Escalation in the AI dispute China Warns of "Backdoor" in Claude Code—Anthropic Disagrees

From Henrik Bork Henrik Bork | Translated by AI 6 min Reading Time

China's vulnerability platform NVDB classifies older versions of Claude Code as a security risk. Anthropic, on the other hand, refers to a protection mechanism that has since been removed. Behind this lies a growing conflict over model theft, access restrictions, and technological dependencies.

China warns of "backdoor" in Claude Code – Anthropic disagrees.(Image: Anthropic)
China warns of "backdoor" in Claude Code – Anthropic disagrees.
(Image: Anthropic)

China has warned of a security risk in older versions of Claude Code. The National Vulnerability Database (NVDB), operated by the Ministry of Industry and Information Technology, issued a warning on July 8, 2026, about a built-in "backdoor."

Claude Code is an AI tool from the American company Anthropic. Users receive highly powerful assistance in the terminal window of their computers for programming and other tasks. Depending on the configuration, the tool can gain direct access to local files, development tools, and external services.

However, according to China's warning, Claude Code could transmit sensitive information such as users' location and identity details to remote servers without their consent, reports the Chinese business magazine Caixin.

The affected versions are 2.1.91 to 2.1.196, the NVDB announced via social media, Reuters additionally reported. Companies should immediately check their systems and either uninstall the software or switch to a cleaned newer version. Furthermore, the authority advised stricter control of external network access from development tools to prevent the "unauthorized transfer of sensitive data."

Anthropic versus Alibaba

The warning is the latest escalation in an increasingly tense exchange between Anthropic, Chinese technology companies, and the government in Beijing. In June 2026, Anthropic accused Alibaba of carrying out the "largest known distillation attack" on its AI models in a letter to leading members of the U.S. Senate Banking Committee, as reported by the American television network CNBC. According to the letter, actors associated with Alibaba and its language model Qwen carried out 28.8 million interactions with Claude between April 22 and June 5 using approximately 25,000 fake accounts.

In distillation, a weaker AI model is trained with the answers of a stronger one. The procedure is generally common in the AI industry and can be used legitimately. Anthropic's accusation primarily targets the alleged use of fake accounts, circumvention of access restrictions, and the scope of the operation. Alibaba has not commented on the allegations.

At the beginning of July, Alibaba responded with an internal ban on the American software. The company placed Claude Code on its internal high-risk software list and prohibited its employees from using all Anthropic products starting July 10, 2026, as reported by Caixin. Employees must uninstall the tools and switch to the in-house AI assistant "Qoder."

Anthropic countered that the use of Claude Code had never been permitted in China anyway. The company's usage policies had always prohibited access from China, the South China Morning Post (SCMP) quoted a company spokesperson as saying.

Ineffective User Block?

Since July 2024, Anthropic has officially blocked users in mainland China and Hong Kong, and since September 2025, all majority Chinese-controlled companies worldwide. However, the U.S. software remains very popular among many programmers in China, even though it was never officially offered there by Anthropic.

Anthropic has admitted to using a covert mechanism to detect China-related user environments. This was a test launched in March to counter abuse and distillation, explained Anthropic technician Thariq Shihipar in response to an article by the specialist publication International Cyber Digest. The mechanism has since been removed. Anthropic is currently running version 2.1.220 as the latest edition of Claude Code.

The location mechanism cited in the Chinese warning is a "direct and unacceptable security risk" for any Chinese company, said Cai Peng, a partner at the Beijing law firm Zhong Lun, to the SCMP. Given Anthropic's "hostile" stance toward China, he was not surprised by the counterreaction. More Chinese companies are likely to follow, the lawyer added.

AI is Not Classic Software

The dispute cannot be separated from the general AI race between China and the USA. "Chinese companies will need to evaluate AI providers not just as classic software suppliers, but as strategic suppliers whose reliability can be influenced by geopolitics and national security," said Ben Hu of the Hong Kong China Network Security Association.

As with any highly politicized dispute, there are collateral damages this time as well. In Hong Kong, Goldman Sachs and JPMorgan Chase have cut off their bankers' access to Anthropic models, strictly interpreting the terms of use. "Restricting access to the world's most advanced AI models threatens Hong Kong's resurgence as an international financial center, given their rapid adoption in other parts of the world, especially in programming," warned the Financial Times. The restrictions demonstrate that Anthropic's regional terms of use are now also affecting international companies in Hong Kong.

Subscribe to the newsletter now

Don't Miss out on Our Best Content

By clicking on „Subscribe to Newsletter“ I agree to the processing and use of my data according to the consent form (please expand for details) and accept the Terms of Use. For more information, please see our Privacy Policy. The consent declaration relates, among other things, to the sending of editorial newsletters by email and to data matching for marketing purposes with selected advertising partners (e.g., LinkedIn, Google, Meta)

Unfold for details of your consent

One factor driving the growing demand for Chinese models is the price. Deepseeks' top model, V4 Pro, is nearly 60 times cheaper per token output compared to Anthropic's Fable 5. Minimax M2.7, Xiaomi's Mimo V2.5 Pro, and Alibaba's Qwen3.7 Max perform well in price-performance rankings by the American benchmark firm Artificial Analysis. "The performance of Chinese models like Deepseeks V4 Pro, GLM, Kimi, Minimax, and Qwen is increasingly on par with American AI," wrote Agathe Demarais from the European Council on Foreign Relations in the Financial Times.

Above all, several highly sought-after Chinese models are being released with open weights. Customers can download these, adapt them to their own requirements within the respective licensing terms, and in some cases, operate them on their own infrastructure. This reduces the risk of suddenly losing access to an already downloaded model due to a provider's access block. "The demand for Chinese models has already surpassed that for U.S. models on Openrouter," journalist Nicholas Gordon recently wrote in Fortune magazine. His statement refers to the token volume processed via Openrouter, where Chinese models overtook American providers in early June. A nation relying on foreign technology could "have the plug pulled overnight," warned former French Interior Minister Bruno Retailleau in recent times.

For Anthropic CEO Dario Amodei, the escalation comes at a bad time, as his company confidentially filed documents for an IPO with U.S. authorities on June 1. Amodei has long warned of the danger from China. He portrays himself as the conscience of the AI industry and calls on the U.S. government to keep authoritarian states away from the most powerful models. In its letter to the U.S. Senate, the company also urged Congress to close loopholes for Chinese AI labs and punish unauthorized distillation attacks.

The U.S. government in Washington now takes such warnings very seriously. Leading government officials recently announced investigations, financial sanctions, and trade restrictions against Chinese AI companies accused of unauthorized distillation of American models. On July 27, China referred to this as "AI hegemonism" and threatened countermeasures.

Already on June 12, the U.S. Department of Commerce restricted access to the then-new Anthropic models Fable 5 and Mythos 5 for foreign users. Since Anthropic was unable to reliably verify the nationality of its users in real-time, the company initially took both models offline worldwide—even for its own foreign employees. However, the export controls were lifted on June 30. Fable 5 has been globally available again since July 1, while Mythos 5 remains accessible to a limited user group. The incident nevertheless demonstrated how quickly access to a strategically important AI technology can be disrupted by political decisions.

Commentators like former financial trader Patrick Boyle see Anthropics' public relations and constant warnings about China as possibly backfiring, he argues in essence. "Telling authorities you've built a weapon and then being shocked when they treat it as such is, all in all, poor corporate governance," Boyle mocked Amodei.