The new source of controversy between two of the world's leading technological nations is unfolding right now. In particular, on July 8, 2026, a cybersecurity portal operated by the Chinese Ministry of Industry and Information Technology warned that Anthropic's widely used AI coding application, Claude Code, has a dangerous backdoor vulnerability.
This accusation is officially published on the official website of China's National Vulnerability Database (NVDB).
As per the message published by NVDB on its WeChat channel, it seems that Claude Code has a monitoring system built within the application that can send private details, including geographic location and personal identifiers of the users, to external servers without any user consent.
This warning is not a general message with broad implications; it clearly specifies that specific versions of Claude Code have the problem. The important part about this is that there was no problem from the very beginning; rather, it emerged after some time and has now been fixed, at least according to the Chinese regulator.
China’s cybersecurity regulator did not limit itself to simply issuing a warning but took one additional step and instructed both organizations and users to take action on their end. It instructed them to examine their systems right away and to either delete the vulnerable version or update their software to the most recent version, which, according to the regulator, does not contain the suspected backdoor anymore. In addition, the NVDB instructed organizations to increase control of network access for development tools to external networks and monitor traffic of core business networks in order to prevent data leaks.
To provide some context, this is not some sort of obscure technical bulletin posted on some governmental webpage but an official statement by a governmental cybersecurity authority.
Surprisingly, the story didn’t start with some governmental statement. It began on… Reddit. According to the reporting, the catalyst of the incident was a post from June 30 in the r/ClaudeAI community, in which the author revealed having reverse-engineered Claude Code while attempting to fix an issue with disabling the remote control functionality.
What the author has supposedly discovered is quite unexpected. The post mentioned the obfuscation algorithm of detection that has supposedly been silently implemented since version 2.1.91, released on April 2, without any reference in the release notes. More to it, it is alleged that whenever a proxy was detected, the software verified if the timezone of the system matches Asia/Shanghai and Asia/Urumqi and also checked the proxy URL against the list of hardcoded Chinese websites and AI labs, including such names as Alibaba, Baidu, Ant Group, and ByteDance.
What is even more astonishing is that the way in which the information apparently escaped from the program was not through a clear signal but through a hidden way that included changing a date format and switching the punctuation mark in the system prompt that went to Anthropic's server.
If all of this is true, then the tool must have been trying to find out whether the individual using it came from China or any Chinese artificial intelligence laboratory without letting the user know about it.
Prior to the government’s official warning issued recently, one of China’s major technology firms was ahead of the game. Alibaba banned its workers from using the Claude code in any of their works starting July 10, based on security researchers’ claims about the existence of a backdoor.
According to the South China Morning Post, Alibaba has included Claude code in the list of dangerous software because it is known to have security loopholes due to back-door risks.
It isn’t that Alibaba simply asked its employees to stop using the code. It is claimed that the firm directed them to use Qoder, an in-house artificial intelligence coding system created by Alibaba.
Based on some reports, Alibaba went further and instructed its workers to uninstall all Anthropic software, which includes the Sonnet, Opus, and Fable families of models.
In order to explain the rapid development of the controversy, some background needs to be provided.
Anthropic and Chinese companies have had conflicts in the past weeks. On June 10, Anthropic wrote a letter to the leaders of the US Senate Banking Committee, alleging that the people working for the Qwen AI lab of Alibaba have been creating almost 25,000 fake accounts and created 28.8 million exchanges with Claude between April 22 and June 5.
This was described as an effort to industrially distill the software engineering and reasoning skills of Claude in a competing model.
For reference, distillation is the process of training an AI model with the data from a larger and better model.
This practice is still being debated ethically and legally within the AI community.
Alibaba has not admitted to any fault and has not commented on the particular accusations made against it. However, while writing to the legislators about the situation, Anthropic took more steps and imposed severe user restrictions, having blocked a considerable number of users from China without prior notice. This is consistent with the trend since Anthropic has been known for imposing the most restrictive access policy to China out of all frontier AI companies, which impose restrictions on China-based entities only.
It should be noted that despite the restrictions, Anthropic does not allow official access to its product by users or companies from China, although they can still be used in China through the usage of proxy services or via a VPN.
This becomes relevant due to the fact that it becomes clear why the users from China, especially those from Alibaba Group, were using Claude Code despite the ban.
At the time of this writing, Anthropic has made no formal statement concerning the above allegations. The company failed to provide any response in time to a CNBC query concerning the above, nor to AFP queries concerning this issue, which came to light through specialist technology press last week.
In terms of the reality on the ground for corporations, the situation is simple enough, certainly from the Chinese perspective. This is because the currently available version of Claude Code, as of this writing, Version 2.1.204, according to Anthropic's own website, is a more recent update and thus not in the problematic range listed by Chinese authorities.












