Story
China Issues Security Alert Over 'Backdoor' Risk in Anthropic's Claude Code

Summary
A Chinese cybersecurity platform has issued a warning about a potential security risk in Anthropic's AI coding tool, Claude Code, alleging it can transmit sensitive user data without consent. Anthropic described the feature as an experimental anti-abuse mechanism.
A cybersecurity platform operated by China’s industry ministry has issued a warning regarding what it describes as a serious security "backdoor" risk in the AI coding tool, Claude Code, developed by Anthropic. The National Vulnerability Database posted a statement alleging that the tool contains a built-in monitoring mechanism.
According to the warning, this mechanism is capable of transmitting sensitive information, including users’ geographic location and identity-related identifiers, to remote servers without the user's consent. The alert specifically applies to Claude Code versions 2.1.91 through 2.1.196.
The Chinese database advised organizations and users to immediately review their systems and either uninstall the affected versions or upgrade to a secure release where the alleged code has been removed. It also recommended that organizations tighten controls on external network access for development tools and increase monitoring of network traffic to prevent unauthorized data transfers.
AdIn response to the claims, Anthropic stated that what was being described as a "backdoor" is an experimental anti-abuse mechanism. The company also noted that access to its Claude services is not permitted in China.
This development follows earlier reports that Chinese tech company Alibaba had banned its employees from using Claude Code at work due to scrutiny over features that could potentially identify China-linked users.