China accuses Anthropic’s Claude Code of hidden ‘backdoor’ for data collection

A Chinese cybersecurity regulator on July 8 warned users about an alleged built-in ‘backdoor’ in versions of the programming tool Claude Code developed by the American company Anthropic. According to the National Vulnerability Database of China (NVDB), this mechanism could enable the program to “transmit confidential information,” including location data and user identifiers, to Anthropic servers without user consent.

Claude Code is an AI programming agent that can generate code, identify errors, and analyze software based on user requests. The company Anthropic, based in San Francisco, officially restricts access to its products for users and companies from China and other nations it deems unfriendly. However, users in China can still access the service via VPN or third-party proxy services.

TOP  Britain will be 'unwavering' in defending Falkland Islanders' right to be British, says Burnham

China recommends removing Claude Code

The NVDB, operating under the Ministry of Industry and Information Technology of China, stated that it had “identified security risks associated with the backdoor in Claude Code, which pose a serious threat.” Anthropic did not respond to a request for comment from AFP. Reports of the potential issue first emerged in specialized technology media last week.

The NVDB advised users and organizations to “immediately conduct a comprehensive review” and “remove the program or update it to the latest secure version, in which the relevant code has already been removed.” The regulator also called for enhanced monitoring of network traffic to prevent potential leaks of confidential information.

TOP  US launches new next-generation hypersonic missile program to counter China's progress

According to sources, last week, Chinese technology giant Alibaba informed employees that the use of Claude Code would be banned starting July 10 due to security risks. Previously, Anthropic had accused Alibaba of reverse engineering its AI models to replicate their capabilities in a process known as “distillation.”

An engineer of Claude Code, Thariq Shihipar, previously addressed reports of alleged data tracking from Chinese users on the social network X. He stated that “this was an experiment launched in March to prevent abuse by unauthorized resellers and to protect against model distillation.” He added that the team had already implemented more effective protection mechanisms and that the controversial functionality was scheduled to be completely removed in the next release.

TOP  Burnham: Britain must stand against injustice over West Bank settlements

Source: Channel NewsAsia