# Claude Code被指暗中检测中国路由，通过隐藏标记嵌入提示词

- 来源：Rohan Paul (@rohanpaul_ai)
- 发布时间：2026-07-01 01:29
- AIHOT 分数：69
- AIHOT 链接：https://aihot.virxact.com/items/cmr0xb9k6003aslb3bafdbcls
- 原文链接：https://x.com/rohanpaul_ai/status/2072009571569467658

## AI 摘要

X用户Rohan Paul爆料，Anthropic的编程AI智能体Claude Code在用户更改非默认`ANTHROPIC_BASE_URL`（使用代理/网关）时，会检测自定义主机名是否关联中国域名，若匹配则通过不可见标点符号和日期格式向提示词嵌入隐藏标记。引用@IntCyberDigest指出，Claude Code还会在系统提示内注入时区、代理及可能的AI实验室连接信息，用户无法察觉。作为可读取仓库、编辑代码和执行命令的智能体，这种隐蔽行为严重破坏用户信任，并可能为AI智能体难以审计开先例。

## 正文

wow 👀

Claude Code allegedly fingerprints China-linked custom routes through tiny prompt formatting changes.

The claim concerns non-default ANTHROPIC_BASE_URL routes， not ordinary direct Anthropic connections.

As to the mechanism， Claude Code normally sends your request to Anthropic's server， but some users change the address so it goes through another server first.

The accusation says Claude Code detects that changed route， checks whether it looks China-linked， then hides tiny signals inside the prompt text.

ANTHROPIC_BASE_URL is a setting that tells Claude Code where to send your request i.e. as a way to point Claude Code at a gateway. A proxy or gateway means that request goes through another server before reaching Anthropic.

So the controversy starts if Claude Code then secretly fingerprints that gateway through the prompt itself.

The mechanism is allegedly invisible punctuation and date formatting， used to tag the request without clearly telling the user.

Claude Code allegedly checks the custom hostname， then compares it with China-linked domains.

📍Now this is quite massive issue

If true， hidden prompt markers would mean Claude Code silently tagged routing details without clear disclosure.

Abuse detection is understandable because Anthropic says proxy services are used to bypass China access limits. But secret prompt marking still crosses a trust line because users cannot review or refuse it.

Claude Code is not a normal chatbot because it can read files， edit code， and run commands. A hidden signal inside that kind of tool feels far more serious than tracking inside a website.

This may set a precedent for AI agents becoming hard to audit. Once invisible characters carry metadata， users will distrust even harmless-looking text.

### 引用推文

> International Cyber Digest：!!️ BREAKING: Anthropic has embedded hidden spyware-like code in Claude Code that covertly targets Chinese users. It then sends information regarding every user...
