China warns of 'security backdoor' in Anthropic AI coding tool

Published
0
Anthropic logo is seen in this illustration taken on May 20, 2024. — Reuters/File Photo
Anthropic logo is seen in this illustration taken on May 20, 2024. — Reuters/File Photo

A Chinese industry regulator warned users on Wednesday of a “security backdoor” embedded in versions of US artificial intelligence company Anthropic’s coding tool, Claude Code.

The alleged backdoor could allow the software to “transmit sensitive information”, including users’ locations and identity-related identifiers, back to Anthropic’s servers without users’ consent, said China’s National Vulnerability Database (NVDB), a cybersecurity platform.

Claude Code is an AI coding agent that can generate computer code, debug software and review code based on user prompts.

San Francisco startup Anthropic blocks users and companies in China and other nations it deems adversarial from accessing its products, but it is still possible to use them in the country through a VPN or third-party proxy services.

The NVDB, which is affiliated with China’s Ministry of Industry and Information Technology, said on its website that it had recently “detected that the AI coding tool Claude Code contains security backdoor risks, posing a severe threat”.

Anthropic has not responded to AFP requests for comment on the allegations, which first emerged in specialist tech media last week.

The NVDB advised relevant institutions and users “to conduct a comprehensive check immediately” and “promptly uninstall or upgrade to the latest secure version from which the relevant backdoor code has been removed”.

It also urged organisations to strengthen network traffic monitoring to prevent the unauthorised leakage of sensitive data.

Chinese tech giant Alibaba told employees last week that the use of Claude Code would be banned from July 10 due to security concerns, people familiar with the matter said.

Anthropic has previously accused Alibaba of reverse-engineering its AI models to mimic their abilities in a process known as “distillation”.

Claude Code engineer Thariq Shihipar responded in an X post last week to reports alleging that the tool was tracking certain data from Chinese users.

“This is an experiment we launched in March that was meant to prevent account abuse from unauthorised resellers and protect against distillation,” Shihipar wrote.

“The team has landed stronger mitigations since then and we’ve actually been meaning to take this down for a while… this should be fully rolled back in tomorrow’s release.”

Opinion

Editorial

Kashmir unresolved
Updated 30 Sep, 2026

Kashmir unresolved

The just solution lies in India addressing the issue through a trilateral dialogue involving the legitimate representatives of the Kashmiri people and Pakistan.
Water shortage
30 Sep, 2026

Water shortage

THAT the country is entering the Rabi season with an anticipated water shortage of nearly 25pc, the lowest carryover...
Young hearts
30 Sep, 2026

Young hearts

THE observance may have passed, but the message of World Heart Day should not fade with it. The occasion is a useful...
Terror and politics
Updated 29 Sep, 2026

Terror and politics

There is an urgent need to tone down the rhetoric and tackle terrorism as a collective challenge for both the affected provinces and the federation.
Watching the glaciers
29 Sep, 2026

Watching the glaciers

THE latest signs from Pakistan’s mountains are worrying. Suparco says the number of unfrozen glacial lakes it...
Dangerous agenda
29 Sep, 2026

Dangerous agenda

AS the world remains fixated on the US-Iran conflict, elsewhere in the Middle East, Israel is consolidating its grip...