Cryptobriefing Anthropic's Claude Code Faces Backlash Over Covert User Tracking of Chinese Users
Article Content
- •Anthropic's Claude Code contained hidden tracking mechanisms targeting Chinese users.
- •Alibaba has banned Claude Code for its employees due to security risks associated with the tool.
- •The covert tracking logic was discovered by a developer and utilized steganographic techniques.
Anthropic's AI tool, Claude Code, was found to contain hidden tracking mechanisms targeting Chinese users, raising significant privacy concerns. The covert detection logic, embedded since April 2, 2026, identified users based on their timezone and proxy settings, transmitting data back to Anthropic's servers using steganographic techniques. Following the revelations, Alibaba announced a ban on Claude Code for its employees, effective July 10, 2026, citing security risks. The tracking mechanism was discovered by developer LegitMichel777 and confirmed by security researchers, leading to widespread criticism of Anthropic's practices. The company claimed the tracking was an 'experiment' aimed at preventing unauthorized reselling and model distillation. Despite removing the code on July 1, the backlash continues, with concerns over user privacy and transparency in AI tools. The incident highlights ongoing tensions between Anthropic and Chinese entities amid allegations of industrial espionage.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (41)
Following this threat?
Track Alibaba in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…