
China's National Vulnerability Database (NVDB) issued a serious security warning on Wednesday regarding Anthropic's AI coding tool, Claude Code. According to reports from Reuters and the Wall Street Journal, the cybersecurity platform operated by China's Ministry of Industry and Information Technology (MIIT) identified a serious security 'backdoor' risk in the AI coding tool. The warning was posted on the NVDB's WeChat account, highlighting the urgency of the security concern and calling the mechanism 'a serious threat' to users. The Chinese cybersecurity platform specifically stated that Claude Code's 'built-in monitoring mechanism' means that sensitive user information could be sent to a remote server without the user's consent. As per Yahoo Finance, the warning has raised questions about whether the tool could expose sensitive user data to unauthorized parties.
The NVDB identified that Claude Code contains a built-in monitoring mechanism capable of transmitting sensitive information to remote servers without user consent. As reported by Reuters and the Wall Street Journal, the tool is allegedly transmitting sensitive user information, including users' geographic location and identity-related identifiers to external servers. This mechanism operates without the knowledge or authorization of the users, raising significant privacy and security concerns. The Wall Street Journal specifically reports that versions of the tool released between April and June 2026 can send sensitive information such as user location and identity to remote servers without the user's consent. According to Anthropic, the company confirmed last week that it had embedded hidden code in Claude Code to track user locations in an attempt to stop illicit 'distillation' of its models. According to Yahoo Finance, the tool's alleged backdoor mechanism has drawn scrutiny for features that can help identify China-linked users.
The security warning applies specifically to Claude Code versions 2.1.91 through 2.1.196. According to Reuters, NVDB advised that organizations and users should immediately review affected systems and either uninstall the impacted versions or upgrade to the latest secure release where the alleged backdoor code has been removed. The database also urged organizations to tighten controls on external network access for development tools and strengthen traffic monitoring on core business networks. The Wall Street Journal notes that this guidance comes even though Claude Code isn't approved for public use in China, with the Chinese government requiring all AI LLMs to undergo review, which Anthropic's AI models did not complete. The NVDB specifically recommended that for developers that have installed the above-mentioned affected versions, they should immediately uninstall or upgrade to the latest secure version that has removed the relevant backdoor code.
The security concerns have already prompted action from major Chinese companies. As reported by Reuters, Alibaba has banned employees from using Claude Code at work after the tool drew scrutiny for features that can help identify China-linked users. Anthropic responded to the security allegations, stating that what was being described as a 'backdoor' was an experimental anti-abuse mechanism, and that access to Claude was not permitted in China. According to Wall Street Journal reports, Anthropic engineer Thariq Shihipar confirmed on X that it was an experiment launched in June 'to prevent account abuse from unauthorized resellers and protect against distillation'. He added that 'this should be fully rolled back in tomorrow's release', suggesting the tracking functions will no longer be hidden and will be baked directly into Claude Code. The company emphasized that users in China being advised to uninstall its flagship Claude Code product were not supposed to be using it in the first place.