Technology, AI & Cyber
Claude Code has security backdoor, China warns
China's National Vulnerability Database warned on Wednesday that versions of Anthropic's Claude Code AI coding tool had “security backdoor risks”, while Anthropic said the mechanism was an anti-abuse measure.
Claude Code is an AI agent that can generate computer code, debug software and review code based on user prompts. Anthropic bars users and companies in China and other countries it classifies as adversarial from accessing it, though some users can try to bypass those limits through VPNs or proxy services.
The Chinese cybersecurity platform, which is affiliated with the Ministry of Industry and Information Technology, advised institutions and users to check systems immediately and uninstall or upgrade to a newer version it said had removed the relevant code. It also urged organisations to strengthen network traffic monitoring to prevent unauthorised leakage of sensitive data.
Anthropic said the mechanism checked a device's timezone and whether a request was routed through a domain tied to an unsupported region or a known problematic entity. The company said this was a standard way to detect fraud and abuse.
Claude Code engineer Thariq Shihipar wrote on X last week that the mechanism was an experiment launched in March to prevent account abuse by unauthorised resellers and protect against model “distillation”. He said stronger mitigations had since been developed and that the mechanism would be rolled back.
Chinese tech giant Alibaba told employees last week that use of Claude Code would be banned from July 10 because of security concerns, people familiar with the matter said.
Uncertainty notes
China's backdoor allegation is disputed by Anthropic.
The supplied information does not state how many users or organisations were affected.
Source
AFP news report published on .