China’s National Vulnerability Database (NVDB) has issued a cybersecurity warning about a suspected “security backdoor” embedded in certain versions of Anthropic’s AI coding tool, Claude Code. The backdoor risk reportedly allows the software to transmit sensitive user information, including location and identity-related data, back to Anthropic servers without user consent. This alert surfaced amid growing scrutiny over data security in AI tools.
What Happened
On July 8, 2026, China’s NVDB, associated with the Ministry of Industry and Information Technology, publicly disclosed that versions of Claude Code contain security backdoor vulnerabilities deemed a “severe threat.” Claude Code is an AI-powered coding agent developed by Anthropic, a U.S.-based AI company. The tool can generate programming code, debug software, and review user-submitted code snippets in response to prompts.
Although Anthropic restricts direct access to its tools for users in China and other designated countries, Chinese users have reportedly accessed Claude Code through VPNs and third-party proxy services. The NVDB cautioned institutions and individuals to conduct immediate security reviews, uninstall compromised versions, or upgrade to the latest secure releases that remove the backdoor code. Additionally, it recommended enhancing network traffic monitoring to detect and prevent unauthorized data leakage.
Chinese tech giant Alibaba has reportedly banned employee use of Claude Code from July 10, citing these security concerns. This development follows previous tensions, as Anthropic has accused Alibaba of reverse-engineering its AI models via a practice called “distillation.”
Key Facts
The NVDB’s official disclosure does not specify a CVE identifier or a CVSS score for the backdoor. The vulnerability concerns versions of Claude Code in circulation before recent patches. The backdoor allegedly allowed covert transmission of sensitive information such as user locations and identity-related identifiers back to Anthropic servers. Anthropic’s engineer Thariq Shihipar addressed the issue on social media, explaining that this data collection experiment started in March aimed to prevent account abuse from unauthorized resellers and to mitigate distillation risks.
Shihipar stated that stronger mitigations have been implemented since and the backdoor was planned for removal in the upcoming software release expected shortly after the NVDB announcement. Anthropic has not responded directly to AFP requests for comment on this matter.
What This Means
The detection of a backdoor in a prominent AI coding assistant raises significant concerns about privacy and data security, especially for users in jurisdictions with restricted direct access like China. The ability of software to transmit sensitive identifying information without explicit consent exposes users to privacy violations and potential targeted surveillance risks.
This incident highlights challenges in balancing AI tool functionality and security, especially when deployed across geopolitical boundaries with varying data protection standards. It also underscores the importance of vendor transparency and swift patch deployment to mitigate vulnerabilities.
For users and organizations, this serves as a reminder to scrutinize AI tools for hidden data collection mechanisms and maintain vigilant network monitoring. Enterprises like Alibaba taking proactive steps to restrict risky software use reflect increasing sensitivity to insider threats and compliance requirements in technology operations.
Background
Anthropic’s Claude line of AI assistants has faced prior claims of intellectual property disputes, particularly allegations against Alibaba for “distillation”—a process where AI models are reverse-engineered to replicate capability. The recent publicity around the backdoor coincides with ongoing friction between Chinese tech firms and U.S.-based AI developers over IP and data security.
What Comes Next
Anthropic plans to release an updated version of Claude Code with the backdoor fully removed, as confirmed by engineer Thariq Shihipar. Users and organizations are urged by the NVDB to upgrade promptly and continue monitoring network traffic for unauthorized data transmissions until the patch is applied.
Sources
This article is based on reporting and publicly available information from the following source:
Read more Cybersecurity stories on Goka World News.
