Escalation in the AI disputeChina Warns of "Backdoor" in Claude Code—Anthropic Disagrees
From
Henrik Bork
Henrik Bork | Translated by AI
6 min Reading Time
China's vulnerability platform NVDB classifies older versions of Claude Code as a security risk. Anthropic, on the other hand, refers to a protection mechanism that has since been removed. Behind this lies a growing conflict over model theft, access restrictions, and technological dependencies.
China warns of "backdoor" in Claude Code – Anthropic disagrees.
(Image: Anthropic)
China has warned of a security risk in older versions of Claude Code. The National Vulnerability Database (NVDB), operated by the Ministry of Industry and Information Technology, issued a warning on July 8, 2026, about a built-in "backdoor."
Claude Code is an AI tool from the American company Anthropic. Users receive highly powerful assistance in the terminal window of their computers for programming and other tasks. Depending on the configuration, the tool can gain direct access to local files, development tools, and external services.
However, according to China's warning, Claude Code could transmit sensitive information such as users' location and identity details to remote servers without their consent, reports the Chinese business magazine Caixin.
The affected versions are 2.1.91 to 2.1.196, the NVDB announced via social media, Reuters additionally reported. Companies should immediately check their systems and either uninstall the software or switch to a cleaned newer version. Furthermore, the authority advised stricter control of external network access from development tools to prevent the "unauthorized transfer of sensitive data."
Anthropic versus Alibaba
The warning is the latest escalation in an increasingly tense exchange between Anthropic, Chinese technology companies, and the government in Beijing. In June 2026, Anthropic accused Alibaba of carrying out the "largest known distillation attack" on its AI models in a letter to leading members of the U.S. Senate Banking Committee, as reported by the American television network CNBC. According to the letter, actors associated with Alibaba and its language model Qwen carried out 28.8 million interactions with Claude between April 22 and June 5 using approximately 25,000 fake accounts.
In distillation, a weaker AI model is trained with the answers of a stronger one. The procedure is generally common in the AI industry and can be used legitimately. Anthropic's accusation primarily targets the alleged use of fake accounts, circumvention of access restrictions, and the scope of the operation. Alibaba has not commented on the allegations.
At the beginning of July, Alibaba responded with an internal ban on the American software. The company placed Claude Code on its internal high-risk software list and prohibited its employees from using all Anthropic products starting July 10, 2026, as reported by Caixin. Employees must uninstall the tools and switch to the in-house AI assistant "Qoder."
Anthropic countered that the use of Claude Code had never been permitted in China anyway. The company's usage policies had always prohibited access from China, the South China Morning Post (SCMP) quoted a company spokesperson as saying.
Since July 2024, Anthropic has officially blocked users in mainland China and Hong Kong, and since September 2025, all majority Chinese-controlled companies worldwide. However, the U.S. software remains very popular among many programmers in China, even though it was never officially offered there by Anthropic.
Anthropic has admitted to using a covert mechanism to detect China-related user environments. This was a test launched in March to counter abuse and distillation, explained Anthropic technician Thariq Shihipar in response to an article by the specialist publication International Cyber Digest. The mechanism has since been removed. Anthropic is currently running version 2.1.220 as the latest edition of Claude Code.
The location mechanism cited in the Chinese warning is a "direct and unacceptable security risk" for any Chinese company, said Cai Peng, a partner at the Beijing law firm Zhong Lun, to the SCMP. Given Anthropic's "hostile" stance toward China, he was not surprised by the counterreaction. More Chinese companies are likely to follow, the lawyer added.
The dispute cannot be separated from the general AI race between China and the USA. "Chinese companies will need to evaluate AI providers not just as classic software suppliers, but as strategic suppliers whose reliability can be influenced by geopolitics and national security," said Ben Hu of the Hong Kong China Network Security Association.
As with any highly politicized dispute, there are collateral damages this time as well. In Hong Kong, Goldman Sachs and JPMorgan Chase have cut off their bankers' access to Anthropic models, strictly interpreting the terms of use. "Restricting access to the world's most advanced AI models threatens Hong Kong's resurgence as an international financial center, given their rapid adoption in other parts of the world, especially in programming," warned the Financial Times. The restrictions demonstrate that Anthropic's regional terms of use are now also affecting international companies in Hong Kong.
Date: 08.12.2025
Naturally, we always handle your personal data responsibly. Any personal data we receive from you is processed in accordance with applicable data protection legislation. For detailed information please see our privacy policy.
Consent to the use of data for promotional purposes
I hereby consent to Vogel Communications Group GmbH & Co. KG, Max-Planck-Str. 7-9, 97082 Würzburg including any affiliated companies according to §§ 15 et seq. AktG (hereafter: Vogel Communications Group) using my e-mail address to send editorial newsletters. A list of all affiliated companies can be found here
Newsletter content may include all products and services of any companies mentioned above, including for example specialist journals and books, events and fairs as well as event-related products and services, print and digital media offers and services such as additional (editorial) newsletters, raffles, lead campaigns, market research both online and offline, specialist webportals and e-learning offers. In case my personal telephone number has also been collected, it may be used for offers of aforementioned products, for services of the companies mentioned above, and market research purposes.
Additionally, my consent also includes the processing of my email address and telephone number for data matching for marketing purposes with select advertising partners such as LinkedIn, Google, and Meta. For this, Vogel Communications Group may transmit said data in hashed form to the advertising partners who then use said data to determine whether I am also a member of the mentioned advertising partner portals. Vogel Communications Group uses this feature for the purposes of re-targeting (up-selling, cross-selling, and customer loyalty), generating so-called look-alike audiences for acquisition of new customers, and as basis for exclusion for on-going advertising campaigns. Further information can be found in section “data matching for marketing purposes”.
In case I access protected data on Internet portals of Vogel Communications Group including any affiliated companies according to §§ 15 et seq. AktG, I need to provide further data in order to register for the access to such content. In return for this free access to editorial content, my data may be used in accordance with this consent for the purposes stated here. This does not apply to data matching for marketing purposes.
Right of revocation
I understand that I can revoke my consent at will. My revocation does not change the lawfulness of data processing that was conducted based on my consent leading up to my revocation. One option to declare my revocation is to use the contact form found at https://contact.vogel.de. In case I no longer wish to receive certain newsletters, I have subscribed to, I can also click on the unsubscribe link included at the end of a newsletter. Further information regarding my right of revocation and the implementation of it as well as the consequences of my revocation can be found in the data protection declaration, section editorial newsletter.
One factor driving the growing demand for Chinese models is the price. Deepseeks' top model, V4 Pro, is nearly 60 times cheaper per token output compared to Anthropic's Fable 5. Minimax M2.7, Xiaomi's Mimo V2.5 Pro, and Alibaba's Qwen3.7 Max perform well in price-performance rankings by the American benchmark firm Artificial Analysis. "The performance of Chinese models like Deepseeks V4 Pro, GLM, Kimi, Minimax, and Qwen is increasingly on par with American AI," wrote Agathe Demarais from the European Council on Foreign Relations in the Financial Times.
Above all, several highly sought-after Chinese models are being released with open weights. Customers can download these, adapt them to their own requirements within the respective licensing terms, and in some cases, operate them on their own infrastructure. This reduces the risk of suddenly losing access to an already downloaded model due to a provider's access block. "The demand for Chinese models has already surpassed that for U.S. models on Openrouter," journalist Nicholas Gordon recently wrote in Fortune magazine. His statement refers to the token volume processed via Openrouter, where Chinese models overtook American providers in early June. A nation relying on foreign technology could "have the plug pulled overnight," warned former French Interior Minister Bruno Retailleau in recent times.
For Anthropic CEO Dario Amodei, the escalation comes at a bad time, as his company confidentially filed documents for an IPO with U.S. authorities on June 1. Amodei has long warned of the danger from China. He portrays himself as the conscience of the AI industry and calls on the U.S. government to keep authoritarian states away from the most powerful models. In its letter to the U.S. Senate, the company also urged Congress to close loopholes for Chinese AI labs and punish unauthorized distillation attacks.
The U.S. government in Washington now takes such warnings very seriously. Leading government officials recently announced investigations, financial sanctions, and trade restrictions against Chinese AI companies accused of unauthorized distillation of American models. On July 27, China referred to this as "AI hegemonism" and threatened countermeasures.
Already on June 12, the U.S. Department of Commerce restricted access to the then-new Anthropic models Fable 5 and Mythos 5 for foreign users. Since Anthropic was unable to reliably verify the nationality of its users in real-time, the company initially took both models offline worldwide—even for its own foreign employees. However, the export controls were lifted on June 30. Fable 5 has been globally available again since July 1, while Mythos 5 remains accessible to a limited user group. The incident nevertheless demonstrated how quickly access to a strategically important AI technology can be disrupted by political decisions.
Commentators like former financial trader Patrick Boyle see Anthropics' public relations and constant warnings about China as possibly backfiring, he argues in essence. "Telling authorities you've built a weapon and then being shocked when they treat it as such is, all in all, poor corporate governance," Boyle mocked Amodei.