China Warns of Backdoor Vulnerabilities in Anthropic's Claude Code AI Tool
China's National Vulnerability Database issued a cybersecurity warning on July 9, 2026, stating that Anthropic's Claude Code AI coding tool (versions 2.1.91–2.1.196) contains a backdoor vulnerability that sends sensitive user data—including location and identity—to remote servers without consent. Anthropic confirmed it was an experimental anti-abuse mechanism to prevent model distillation by Chinese AI labs, and said it would be rolled back. The incident escalates US-China tech tensions, with Alibaba banning employee use of the tool.
Editorial summary awaiting refresh
Cross-source coverage
Wire timeline
China issues 'backdoor' security alert over Anthropic's Claude Code
China's National Vulnerability Database, operated by the industry ministry, issued a security alert on July 9, 2026, warning that Anthropic's AI coding tool Claude Code contains a built-in monitoring mechanism capable of transmitting sensitive user information—including geographic location and identity-related identifiers—to remote servers without consent. The warning applies to Claude Code versions 2.1.91 through 2.1.196. The database urged organizations and users to immediately review affected systems, uninstall impacted versions, or upgrade to the latest secure release. It also recommended tightening controls on external network access for development tools and strengthening traffic monitoring. China's Alibaba has banned employees from using Claude Code at work following scrutiny over features that can identify China-linked users. Anthropic responded that the feature is an experimental anti-abuse mechanism and noted that access to Claude is not permitted in China.
The Hindu: Latest News today from India and the World, Breaking news, Top Headlines and Trending News Videos.China Alleges Claude Code Contains Backdoors, Warns Users to Uninstall or Update
China's National Vulnerability Database (NVDB) has issued a warning that Anthropic's AI coding tool, Claude Code, contains security backdoor vulnerabilities. Versions released between April and June 2026 allegedly send sensitive user information, such as location and identity, to remote servers without consent. The warning comes despite Claude Code not being approved for public use in China, and Anthropic restricting access due to national security risks. Developer Troye Sivan revealed the covert data collection, and Anthropic engineer Thariq Shihipar confirmed it was an experiment to prevent account abuse and distillation, stating it would be rolled back. The incident follows Anthropic's accusations that Chinese AI labs, including DeepSeek and Alibaba, have distilled Claude's models. The Chinese government's directive to update the app suggests tacit acknowledgment that Chinese developers are accessing the tool despite bans.
Latest from Tom's HardwareChina Alleges Claude Code Contains Backdoors, Warns Users to Uninstall or Update
China's National Vulnerability Database (NVDB) has issued a warning that Anthropic's AI coding tool, Claude Code, contains 'security backdoor vulnerabilities' that can send sensitive user information such as location and identity to remote servers without consent. The warning targets versions released between April and June 2026. Developer Troye Sivan revealed the covert data collection, and Anthropic engineer Thariq Shihipar confirmed it was an experiment to prevent account abuse and model distillation, stating the feature would be rolled back in the next release. Despite Claude Code not being approved for use in China and Anthropic restricting access due to national security risks, Chinese developers continue to access the tool. The Chinese government's directive acknowledges this reality, advising users to update to the latest version. This follows Anthropic's accusations that Chinese AI labs, including DeepSeek and Alibaba, have distilled Claude's models using fraudulent accounts.
Latest from Tom's HardwareChina Alleges Claude Code Contains Backdoors, Warns Users to Uninstall or Update
China's National Vulnerability Database (NVDB) has issued a warning that Anthropic's AI coding tool, Claude Code, contains security backdoor vulnerabilities that can send sensitive user information such as location and identity to remote servers without consent. The warning targets versions released between April and June 2026. Developer Troye Sivan revealed the covert data collection, and Anthropic engineer Thariq Shihipar confirmed it was an experiment to prevent account abuse and distillation, stating the feature would be rolled back. This comes amid ongoing tensions between Anthropic and Chinese AI labs, which the company has accused of distilling Claude models. Notably, the Chinese government issued this guidance even though Claude Code is not approved for public use in China, and Anthropic restricts access due to national security risks. The directive effectively acknowledges that Chinese developers are accessing the tool despite restrictions.
Latest from Tom's HardwareChina Warns of Backdoor Vulnerabilities in Anthropic's Claude Code AI Tool
China's Ministry of Industry and Information Technology issued a cybersecurity warning on Wednesday, stating that specific versions of Anthropic's Claude Code AI coding tool (versions 2.1.91 to 2.1.196) contain a backdoor vulnerability that can send sensitive user information, including location and identity data, to a remote server without consent. The warning comes amid escalating US-China tech tensions, following Anthropic's accusation last month that Chinese company Alibaba attempted to extract its AI capabilities. Alibaba has since ordered employees to stop using Anthropic tools starting July 10. The Chinese cybersecurity platform urged users to uninstall or upgrade from the affected versions to the latest version 2.1.204. Anthropic did not immediately respond to a request for comment.
US Top News and Analysis