Skip to main content
Live
Main content

China flags Anthropic's Claude Code as a security back-door risk

Beijing's cybersecurity platform tells users to uninstall or upgrade Claude Code versions 2.1.91 through 2.1.196, released April 2 to June 29.

Jaeden Schafer
Editor in Chief · · 4 min read
Anthropic logo

China's Ministry of Industry and Information Technology on Wednesday warned that Anthropic's Claude Code contains a back-door vulnerability, telling domestic users to uninstall or upgrade versions 2.1.91 through 2.1.196. The flagged range covers roughly three months of releases, from April 2 to June 29, according to Anthropic's own version history. The current build, 2.1.204, is three point releases past the ministry's cutoff.

The MIIT's cybersecurity threat platform said Claude Code can send sensitive information to a remote server without user consent, including location and identity data. The statement described the flaw as a "security back-door vulnerability that poses a serious threat." It did not publish technical details, a proof-of-concept, or a CVE identifier.

Anthropic did not immediately respond to a request for comment on the advisory. Claude Code is not officially sold in China, which makes the ministry's warning notable — Beijing is telling users to stop running a product that Anthropic does not formally distribute in the country.

Key facts

  • 01China's Ministry of Industry and Information Technology said Claude Code contains a back-door vulnerability that can exfiltrate user location and identity without consent.
  • 02The advisory names Claude Code versions 2.1.91 to 2.1.196, covering releases from April 2 to June 29, and tells users to uninstall or upgrade.
  • 03Anthropic's latest Claude Code build as of Wednesday is 2.1.204, three point releases past the flagged range.
  • 04Alibaba ordered employees to stop using Anthropic tools for work starting July 10, a week after Anthropic accused the company of trying to extract its AI capabilities.
  • 05Claude is not officially available in China, but Xiaomi AI developers publicly acknowledged using Claude Code at a state-organized forum in March.

The advisory lands one week before Alibaba's internal ban on Anthropic tools takes effect on July 10. CNBC confirmed on Monday that Alibaba has ordered employees to stop using Anthropic products for work. Last month, Anthropic publicly accused Alibaba of attempting to extract its AI capabilities. Alibaba did not comment on the accusation at the time.

The sequence — Anthropic accuses Alibaba, Alibaba bans Anthropic internally, MIIT flags Claude Code nationally — reads as a coordinated escalation rather than an isolated security disclosure. Chinese state cybersecurity platforms have previously issued similar advisories against foreign chip and software vendors during periods of trade friction with Washington.

Despite the lack of official availability, Claude Code has real users inside China. In March, a Xiaomi AI developer said at a state-organized forum that many engineers were using the tool. Chinese developers routinely reach US AI products through VPNs, third-party proxies, and API resellers, and Claude Code's terminal-native workflow has made it a favorite for autonomous coding tasks worldwide.

The technical claim in the advisory — that Claude Code transmits telemetry to remote servers — is not by itself unusual. Most modern developer tools, including competing coding assistants from OpenAI, Google, and Chinese vendors, send telemetry, crash reports, and usage data back to their operators. Whether that constitutes a "back door" depends on scope, disclosure, and user consent, none of which the MIIT statement specified.

For Anthropic, the practical impact inside China is limited because the product was never officially sold there. The reputational impact outside China is a different question. Anthropic has spent 2026 pitching Claude Code as an enterprise-grade agentic coding tool, and a foreign-government security advisory — however politically motivated — becomes a talking point for procurement teams and rival vendors in markets where the product does compete.

Related · from this week
Alibaba moves to ban employees from using Anthropic's Claude Code
Jaeden Schafer · 4 min read →

The broader pattern is one AI Chat Daily has tracked across recent coverage of DeepSeek's move to in-house inference chips and Microsoft's shift toward its own MAI models: the AI stack is fragmenting along national lines faster than the technology is maturing. Chinese cloud vendors, Chinese chipmakers, and now Chinese regulators are drawing hard perimeters around what US AI products employees and enterprises are allowed to touch.

The MIIT notice is thin on forensic evidence, and Anthropic has not been given a public window to respond before the advisory landed. Independent security researchers outside China have not yet corroborated the back-door claim, and no CVE has been filed against the affected versions. Readers should treat the technical specifics as unverified until a second source publishes analysis.

The strategic read is clearer than the technical one. Anthropic is now a named target in Beijing's AI-decoupling playbook, joining a short list of US frontier labs whose products are being formally warned against inside China. That closes off a gray-market user base Anthropic was never officially serving, but it also hardens the split that will define how enterprise AI gets sold for the rest of the decade — one stack for the US and its allies, another for China, and vanishing overlap in the middle.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Business

Alibaba moves to ban employees from using Anthropic's Claude Code

The Chinese cloud giant is cutting off internal access to Claude Code as US export controls tighten around frontier AI tools.

Jaeden Schafer4 min read
Anthropic logo
Security

Anthropic disrupts Russian and Chinese campaigns abusing Claude

The company says state-linked operators tried to weaponize its Claude models; access has been cut and accounts terminated.

Jaeden Schafer4 min read
Anthropic logo
Security

Anthropic accuses Alibaba of 28.8M-query distillation attack on Claude

A letter to the Senate Banking Committee calls it the largest known distillation attack on Anthropic to date.

Jaeden Schafer5 min read