Anthropic quickly removed a covert tracker secretly embedded in Claude Code after a security researcher discovered it was using prompt steganography to monitor Chinese users. The hidden code sent information such as timezone, proxy, and potential connections to Chinese AI labs that Anthropic had previously accused of distillation attacks.
An Anthropic engineer confirmed the tracker was a March experiment meant to prevent account abuse from unauthorized resellers and protect against model theft. The incident drew criticism as a breach of user trust, especially given Anthropic’s stated anti-surveillance stance.
Comments