Anthropic's secret tracker in Claude Code sparks user trust backlash
Hidden steganography in Claude Code tracked Chinese users' timezone and proxies.
Anthropic secretly embedded a tracker in Claude Code using prompt steganography—hiding code in plain sight—to monitor users in China. Security researcher 'Thereallo' uncovered the code, which quietly flagged timezone, proxy, and potential ties to Chinese AI labs accused of distillation attacks. Anthropic engineer Thariq Shihipar confirmed the March 'experiment,' stating it was meant to prevent unauthorized resellers and model copying. Despite claims that stronger mitigations were already in place, privacy advocates called it a serious breach of trust, especially given Anthropic's recent refusal to let the U.S. government use Claude for surveillance and its subsequent lawsuit against the Trump administration.
Alibaba responded by banning employees from using Claude Code for work, citing the tracker controversy. The incident underscores escalating tensions between U.S. and Chinese AI firms. Anthropic has joined OpenAI in urging the U.S. to classify distillation as intellectual property theft, pushing for export controls and penalties. The Post noted Chinese models now consistently match U.S. capabilities within months—most recently, Zhipu AI's free model outperformed Anthropic's Claude Opus 4.8 in vulnerability detection.
- Claude Code used 'prompt steganography' to secretly send user timezone, proxy, and lab affiliation data to Anthropic
- Anthropic engineer Thariq Shihipar confirmed the tracker was an experimental measure against resellers and distillation attacks
- Alibaba banned employees from using Claude Code after the tracker was exposed, citing privacy concerns
Why It Matters
Anthropic's hidden tracker risks user trust and highlights dual standards on surveillance, escalating US-China AI tensions.