China issues a security alert over an alleged 'backdoor' in Anthropic's Claude Code

🕒 Published on Zendoric: July 9, 2026 · 00:21
China's Ministry of Industry and Information Technology (MIIT) announced on Wednesday, July 8, that its cybersecurity threat platform detected that Anthropic's AI-assisted coding tool Claude Code "contains a backdoor vulnerability that poses a serious threat."
China's Ministry of Industry and Information Technology (MIIT) announced on Wednesday, July 8, that its cybersecurity threat platform had detected that Anthropic's AI-assisted coding tool Claude Code "contains a backdoor vulnerability that poses a serious threat." According to the Chinese-language statement, cited by CNBC, the tool could send sensitive information to a remote server without the user's consent, including location and identity data. Chinese authorities recommended that users uninstall or update the affected versions, ranging from 2.1.91 to 2.1.196 —released between April 2 and June 29— given that the most recent version available on Wednesday was 2.1.204, according to Anthropic's website. The company did not immediately respond to CNBC's request for comment.
The backdrop to this alert is no coincidence: it comes at a moment of growing friction between Anthropic and Chinese tech players. Last month, Anthropic accused the Chinese company Alibaba of trying to extract its AI capabilities, a product that, it is worth recalling, is not officially available in China. Alibaba did not publicly comment on those accusations at the time. In parallel, CNBC confirmed on Monday that Alibaba has ordered its employees to stop using Anthropic tools for work starting July 10, a move that coincides in timing with the government warning about Claude Code.
The contrast between the official ban and actual usage is striking: even though Anthropic's tools are not officially marketed in China, many local users have found ways to access them. The article mentions that in March a Xiaomi AI developer noted, at a state-organized forum, that a considerable number of people in China were already using Claude Code despite the restrictions. This suggests that the de facto adoption of US generative AI tools among Chinese developers is significant, even amid geopolitical tension and declared technological competition between the two countries.
The analysis that can be drawn from these facts points to a mutual instrumentalization of security concerns in the US-China technological rivalry. On the one hand, Anthropic denounced attempts by a large Chinese tech company to extract its capabilities; on the other, just weeks later, a Chinese regulatory body issues a public alert describing a vulnerability in that same US company's flagship product as a "backdoor." The article provides no independent technical evidence confirming the actual existence of that backdoor, nor does it detail the origin or detection methodology of the supposed Chinese cyberthreat platform; it merely reproduces the MIIT's official statement. Nor is there any indication, in the text, that Anthropic has acknowledged or denied the security flaw, since the company did not respond in time for the news to be published.
It is important to underline the limits of the available information: the article is brief, from a news agency, and does not delve into technical aspects such as the exploitation vector, whether published proofs of concept exist, or whether other cybersecurity firms —Western or independent— have corroborated the Chinese finding. Nor does it specify whether the MIIT warning is binding for Chinese companies or whether it is a recommendation. Against a backdrop of strategic rivalry in AI between Washington and Beijing, alerts of this kind may respond both to genuine security concerns and to moves of regulatory pressure or industrial policy, aimed at discouraging the use of US technology by Chinese companies and developers in favor of national alternatives. Without further sources technically corroborating the vulnerability, the accusation should be treated with caution until Anthropic offers an official response or third parties independently audit the finding.
🔗 Related on Zendoric
- Anthropic's Anti-Distillation Tracking Becomes a Geopolitical Weapon in China · 2026-07-09
- Alibaba's Claude Code Ban Shows the Real US-China AI Fault Line Is Trust, Not Just Chips · 2026-07-07
- Anthropic hid an anti-China tracker in Claude Code: when ethics becomes a brand and the brand becomes a liability · 2026-07-08


