MakeBox AI
← Back to News
AnthropicJuly 10, 20266 min read

The Hidden Beacon: How Anthropic Used Steganography to Spy on Claude Code Users

Anthropic confirmed it embedded hidden surveillance code in its developer tool Claude Code to flag Chinese users and AI labs, using steganography in system prompts. The code was removed after public backlash, but the incident raises serious questions about trust and consent in AI development tools.

The Hidden Beacon: How Anthropic Used Steganography to Spy on Claude Code Users

Anthropic, the AI company that once positioned itself as a principled opponent of mass surveillance, has admitted to embedding covert monitoring code in its developer tool Claude Code. The hidden code, active from April 2, 2026 (version 2.1.91), used steganography in system prompts to secretly flag users connecting from China or affiliated with Chinese AI labs. The revelation has sparked outrage, with security researchers calling it a "serious breach of user trust" and Alibaba moving to ban the tool entirely.

What Happened: Steganography, Hardcoded Domains, and a Reddit Exposé

The hidden mechanism was first uncovered on June 30, 2026 by a developer using the handle u/LegitMichel777, who published a reverse‑engineering analysis of the Claude Code binary on Reddit. The analysis revealed obfuscated code that performed the following checks:

  • Proxy detection: The tool checked whether the user was connecting through a proxy.
  • Timezone check: It compared the system timezone against Chinese timezones.
  • Domain inspection: Network traffic was checked against a hard‑coded list of Chinese domains and AI lab addresses, including DeepSeek, Moonshot, and MiniMax.
  • Affiliation assessment: The code assessed whether an account looked affiliated with Chinese AI labs, in the context of alleged "distillation" attacks on Claude.
  • Rather than sending standard telemetry, the tool used prompt steganography to covertly signal this information back to Anthropic’s servers. The system prompt’s date formatting was subtly altered (e.g., dashes changed to slashes), and the apostrophe in the phrase "Today’s date is" was swapped for one of three visually identical but technically distinct Unicode characters, each encoding a different tracking flag. Security researchers described this as a "covert surveillance / nationality‑detection mechanism."

    The active period of the hidden code was from April 2, 2026 (v2.1.91) until its removal around July 1–2, 2026. Subsequent researchers, including Adnane Khan, reconstructed the JavaScript source of the detection mechanism from versions 2.1.193–2.1.196.

    💡 Anthropic deployed a hidden, steganographic tracking system in a developer tool with filesystem and shell access—an approach that goes far beyond standard telemetry and raises serious consent and security concerns.

    Anthropic’s Acknowledgment and Rationale

    After the public disclosure, Anthropic engineers acknowledged the existence of the hidden code. Thariq Shihipar, an engineer on the Claude Code team, publicly stated that the tracker was added as an experiment in or around March 2026 to "prevent account abuse from unauthorized resellers and protect against distillation." He added that the company had "been meaning to take this down for a while" because they had "landed stronger mitigations" against abuse and distillation.

    Anthropic had previously reported significant distillation attacks by Chinese AI labs, describing ~24,000 fraudulent accounts and >16 million exchanges used for model copying. In a June 10, 2026 letter to the U.S. Senate Banking Committee, the company stated that it shares intelligence about such abuse with "other AI labs, cloud providers, and relevant authorities."

    💡 Anthropic’s justification—preventing model distillation—is undercut by the covert, obfuscated nature of the tracking, which intentionally concealed the monitoring from users. This is a sharp departure from standard industry practices.

    Why It Matters: A Deep Trust Crisis

    The incident is particularly damaging because Anthropic had long positioned itself as a champion of ethical AI, famously refusing to relax contractual prohibitions on mass domestic surveillance and autonomous weapons—a stance that led some U.S. federal agencies to phase out Claude. Now, the company has been caught deploying the very kind of surveillance it publicly opposed, albeit in a developer tool rather than a consumer product.

    Security researchers and commentators have described the feature as "targeted surveillance without consent," a "covert intelligence tool," and a "serious breach of user trust." The hidden and obfuscated implementation, plus the use of steganography instead of standard telemetry, has been cited as evidence of intentional concealment.

    The backlash has been swift. Alibaba reportedly banned Claude Code, effective July 10, 2026, citing Anthropic’s hidden tracking and the broader implications of AI surveillance and industrial distillation. This move signals that the trust damage extends beyond individual developers to major enterprise customers.

    What It Means for Business: Rebuilding Trust in the AI Supply Chain

    For developers and enterprises using Claude Code, the lesson is clear: even tools from companies with strong ethical branding may contain hidden surveillance mechanisms. The tool’s access to filesystem and shell commands amplifies the risk—covert code could, in theory, exfiltrate sensitive data.

    This incident will likely accelerate calls for third‑party auditing of AI developer tools and transparency reports on any monitoring capabilities. Companies that rely on AI tools for critical workflows should consider requiring source code transparency and independent security reviews before adoption.

    💡 The use of steganography to hide tracking in system prompts is a novel technique that could become a red flag for future audits. Developers should watch for subtle anomalies in prompt formatting—a potential sign of covert monitoring.

    What to Watch Next

    Anthropic has removed the code and promised stronger mitigations, but the reputational damage is done. The company’s past anti‑surveillance stance will now be a liability, and regulators may take a closer look at how AI companies monitor users. The broader question remains: as AI models become more valuable, how far will companies go to protect their intellectual property? This incident sets a dangerous precedent—one that could erode trust in the entire AI development ecosystem.

    Want automation like this for your business?

    Get in touch and we'll show you exactly what's possible for your setup.