Anthropic says it is rolling back a covert Claude Code tracking feature that identifies users based in China or affiliated with Chinese AI labs, after backlash
Anthropic is backtracking a spyware rolled out covertly to track users' location and whether they are based in China or affiliated …
The InformationJuro Osawa
Context & Ripple Effects
Anthropic’s China-related access controls have been tightening across its products and customer policies: related coverage describes ID-and-selfie checks for some users, restrictions on majority Chinese-owned groups, and efforts to close access routes through cloud providers and overseas subsidiaries.
The rollback introduces a constraint on that strategy. It follows reporting that Anthropic has also alleged large-scale adversarial use of Claude by Alibaba, making the company’s need to limit misuse visible while raising scrutiny of how it identifies suspected users.
First-order effects
Anthropic will withdraw the covert Claude Code tracking mechanism, reducing its ability to use that particular signal to identify China-based users or users tied to Chinese AI labs.
Claude Code users and developers affected by the feature gain a clearer privacy boundary, while Anthropic must rely on other safeguards already described in related coverage.
Second-order effects
The backlash makes covert telemetry a less viable enforcement tool, increasing pressure on Anthropic to make access controls more explicit and defensible to customers and developers.
Other model providers pursuing geographic or affiliation-based restrictions may face a similar trade-off: tighter anti-abuse controls can create trust and privacy costs if their collection methods are not transparent.
Third-order effects
If access restrictions on advanced AI services continue to expand, enforcement is likely to shift toward more formal account, organizational, and distribution controls rather than hidden client-side tracking.
The episode points to a durable governance tension in AI platforms: providers will be expected to prevent adversarial access while giving users meaningful notice and limits around the data used to enforce those policies.
The trend: AI model providers are moving from broadly available developer tools toward more tightly governed access, with privacy and transparency becoming central constraints on enforcement.
@IntCyberDigest Hi, this is an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation. The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while. …
‼️ BREAKING: Anthropic has embedded hidden spyware-like code in Claude Code that covertly targets Chinese users. It then sends information regarding every user by injecting it into their prompt message. Claude Code is sending info like timezone, proxy and possible AI Lab [image]
I think it's fair to say at this point that Anthropic is not a trustworthy company. I have verified this myself in 2.1.91 as well as current 2.1.197. Sneaky steganographic embeds in a ships-to-customers product is a line best not crossed.
Colorful Chinese acquaintance noted that Westerners who go to Russia often dementedly fall in love with it, while those who go to China develop a weird seething hatred of it. Dario might be the most world-historically consequential example of the latter.
wow 👀 Claude Code allegedly fingerprints China-linked custom routes through tiny prompt formatting changes. The claim concerns non-default ANTHROPIC_BASE_URL routes, not ordinary direct Anthropic connections. As to the mechanism, Claude Code normally sends your request to [image]
Anthropic yet again confirmed as the most dystopian tech company out there. Imagine the outcry if they'd done the same thing with Jews or Blacks: a piece of code that detects if a user is Jewish or Black and immediately reports him back to headquarters on that basis, covertly
Anthropic hiding spyware in Claude Code, at the moment to detect Chinese users. The way they fingerprint your message is by using different characters that looks almost the same, such as ‘, ’, ʼ, and ʹ. You know what to do ... Open source !
This is pretty concerning. You could still do this at the API level to some degree, but they seemingly just blatantly put it right into the code? This is why open harnesses and agents are a much better option, among countless other reasons. You can inspect the code, observe the
I like my AI coding agent to not be trying to fingerprint me. — If you needed yet another reason to use an amazing open-source harness like https://pi.dev by @mitsuhiko — and @nitter.net.badlogicgames — https://thereallo.dev/... https://www.reddit.com/...
Evidence that Anthropic is using prompt stenography to track whether Claude Code is being used by certain labs and certain web domains thereallo.dev/blog/claude-...