The Decoder:AI News(RSS)
同事件
81AI 编辑部评分,满分 100

Claude Code 被曝内置隐蔽检测中国用户代码,Anthropic 已回滚

2026-07-01 19:27· 45天前· Maximilian Schreiner
AI 导读

网友发现,Claude Code 从 2.1.91 版本起,通过系统提示词中的隐写术(比对时区、代理 URL 及中国 AI 实验室域名)秘密判别用户是否位于中国,结果通过不易察觉的格式差异传输。代码使用 XOR 加密(密钥 91)隐藏,未出现在发布说明中。发现者称此举“根本性违反用户信任”。Anthropic 员工解释这是 3 月启动的实验,旨在防止账户滥用和知识蒸馏,团队已合并回滚请求,次日版本完全移除。Anthropic 因国家安全原因未在中国提供模型,此前曾指控 DeepSeek、月之暗面、MiniMax 和阿里巴巴未经授权使用 Claude 输出训练模型。

Image description

Anthropic / NBPro prompted by THE DECODER

Anthropic is rolling back a covert surveillance feature in its coding tool Claude Code after it sparked outrage on social media.

Reddit post by user LegitMichel777 first exposed the feature. According to the post, Claude Code has been secretly checking since version 2.1.91, released April 2, 2026, whether users with an active proxy are located in China, routing through a Chinese URL, or connected to a Chinese AI lab.

Hidden signals buried in the system prompt

The data gets transmitted through barely perceptible changes to the system prompt, a form of steganography. Claude Code compares the system timezone against "Asia/Shanghai" or "Asia/Urumqi" and scans the proxy URL for Chinese domains and AI labs. Based on the results, the software tweaks the date format and swaps in a subtly different apostrophe character in the phrase "Today's date is." Users can't see the difference. Anthropic can read it instantly.

According to LegitMichel777, Anthropic also obfuscated the code using XOR encryption with key 91, keeping it from showing up in a simple text dump. The release notes for version 2.1.91 made no mention of the check.

The discoverer called the covert transmission of system and proxy data without user knowledge "a fundamental violation of user trust." Since Claude Code has full filesystem and shell access, this would open the door to all kinds of abuse, from remote control to data exfiltration. He also argued that the check is trivial for skilled attackers to bypass, calling its usefulness into question.

Anthropic calls it an experiment

Anthropic employee Thariq Shihipar, who works on the Claude Code team, described the feature on X as "an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation." The team had since shipped stronger protections: "The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while." They had merged the corresponding pull request: "We merged the PR and this should be fully rolled back in tomorrow's release."

Anthropic doesn't offer its models in China for national security reasons. Still, many Chinese developers access Claude through foreign phone numbers and credit cards. Anthropic had previously accused DeepSeek, Moonshot AI, MiniMax, and Alibaba of using Claude model outputs without permission to train their own language models.

来源:The Decoder:AI News(RSS) · the-decoder.com

同一事件 · 2

Claude Code 被曝内置隐蔽检测中国用户代码,Anthropic 已回滚

The Decoder:AI News(RSS)·2026-07-01 19:27·45天前·Maximilian Schreiner
AI 导读

网友发现,Claude Code 从 2.1.91 版本起,通过系统提示词中的隐写术(比对时区、代理 URL 及中国 AI 实验室域名)秘密判别用户是否位于中国,结果通过不易察觉的格式差异传输。代码使用 XOR 加密(密钥 91)隐藏,未出现在发布说明中。发现者称此举“根本性违反用户信任”。Anthropic 员工解释这是 3 月启动的实验,旨在防止账户滥用和知识蒸馏,团队已合并回滚请求,次日版本完全移除。Anthropic 因国家安全原因未在中国提供模型,此前曾指控 DeepSeek、月之暗面、MiniMax 和阿里巴巴未经授权使用 Claude 输出训练模型。

原文 · 保持原样,未翻译
Image description

Anthropic / NBPro prompted by THE DECODER

Anthropic is rolling back a covert surveillance feature in its coding tool Claude Code after it sparked outrage on social media.

Reddit post by user LegitMichel777 first exposed the feature. According to the post, Claude Code has been secretly checking since version 2.1.91, released April 2, 2026, whether users with an active proxy are located in China, routing through a Chinese URL, or connected to a Chinese AI lab.

Hidden signals buried in the system prompt

The data gets transmitted through barely perceptible changes to the system prompt, a form of steganography. Claude Code compares the system timezone against "Asia/Shanghai" or "Asia/Urumqi" and scans the proxy URL for Chinese domains and AI labs. Based on the results, the software tweaks the date format and swaps in a subtly different apostrophe character in the phrase "Today's date is." Users can't see the difference. Anthropic can read it instantly.

According to LegitMichel777, Anthropic also obfuscated the code using XOR encryption with key 91, keeping it from showing up in a simple text dump. The release notes for version 2.1.91 made no mention of the check.

The discoverer called the covert transmission of system and proxy data without user knowledge "a fundamental violation of user trust." Since Claude Code has full filesystem and shell access, this would open the door to all kinds of abuse, from remote control to data exfiltration. He also argued that the check is trivial for skilled attackers to bypass, calling its usefulness into question.

Anthropic calls it an experiment

Anthropic employee Thariq Shihipar, who works on the Claude Code team, described the feature on X as "an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation." The team had since shipped stronger protections: "The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while." They had merged the corresponding pull request: "We merged the PR and this should be fully rolled back in tomorrow's release."

Anthropic doesn't offer its models in China for national security reasons. Still, many Chinese developers access Claude through foreign phone numbers and credit cards. Anthropic had previously accused DeepSeek, Moonshot AI, MiniMax, and Alibaba of using Claude model outputs without permission to train their own language models.

来源:The Decoder:AI News(RSS)· the-decoder.com

同一事件 · 2