomi AI developer said at a state forum that many were using Claude Code.

The technical claim itself is not unusual on its face. Most modern developer tools send telemetry, crash reports, and usage data back to their makers, and whether that amounts to a backdoor depends on scope, disclosure, and consent, none of which the notice specified. Independent researchers outside China have not yet corroborated the claim, and no CVE has been filed against the affected versions. Anthropic has said the users being advised to uninstall were not meant to have access in the first place.

The bigger story is a market splitting along national lines. The episode adds Anthropic to a short list of US labs formally warned against inside China, part of a decoupling that is reshaping how enterprise AI gets sold. Anthropic has spent the year expanding Claude Code across new surfaces and growing its paying base, even as US export controls and cross-border tensions complicate its reach. The distillation fight also has history: the company previously cut off a rival's access over terms-of-service violations, underscoring how aggressively frontier labs now guard their models. For most Chinese users the practical impact is limited, since the product was never officially sold there, but the reputational note becomes a talking point in markets where it does compete.

Originally published by Technology Org

Read original source →
Anthropic