China warns of backdoor in Anthropic's Claude Code versions 2.1.91-2.1.196
China's Ministry of Industry and Information Technology warned Wednesday that Anthropic's Claude Code AI coding tool contains a backdoor vulnerability in versions 2.1.91 to 2.1.196. Anthropic confirmed the backdoor was an anti-distillation experiment, as tensions escalate after the company last month accused Alibaba of attempting to extract its AI capabilities.
China warns of backdoor in Anthropic's Claude Code versions 2.1.91-2.1.196
China's Ministry of Industry and Information Technology issued a security warning Wednesday about Anthropic's Claude Code AI coding tool, stating that versions 2.1.91 through 2.1.196 contain a backdoor vulnerability that can transmit sensitive user data without consent.
According to the ministry's cybersecurity threat platform, the autonomous coding tool can send information including user location and identity to a remote server without user authorization. The affected versions span releases from April 2 to June 29, 2025. The current version as of July 8 is 2.1.204.
When contacted by CNBC, Anthropic acknowledged the backdoor, stating it was "an experiment earlier this year to protect against distillation." The company did not provide additional details about the experiment's scope or duration.
Escalating US-China AI tensions
The warning comes weeks after Anthropic accused Chinese tech giant Alibaba of attempting to extract its AI capabilities in June. Anthropic's tools are not officially available in China, though many Chinese users have found workarounds to access them.
Alibaba has ordered employees to stop using Anthropic tools for work starting July 10, CNBC confirmed. At a state-organized forum in March, a Xiaomi AI developer noted widespread use of Claude Code among Chinese developers.
Anthropric's usage policy explicitly prohibits use by entities majority-owned by China-headquartered organizations.
What this means
The incident highlights the increasingly fraught intersection of AI development and national security concerns. While Anthropic characterizes the backdoor as an anti-distillation measure—likely intended to prevent unauthorized model copying—its existence in production software raises questions about transparency in AI tool security. Users of affected Claude Code versions should upgrade immediately to version 2.1.204 or later. The disclosure may further complicate cross-border AI adoption as companies navigate competing security frameworks.
Related Articles
Anthropic Opens Cyber Verification Program to More Security Teams With Reduced Claude Safety Filters
Anthropic is expanding its Cyber Verification Program (CVP) to a much larger pool of vetted security professionals, giving them access to Claude's most powerful models with reduced safety filters. Access is split into three tiers: Defense, Red Team, and Specialized. Anthropic claims partners in its predecessor program, Project Glasswing, found at least 129,000 confirmed vulnerabilities between April and July 2026.
Claude Haiku 5.5 arrives on Amazon Bedrock; Anthropic claims ~75% lower cost than Haiku 4.5
Claude Haiku 5.5 is available on Amazon Bedrock and Claude Platform on AWS. According to Anthropic, it is the fastest and most efficient model in the Claude 5.5 family and costs around 75% less than Claude Haiku 4.5 for most tasks. It is the first Haiku model with effort controls.
Anthropic releases Claude Haiku 5.5, claims ~75% lower running cost than Haiku 4.5
Anthropic released Claude Haiku 5.5 on October 7, 2026. The company claims it costs around 75% less to run than Haiku 4.5 and is its fastest model to date. Anthropic also halved Claude Sonnet 5.5's cache read pricing and added a monthly API credit for Max and Team subscribers.
Anthropic Python SDK 1.12.0 adds claude-haiku-5-5 and typed computer and browser tool calls
Anthropic's Python SDK v1.12.0, dated 2026-10-07, adds the claude-haiku-5-5 model identifier and typed tool calls for the computer and browser toolsets. It also adds lifecycle fields to /v1/models and several admin API changes. The release notes give no pricing, context window, or benchmark data for the new model.
Comments
Loading...