Anthropic Rejects China's Claim About Claude Code Backdoor
Agentic AI , Application Security , Artificial Intelligence & Machine Learning
Anthropic Rejects China's Claim About Claude Code Backdoor
AI Firm Says Monitoring Mechanism Targets Abuse and Model DistillationAnthropic defended the software checks in Claude Code that could identify whether a user appeared to be accessing the AI coding tool from China, following a warning from the Chinese government's vulnerability database that it contained a "security backdoor."
See Also: Snyk Reportedly Cuts 90 Jobs to Accelerate AI Strategy
The artificial intelligence firm said Thursday the code was an anti-abuse measure aimed at detecting unauthorized access from China and other unsupported regions, according to a report by the South China Morning Post. Anthropic bars access to Claude from China, though developers there have continued to use VPNs or third-party proxy platforms to access the service.
China's National Vulnerability Database, a government-run cybersecurity platform affiliated with the Ministry of Industry and Information Technology, said Wednesday that it "detected that the AI coding tool Claude Code contains security backdoor risks, posing a severe threat," warning that Claude Code versions 2.1.91 to 2.1.196, released from April through June, could transmit sensitive information, including user location and identity-related data back to Anthropic servers without a user's consent. The agency advised users to uninstall affected versions or upgrade to a newer release.
Anthropic told the South China Morning Post that China-based users were never authorized to use Claude Code. The company told AFP the mechanism in question checks a device's time zone and whether a request was routed through an unsupported or banned region or to AI labs suspected of using Claude outputs to train their own models, a practice known as distillation. Anthropic said it's a standard way to detect fraud and abuse.
The dispute comes as U.S. AI companies are attempting to tighten controls over who can access their most capable models. Anthropic has accused several Chinese AI developers, including DeepSeek, Moonshot AI, MiniMax and Alibaba Group, of using Claude for large-scale distillation attacks intended to improve their own models.
The warning comes on the heels of online discussion in China and on Reddit over code that appeared designed to detect whether Claude Code users were linked to China or Chinese AI labs. Claude Code engineer Thariq Shihipar wrote on X that the system was part of a March experiment meant to prevent account abuse by unauthorized resellers and protect against distillation. He said Anthropic has developed stronger mitigations and planned to remove the code.
Last week, Chinese firm Alibaba banned employees from using Claude Code starting July 10 after researchers learned the code checked for China-related indicators. Alibaba added Claude Code to its list of high-risk software and told employees to use its in-house Qoder tool instead, as the dispute intensified broader U.S.-China tensions over whether Chinese AI labs are using U.S. frontier models to improve their own systems.
Anthropic in June sent a letter to two U.S. senators accusing Alibaba of carrying out "the largest known distillation attack on Anthropic to date" ahead of a hearing on AI. The letter said Alibaba and its Qwen AI lab generated 28.8 million exchanges with Claude through roughly 25,000 fraudulent accounts between April 22 and June 5 (see: AI Firms Seek US Help Against China Model Distillation).