China alerts about a "security backdoor" in Anthropic AI programming tool.

China alerts about a "security backdoor" in Anthropic AI programming tool.
Summary
China's NVDB warns of a "security backdoor" in Anthropic's Claude Code tool.
The backdoor could expose sensitive user data to Anthropic's servers without consent.
Alibaba announced a ban on Claude Code usage due to these security concerns.

Share

Bookmark

Newsletter

Beijing has issued a stark warning regarding a potential "security backdoor" discovered within the coding tool Claude Code, developed by the American artificial intelligence firm Anthropic. This concern was raised on Wednesday by China's National Vulnerability Database (NVDB), a cybersecurity initiative linked to the Ministry of Industry and Information Technology.

According to the NVDB, the suspected backdoor may allow the tool to relay sensitive data—such as users' locations and personal identifiers—back to Anthropic's servers without the knowledge or permission of the users. Claude Code is designed to assist users in generating computer code, debugging, and reviewing software according to specified prompts.

While Anthropic has restricted access to its services for users and organizations in China, along with other nations categorized as adversarial, individuals are still able to utilize these tools through Virtual Private Networks (VPNs) or proxy services.

The NVDB noted on its platform that it recently identified risks associated with the security backdoor in Claude Code, stating that these pose a significant risk to users. Despite attempts to obtain a statement from Anthropic regarding these charges, the company has not yet responded to inquiries.

In light of these findings, the NVDB has urged users and organizations to conduct thorough assessments immediately and to either uninstall the program or upgrade to a more secure version that addresses the detected issues. Furthermore, it emphasized the need for enhanced monitoring of network traffic to mitigate the unauthorized transfer of confidential information.

In response to the ongoing security concerns, Chinese tech giant Alibaba informed its employees last week that Claude Code would be prohibited from use effective July 10, as reported by sources familiar with the situation. This comes amid allegations from Anthropic that Alibaba has engaged in reverse-engineering its AI models to replicate their functionalities through a technique known as "distillation."

Reacting to the allegations of data tracking from Chinese users, Claude Code's engineer Thariq Shihipar took to X to clarify that the functionality was part of an experiment initiated in March aimed at preventing account abuse. He mentioned that the team had implemented stronger safeguards and was planning to remove this feature in an upcoming release, indicating that these changes would be fully integrated shortly.

Loading comments...