Drooid Logo
Back to story perspectives

Full Breakdown

China Warns of “Security Backdoor” in Anthropic’s Claude Code AI Coding Tool

7/10/2026, 11:22:03 AM

Core Event

China’s National Vulnerability Database (NVDB), a cybersecurity platform under the Ministry of Industry and Information Technology, issued an advisory on Wednesday warning that certain versions of Anthropic’s Claude Code coding assistant may contain a “security backdoor” capable of transmitting users’ location data and identity-related identifiers to Anthropic’s servers without consent. The regulator urged institutions and individual users to “conduct a comprehensive check immediately” and either uninstall the affected versions or upgrade to a version where the alleged backdoor code has been removed.

Background & Context

Claude Code is an AI-driven coding agent that can generate, debug, and review software code based on natural-language prompts. Anthropic, a U.S. startup, blocks access to its products from China and other jurisdictions it labels “adversarial,” yet users can still reach the service via VPNs or third-party proxies. The warning follows a broader geopolitical contest over AI security, with Chinese authorities tightening scrutiny of foreign AI tools and U.S. firms defending their data-handling practices.

Key Figures & Groups

  • Anthropic – U.S. artificial-intelligence company that developed Claude Code.
  • Thariq Shihipar – Claude Code engineer who responded to the allegations on X (formerly Twitter).
  • National Vulnerability Database (NVDB) – China’s government-affiliated cybersecurity platform that issued the advisory.
  • Alibaba Group – Chinese technology conglomerate that instructed employees to cease using Claude Code from 10 July.

Official Statements & Responses

Anthropic told AFP that the contested mechanism checks a device’s timezone and whether a request routes through a domain linked to an “unsupported region or a known problematic entity,” describing it as a standard anti-fraud and abuse measure. The company has not issued a formal comment beyond this technical explanation. The NVDB advisory recommended immediate security reviews, removal of vulnerable software, and enhanced network-traffic monitoring to prevent unauthorized data leakage. Alibaba’s internal directive, reported by multiple outlets, mandates a ban on Claude Code usage beginning 10 July due to the alleged security risk.

Criticism & Opposition

Chinese regulators label the mechanism a “severe threat,” emphasizing potential unauthorized transmission of sensitive data. Anthropic’s engineers argue the feature was an experimental safeguard launched in March to curb “account abuse from unauthorized resellers” and protect against “distillation,” a process where competitors attempt to replicate proprietary AI models. Critics note that the lack of publicly disclosed technical evidence leaves the severity of the risk unverified, and the ban by Alibaba may reflect broader commercial tensions rather than a purely technical assessment.

Verbatim Quotes

  • “This is an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation,” — Thariq Shihipar, Claude Code engineer
  • “The team has landed stronger mitigations since then and we’ve actually been meaning to take this down for a while… this should be fully rolled back in tomorrow’s release.” — Thariq Shihipar, Claude Code engineer
  • “detected that the AI coding tool Claude Code contains security backdoor risks, posing a severe threat” — NVDB advisory
  • “to conduct a comprehensive check immediately” — NVDB advisory

Conflicting Reports & Gaps

  • Nature of the backdoor: Chinese authorities describe it as a covert channel for data exfiltration, while Anthropic frames it as an anti-abuse check. No independent technical analysis has been published to confirm either claim.
  • Evidence disclosure: The NVDB advisory provides no technical details or proof of exploitation, making it difficult to assess the actual risk level.
  • Scope of impact: Alibaba’s ban applies to its employees, but the advisory targets all Chinese users; the extent to which the alleged backdoor affects broader user populations remains unclear.

What’s Next

The NVDB has not announced a timeline for follow-up inspections, and Anthropic indicated that a software update intended to remove the experimental feature would be released “tomorrow.” Alibaba’s prohibition will take effect on 10 July, after which Chinese organizations may need to adopt alternative coding tools or seek further guidance from regulators.