China accuses Anthropic's Claude Code of a 'security backdoor' and opens probe
- Chinese authorities warned that Anthropic's Claude Code contained a 'security backdoor,' claiming it sent sensitive information to remote servers and urging users to stop using it. - Anthropic responded that users in China were never authorised to use Claude Code, pushing back on the regulator's claim. - The dispute highlights how coding agents are now squarely inside data‑sovereignty and supply‑chain risk conversations. (scmp.com) (cbsnews.com) (tomshardware.com)
1/ China’s National Vulnerability Database, a cybersecurity platform affiliated with the Ministry of Industry and Information Technology, said on July 8 that Anthropic’s Claude Code contained a “security backdoor” risk. It said some versions could send sensitive information — including location and identity-related identifiers — back to Anthropic servers without user consent, and urged users to uninstall or upgrade. (cbsnews.com) 2/ The allegation matters because Claude Code is not a generic chatbot. It is an AI coding agent that can generate code, debug software and review repositories based on prompts, which means it can sit close to source code, developer environments and internal systems. (cbsnews.com) 3/ China’s notice did not frame this as a broad AI-policy complaint. It described a specific software-security issue and said organizations should immediately check deployments, strengthen network traffic monitoring and prevent unauthorized leakage of sensitive data. (cbsnews.com) 4/ Anthropic’s public response, as reported by South China Morning Post, was that users in China were never authorized to use Claude Code in the first place. That is consistent with Anthropic’s September 2025 policy update, which said its terms prohibit use in unsupported regions including China and extend those restrictions to entities controlled from such jurisdictions. (scmp.com) 5/ One important detail is that Anthropic appears to have acknowledged the underlying code path, while disputing the framing. CBS reported that Claude Code engineer Thariq Shihipar said in an X post that the mechanism was an experiment launched in March to prevent account abuse by unauthorized resellers and protect against model distillation, and that it was being rolled back. (cbsnews.com) 6/ In other words, the dispute is not simply “China says backdoor, Anthropic says no.” The regulator described covert outbound data transmission as a backdoor risk; Anthropic’s engineer described the code as an anti-abuse and anti-distillation measure that should be removed in a subsequent release. (cbsnews.com) 7/ The China angle also sits inside a longer fight over access. Anthropic said in September 2025 that companies controlled from China posed legal, regulatory and security risks, and it tightened restrictions on sales to unsupported regions for that reason. (anthropic.com) 8/ Anthropic has also publicly tied China to misuse concerns before. In November 2025, the company said a Chinese state-sponsored group had manipulated Claude Code during what it described as the first reported AI-orchestrated cyber espionage campaign. Anthropic said the activity targeted tech companies, financial institutions, chemical manufacturers and government agencies. (anthropic.com) 9/ That history helps explain why this story is bigger than a narrow vendor dispute. Coding agents now sit at the intersection of software supply chain security, outbound telemetry, export controls and cross-border data access. When a tool can read code and interact with systems, questions about where prompts, metadata and logs go become procurement issues, not just engineering issues. (cbsnews.com) 10/ The commercial fallout had already started before the formal warning. SCMP’s coverage shows Alibaba had moved to ban staff use of Claude Code from July 10 after listing it as high-risk software over spyware concerns. CBS separately reported people familiar with the matter saying Alibaba told employees the tool would be banned starting July 10. (scmp.com) 11/ For companies watching this, the practical question is less whether one side’s rhetoric is harsher than the other’s and more whether coding agents are being evaluated like ordinary SaaS tools or like sensitive infrastructure. China’s notice treated Claude Code as something that could expose sensitive information through network behavior, and Anthropic’s own trust materials show the company now markets compliance and control posture as a core part of its enterprise pitch. (cbsnews.com) 12/ The next things to watch are concrete: whether Chinese regulators publish more technical findings, whether Anthropic documents the rollback Shihipar referenced, and whether more companies follow Alibaba in blocking Claude Code on internal systems. As of July 9, the public record shows a regulator warning, an Anthropic-linked explanation that the code was an anti-abuse experiment, and a widening argument over who should be using the tool at all. (cbsnews.com)