Spying for Safety: Anthropic Busted Secretly Tracking Chinese Claude Code Users
So much for being the "good guys" of AI. The hyper-ethical, safety-obsessed darlings at Anthropic just got caught sneaking secret tracking code into their developer tool to spy on Chinese users—all while claiming they're the ultimate champions of privacy.
A security researcher going by the handle Thereallo discovered that Anthropic used "prompt steganography" to hide tracking code inside Claude Code. This stealthy digital parasite quietly collected time zones, proxy server details, and links to Chinese AI labs, encoding the stolen telemetry into shortened tokens that average developers would never notice in their network logs.
It turns out the tech world's most prominent self-proclaimed monks of AI safety aren't above playing a little CIA cosplay when their intellectual property is on the line.
Anthropic engineer Tariq Shihiphar quickly took to social media to claim this digital wiretap was just a temporary "experiment" launched back in March. According to him, the surveillance was meant to stop unauthorized resellers from renting out premium models for a fraction of the price and to block aggressive model distillation.
Apparently, protecting a $100 subscription from being sold for $12 by some enterprising digital middleman is worth sacrificing the company's entire moral high ground.
The main driver behind this paranoia is the massive wave of model distillation coming from China. Researchers at Peking University recently found that most top Chinese LLMs show heavy signs of cloning, with Alibaba's Qwen model famously copying Claude so closely that it occasionally forgot its own name and identified as Claude during testing. In response to the tracking revelation, Alibaba immediately retaliated by banning its employees from using Claude Code altogether.
It is highly amusing how easily corporate ethics evaporate the moment a competitor starts breathing down their neck. The irony of Anthropic lobbying the US government to treat model copying as literal intellectual property theft, while secretly turning their own developer tools into surveillance malware, perfectly encapsulates the absolute hypocrisy of the AI arms race.
Source: Ars Technica
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.