China flags Anthropic's Claude Code as a security backdoor risk, citing user data transmission without consent
XiaomiNational Vulnerability DatabaseMinistry of Industry and Information TechnologyAlibabaAnthropic

China flags Anthropic's Claude Code as a security backdoor risk, citing user data transmission without consent

China's National Vulnerability Database has flagged Anthropic's Claude Code for potential security backdoor risks, alleging it transmits user data without consent. The software reportedly collects sensitive information, prompting authorities to advise users to uninstall affected versions, which range from 2.1.91 to 2.1.196.

TechRadar+3 sources18 min ago
CuriousCats Full Story

China's Ministry of Industry and Information Technology has raised alarms over Anthropic's Claude Code, labeling it a security risk due to its ability to transmit sensitive user data without consent. The National Vulnerability Database (CNVDB) identified that versions 2.1.91 to 2.1.196 could covertly send user information, including geographic location and identity-linked identifiers, to external servers.1236789

In response, Chinese authorities are advising users to uninstall these versions and upgrade to the latest iteration, 2.1.204, which has addressed these vulnerabilities. The CNVDB's warning follows accusations that the software collects user identity, geographic location, and other machine metadata, raising concerns about data leakage and intellectual property exposure.

While Anthropic has denied that Claude Code contains malicious spyware, it acknowledged that the functionalities in question were part of an experimental anti-abuse measure. The company emphasized that access to Claude Code is not permitted in China, asserting that users being warned are unauthorized. Despite this, the tool has gained traction among Chinese developers, with reports indicating that it is being used within the country, often through foreign proxy services.4

The controversy has led to significant corporate responses, including a memo from Alibaba warning employees against using Claude Code due to security concerns. The situation highlights ongoing tensions between tech companies and regulatory bodies in China, as well as the challenges of managing software security in a globalized digital landscape.

Anthropic has also accused Alibaba of conducting a large-scale attack on its models, further complicating the relationship between the two companies.

Key Insight
“China's Ministry of Industry and Information Technology reported that Claude Code could transmit sensitive user data to external servers without permission, raising concerns about data leakage and IP exposure. Despite Anthropic's denial of malicious intent, the company acknowledged that the mechanism was part of an experimental anti-abuse measure.”
Why China might put curbs on overseas use of its top AI models
CuriousCats Shorts-list
Why China might put curbs on overseas use of its top AI models
China eyes restrictions on its AI models going overseas
CuriousCats Shorts-list
China eyes restrictions on its AI models going overseas
CuriousCats studied:
1
TechRadar
“China has accused Anthropic's Claude Code of containing what it describes as "security backdoor vulnerabilities" after the country's National Vulnerability Database (CNVDB) found mechanisms capable of transmitting user information to Anthropic servers without explicit user permission.”
TechRadar →
2
HDFC Sky
“Anthropic pushed back on Thursday against claims by a Chinese government-run cybersecurity database that the artificial intelligence company’s Claude Code developer tool had a security vulnerability allowing operators to access users’ data surreptitiously, saying users in China never had access to the tool.”
HDFC Sky →
3
qz.comqz.com
“China's Ministry of Industry and Information Technology that Anthropic's Claude Code AI coding tool contains a security backdoor vulnerability that poses a serious threat to organizations and individuals using the software.”
qz.com →
4
Yahoo TechYahoo Tech
“China's Ministry of Industry and Information Technology that Anthropic's Claude Code AI coding tool contains a security backdoor vulnerability that poses a serious threat to organizations and individuals using the software.”
Yahoo Tech →
Ask CuriousCats
What is Claude Code's purpose?
Why did China flag Claude Code as a risk?
How does Claude Code transmit user data?
Are other countries concerned about similar risks?
Which companies have faced similar data concerns?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats