Select Language:
A Chinese industry regulator issued a warning on Wednesday about a “security backdoor” found in certain versions of Anthropic’s coding tool, Claude Code. The alleged security flaw could permit the software to send sensitive data—such as user locations and personal identifiers—back to Anthropic’s servers without user approval, according to China’s National Vulnerability Database (NVDB), a cybersecurity platform.
Claude Code is an AI-powered coding assistant capable of generating code, debugging, and code reviewing based on user input. While Anthropic, based in San Francisco, restricts access to its tools from users and corporations in China and other countries it considers adversarial, these services can still be accessed within China via VPNs or third-party proxy services.
The NVDB, affiliated with China’s Ministry of Industry and Information Technology, stated on its website that it recently discovered “security backdoor risks” in Claude Code, describing the issue as a “severe threat.” Anthropic has not yet responded to AFP’s requests for comment regarding these claims, which first appeared in specialized tech media last week.
The agency urged relevant institutions and users to immediately perform thorough security checks and either uninstall or update to the latest secure version that eliminates the suspected backdoor. It also recommended enhancing network traffic monitoring to prevent unauthorized leakage of sensitive data.
Last week, Alibaba, a major Chinese technology company, reportedly told employees that they would be prohibited from using Claude Code starting July 10 due to security concerns. Sources familiar with the matter noted that Anthropic has previously accused Alibaba of reverse-engineering its AI models to mimic their capabilities through a process called “distillation.”





