Home NewsChina’s Government Just Officially Called Claude Code a Security Threat. The Backstory Is Complicated.

China’s Government Just Officially Called Claude Code a Security Threat. The Backstory Is Complicated.

by Freddy Miller
18 views

China’s National Vulnerability Database, a cybersecurity platform affiliated with the Ministry of Industry and Information Technology, issued a formal security warning on Wednesday declaring that Anthropic’s Claude Code AI coding tool contains backdoor vulnerabilities that pose a serious threat. The warning specified affected versions as Claude Code 2.1.91 through 2.1.196 and advised organizations and users to immediately review affected systems and either uninstall the impacted versions or upgrade to the latest release, in which the relevant code has reportedly been removed. The NVDB stated that the mechanism was capable of transmitting sensitive information – including users’ geographic location and identity-related identifiers – to remote servers without user consent. NEWSCENTRAL notes that the Chinese government’s formal designation of an American AI tool as a national security risk, announced the same week that Alibaba officially banned Claude Code for all employees, is not simply a technical disclosure: it is a regulatory escalation in a commercial dispute that has been building for more than a month.

The origin of the allegation traces to a June 30 post in which a developer claimed to have reverse-engineered Claude Code and discovered obfuscated detection logic that had been present since version 2.1.91, released on April 2. The code allegedly checked whether a user’s system timezone matched Asia/Shanghai or Asia/Urumqi and inspected proxy server URLs against a hardcoded list of Chinese domain patterns. When those conditions were met, the behavior of the tool would subtly differ – not transmitting data back to Anthropic in any obvious way, but altering outputs in ways consistent with a detection and suppression mechanism targeting users who were accessing Claude Code through Chinese network infrastructure. A member of Anthropic’s Claude Code team acknowledged the mechanism publicly, describing it as designed to counter large-scale account abuse and unauthorized model distillation, and said a fix removing it was already in progress as of July 1.

The legal and commercial distinction Anthropic would draw between a security backdoor and an anti-abuse detection routine is technically meaningful. A backdoor transmits data to an unauthorized party; a detection mechanism that modifies behavior for users accessing through prohibited channels is, Anthropic would argue, an enforcement tool rather than a surveillance instrument. Whether that distinction survives regulatory scrutiny depends entirely on whose regulatory framework is applying it. Nathan Clark, Enterprise IT and Systems Architecture Analyst at NEWSCENTRAL, observes that from the perspective of any enterprise IT security team evaluating the tool, the distinction has limited operational significance: undisclosed code that alters behavior based on network-identity detection is a risk factor regardless of the developer’s stated intent, because the presence of such code demonstrates that the tool’s behavior in production differs from its documented behavior, which is the definition of a security concern in institutional risk assessment.

The timeline places the allegation inside a sustained sequence of escalations between Anthropic and Chinese technology companies. In June, Anthropic accused operators linked to Alibaba’s Qwen AI division of conducting the largest known model distillation attack against Claude, involving approximately 25,000 fraudulent accounts and more than 28 million interactions. Alibaba has not publicly addressed that allegation. Days later, Alibaba announced that Claude Code would be banned for employees starting July 10. Now China’s Ministry of Industry and Information Technology platform has formally characterized Claude Code as a security threat, elevating a corporate dispute into an official government-level technology security designation.

NEWSCENTRAL finds the NVDB designation analytically interesting for a reason beyond the immediate dispute: it is the first time that China’s Ministry of Industry and Information Technology has formally characterized a specific AI coding tool as a national security risk using its official vulnerability database mechanism, setting a precedent for how the Chinese government can respond to AI tool usage controversies with the weight of regulatory authority rather than simply corporate or institutional reaction.

Anthropic has not issued a public response to the NVDB warning. The company’s baseline position – that it is the only major frontier AI lab that explicitly restricts access to Chinese-owned entities, even through international subsidiaries – makes the situation structurally awkward: the tool that China is now warning against was one that Chinese developers were accessing in violation of Anthropic’s own terms of service through proxies, and the detection mechanism that triggered the controversy was apparently designed to identify and address exactly that kind of access. What NEWS CENTRAL tracks as the more durable consequence of this episode is not the specific technical dispute but the formal Chinese government designation, which will now be cited in procurement discussions, security assessments, and regulatory proceedings well beyond Alibaba and well beyond this specific version range.