China flags Claude Code vulnerability

- China’s industry ministry warned on July 8 that Anthropic’s Claude Code versions 2.1.91 through 2.1.196 contained a “back-door” risk and urged removal. - The Chinese notice said the tool could send user location and identity data to remote servers without consent; Anthropic called it a March experiment. - Alibaba’s internal ban on Anthropic tools is set to take effect July 10, according to CNBC and people familiar.

China’s industry ministry warned on July 8 that certain versions of Anthropic’s Claude Code contained a “security back-door vulnerability” and told users to uninstall or upgrade the software. China’s cybersecurity threat platform said versions 2.1.91 through 2.1.196 could send sensitive data, including location and identity-related information, to remote servers without user consent. Anthropic said the code China flagged was part of an earlier experiment tied to anti-abuse controls. CNBC reported the company said the “backdoor” was an experiment earlier this year to protect against model distillation, and other reports citing an Anthropic employee on X said the feature had been launched in March to detect unauthorized resellers and distillation attempts. (cnbc.com) ### Which versions did China say were affected? China’s notice covered Claude Code versions 2.1.91 to 2.1.196, which CNBC said corresponded to releases from April 2 through June 29. China’s cybersecurity platform told users to “uninstall or upgrade” those builds, while CNBC reported Anthropic’s latest listed version as of July 8 was 2.1.204. (cnbc.com) The Chinese warning described the issue as a built-in monitoring mechanism rather than a conventional flaw introduced by an outside attacker. Reuters, via syndicated reports, said the National Vulnerability Database under China’s industry ministry posted the warning on its WeChat account and called the risk serious. ### What exactly did Chinese authorities say the code could do? (cnbc.com) China’s cybersecurity platform said the tool could transmit “sensitive information” to a remote server without consent. CNBC said the cited data included a user’s location and identity, and Reuters-based reports described the same allegation as unauthorized transmission of geographic and identity-related identifiers. (aol.com) That framing matters because Claude Code is a coding assistant used inside developer workflows, where prompts and environment details can overlap with internal systems, repositories and corporate credentials. China Daily, citing the same ministry platform, said the concern was unauthorized data transmission from specific versions of the tool. (cnbc.com) ### How did Anthropic respond? Anthropic told CNBC the flagged code was an experiment aimed at protecting against distillation. Separate reports citing Anthropic employee Thariq Shihipar said on X that the feature was “an experiment we launched in March” to prevent account abuse by unauthorized resellers and to protect against model distillation, and that stronger mitigations had since been put in place. (global.chinadaily.com.cn) Anthropic also pointed to its policy barring use by entities majority-owned by China-headquartered organizations, CNBC reported. That response placed the vulnerability dispute inside a broader fight over access controls, model copying and cross-border use of U.S. AI systems. ### Why did this surface in the middle of a wider China-Anthropic dispute? (cnbc.com) CNBC reported on July 6 that Alibaba would ban employees from using Anthropic tools for work starting July 10 and had placed Claude Code on a high-risk software list. The report said the move followed Anthropic’s June accusations that Alibaba had tried to extract its AI capabilities in what Anthropic described as a distillation attack. (cnbc.com) CNBC also reported that developers in China had been discussing hidden code in Claude Code that could identify whether users were operating from China-linked environments. Other reports tied the government alert to those earlier online allegations and to Anthropic’s tightening of access restrictions for users in China. ### What happens next for companies using Claude Code? (cnbc.com) Alibaba’s workplace ban is due to start on July 10, according to CNBC’s July 6 report citing people familiar with the matter. China’s advisory said affected users should review installations of versions 2.1.91 through 2.1.196 and either remove them or upgrade, while Anthropic’s latest listed version on July 8 was 2.1.204. (cnbc.com)

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.