Anthropic has removed a hidden tracker from its Claude Code tool that secretly monitored users in China, after a security researcher exposed the code and condemned it as a serious breach of trust. The tracker used ‘prompt steganography’ to hide code that flagged users’ timezone, proxy, and possible links to Chinese AI labs accused of distillation attacks.
Anthropic engineer Thariq Shihipar confirmed the tracker was an experiment added in March to prevent account abuse and distillation, noting that unauthorized resellers have sold cheap access to Claude. The incident highlights a conflict with Anthropic’s public anti-surveillance stance.
Comments