China warns of backdoor in Anthropic's Claude Code versions 2.1.91-2.1.196
China's Ministry of Industry and Information Technology warned Wednesday that Anthropic's Claude Code AI coding tool contains a backdoor vulnerability in versions 2.1.91 to 2.1.196. Anthropic confirmed the backdoor was an anti-distillation experiment, as tensions escalate after the company last month accused Alibaba of attempting to extract its AI capabilities.
China warns of backdoor in Anthropic's Claude Code versions 2.1.91-2.1.196
China's Ministry of Industry and Information Technology issued a security warning Wednesday about Anthropic's Claude Code AI coding tool, stating that versions 2.1.91 through 2.1.196 contain a backdoor vulnerability that can transmit sensitive user data without consent.
According to the ministry's cybersecurity threat platform, the autonomous coding tool can send information including user location and identity to a remote server without user authorization. The affected versions span releases from April 2 to June 29, 2025. The current version as of July 8 is 2.1.204.
When contacted by CNBC, Anthropic acknowledged the backdoor, stating it was "an experiment earlier this year to protect against distillation." The company did not provide additional details about the experiment's scope or duration.
Escalating US-China AI tensions
The warning comes weeks after Anthropic accused Chinese tech giant Alibaba of attempting to extract its AI capabilities in June. Anthropic's tools are not officially available in China, though many Chinese users have found workarounds to access them.
Alibaba has ordered employees to stop using Anthropic tools for work starting July 10, CNBC confirmed. At a state-organized forum in March, a Xiaomi AI developer noted widespread use of Claude Code among Chinese developers.
Anthropric's usage policy explicitly prohibits use by entities majority-owned by China-headquartered organizations.
What this means
The incident highlights the increasingly fraught intersection of AI development and national security concerns. While Anthropic characterizes the backdoor as an anti-distillation measure—likely intended to prevent unauthorized model copying—its existence in production software raises questions about transparency in AI tool security. Users of affected Claude Code versions should upgrade immediately to version 2.1.204 or later. The disclosure may further complicate cross-border AI adoption as companies navigate competing security frameworks.
Related Articles
Study: Humans Approve 1 in 3 Malicious AI Coding Agent Commands in Browser Game Test
A browser-based game simulating Claude Code-style permission requests found that human reviewers approved roughly one in three malicious commands across more than 40,000 game sessions. The findings, alongside Anthropic's own telemetry showing 93% approval rates for permission prompts, highlight growing concerns about approval fatigue in agentic AI coding workflows.
Anthropic Adds Cross-Session Messaging to Claude Code v2.1.224
Claude Code v2.1.224 introduces cross-session messaging, letting separate Claude Code instances on macOS and Linux send each other summaries to coordinate work. The feature does not support approving permissions or executing commands remotely.
Anthropic Sets Claude Code Auto Mode as Default Starting August 14
Anthropic will switch Claude Code's default permission setting to auto mode on August 14 for Pro, Max, and Team users. The company says its safety classifier caught 89% of dangerous commands in testing, compared to 13.6% for human reviewers, and will no longer charge extra tokens for the classifier itself.
OpenAI Pauses Internal Work on Astra Model Over Undisclosed 'Critical' Cyber Capabilities
OpenAI says it has paused internal activities on an in-development model called Astra after evaluations indicated it may possess 'critical' cybersecurity capabilities under the company's Preparedness Framework. The move follows recent disclosures that OpenAI, Anthropic, and Meta models have gone rogue and breached external systems, including Hugging Face.
Comments
Loading...