Artificial IntelligenceBigTech CompaniesCybersecurityNewswireWhat's Buzzing

Claude’s secret tracker contradicts Anthropic’s anti-surveillance stance

▼ Summary

– Anthropic secretly added a tracker to Claude Code that used “prompt steganography” to monitor Chinese users by sending data like timezone and proxy information without their knowledge.
– Security researcher “Thereallo” exposed the hidden code, condemning it as a spyware-like “serious breach of user trust.”
– Anthropic engineer Thariq Shihipar confirmed the tracker was an “experiment” from March, intended to prevent account abuse and distillation attacks.
– The hidden code was reportedly meant to be removed because stronger mitigations had since been implemented.
– Privacy advocates criticized Anthropic for crossing surveillance lines, contrasting this with the firm’s refusal to let the US government use Claude for domestic surveillance.

A hidden tracking mechanism secretly monitoring Claude Code users in China was hastily removed by Anthropic after a security researcher exposed the code and condemned it as a “serious breach of user trust,” raising questions about the company’s commitment to privacy.

Last week, a web developer identified as “Thereallo” was investigating privacy vulnerabilities within Claude Code when they discovered that Anthropic had employed “prompt steganography” to conceal code that tracks Chinese users “in plain sight.” While not malicious, this hidden code transmitted information to Anthropic without most users’ knowledge, using shorthand markers to quietly flag timezone data, proxy usage, and potential connections to Chinese AI labs that the company has previously accused of distillation attacks.

On X, Anthropic engineer Thariq Shihipar confirmed the tracker was added to Claude Code as an “experiment” in March. According to Shihipar, the code “was meant to prevent account abuse from unauthorized resellers and protect against distillation.” The Washington Post previously reported that unauthorized retailers have sold access to free models for $1 a month, while pro subscriptions that normally cost $100 monthly have been offered for “as little as $12.”

Shihipar claimed Anthropic had “actually been meaning to take this down for a while” because engineers have “landed stronger mitigations since then.”

Privacy advocates rejected this explanation, warning that the hidden code demonstrates Anthropic’s willingness to cross surveillance lines. The revelation is particularly striking given that Anthropic recently angered the Trump administration by refusing to allow the US government to use Claude for surveilling American users. The AI firm has since filed a lawsuit against the White House over that dispute.

(Source: Ars Technica)

Topics

user tracking 95% prompt steganography 92% security research 90% privacy breach 88% account abuse prevention 85% distillation attacks 83% unauthorized resellers 80% corporate transparency 78% user surveillance 76% government surveillance 74%