READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Anthropic Secretly Tracked Chinese Claude Code Users for Four Months, Then Removed the Code After a Researcher Exposed It

Anthropic Secretly Tracked Chinese Claude Code Users for Four Months, Then Removed the Code After a Researcher Exposed It
Since Alibaba banned Claude Code on July 3 over hidden tracking code, the full story has come into clearer focus: Anthropic added covert user surveillance to Claude Code in March, quietly removed it after a security researcher exposed it, and an Anthropic engineer confirmed the code was an 'experiment' targeting Chinese users. The company that sued the White House over U.S. government surveillance of Americans was, simultaneously, running its own undisclosed monitoring operation abroad.

Since Alibaba announced its Claude Code ban on July 3, citing hidden tracking code Anthropic embedded in the tool, the underlying mechanics of that code have now been documented publicly.

A web developer known online as "Thereallo" was auditing Claude Code for privacy issues when he found what he described as "prompt steganography," a technique that hides instructions inside model prompts in a way most users would never detect. The code was quietly sending Anthropic data on users' timezones, proxy connections, and potential ties to Chinese AI labs, according to Ars Technica's reporting.

Anthropic engineer Thariq Shihipar confirmed on X that the tracker was added in March as an "experiment." Its stated purpose: blocking unauthorized resellers and defending against distillation attacks. Shihipar said the company had "actually been meaning to take this down for a while" because engineers had "landed stronger mitigations since then."

The code was removed after Thereallo's exposure. No timeline for that removal has been confirmed publicly.

What the Tracker Was Doing

The code was not malware. It did not steal passwords or inject commands. It used shorthand markers to flag specific user characteristics back to Anthropic: timezone (a rough geographic indicator), proxy usage, and signals suggesting affiliation with Chinese AI labs Anthropic has accused of distillation attacks.

Distillation is the practice of running a competitor's model millions of times to harvest its outputs and train a cheaper model to replicate its behavior. It's legal, and U.S. firms do it too. But doing it at industrial scale violates Anthropic's terms of service, and Anthropic has argued at the U.S. Senate that it should be treated as intellectual property theft.

Sen. Tim Scott (R-S.C.) agreed at a recent hearing that legal intervention is warranted.

The Hypocrisy Problem

The hardest fact for Anthropic to explain is the timing. The company has publicly refused to let the U.S. government use Claude to surveil American users, and has clashed with the White House over that position. That principled stance earned Anthropic significant goodwill among privacy advocates.

Those same advocates are now pointing out that Anthropic was, during roughly the same period, running an undisclosed tracking operation targeting users in another country. The method, prompt steganography, was specifically designed to be invisible to the people being monitored.

Privacy critics are not wrong that this is a contradiction. A company cannot credibly claim a surveillance-resistant identity while embedding covert tracking into its own developer tools.

The Strongest Defense

The strongest good-faith argument for Anthropic's position is that the threat is real and measurable. The Washington Post reported that Chinese AI firms have "consistently matched" leading U.S. models' capabilities within months of release. A model from Zhipu AI released recently outperformed Anthropic's Claude Opus 4 on finding computer vulnerabilities. Unauthorized resellers have been selling access to paid Claude subscriptions, which cost up to $100 per month, for as little as $12, according to the Washington Post.

The tracker was a targeted, technical countermeasure against account abuse and model theft, not broad domestic surveillance. Anthropic did not collect this data on American users. The engineer who confirmed the code's existence said stronger protections have since replaced it.

Those facts do not make the covert deployment acceptable, but they do explain why an AI company under active competitive assault might have decided the surveillance-without-disclosure tradeoff was worth it.

The Broader Race

Anthropic has publicly called on the U.S. government to take distillation attacks seriously enough to justify restricting Chinese access to advanced models, chips, and U.S. data center capacity. A 12- to 24-month technology lead is the goal Anthropic has described in its policy advocacy.

The incident illustrates the gap between that policy ambition and the tools currently available. When legal frameworks and access restrictions are not yet in place, companies are improvising, and improvised surveillance, even when technically narrow, tends to get discovered.

The open question now is what Anthropic replaced the tracker with. Shihipar said "stronger mitigations" are in place, but neither he nor Anthropic has disclosed what those mitigations are or whether they involve any form of user monitoring that users are not told about.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
Ars TechnicaSecret Claude tracker shocks users after Anthropic’s anti-surveillance stance