China’s National Vulnerability Database, a cybersecurity platform affiliated with the Ministry of Industry and Information Technology, warned that some versions of Anthropic’s Claude Code contain a “security backdoor” capable of sending users’ locations and identity-related data to company servers without consent. The regulator urged organizations to uninstall or upgrade to a fixed release and tighten network monitoring. Anthropic did not immediately comment, though a company engineer said the collection was a March experiment aimed at stopping unauthorized resellers and deterring model distillation and would be rolled back. Alibaba told staff it will ban Claude Code, underscoring mounting compliance risks for U.S. AI tools in China as access increasingly depends on VPNs and third-party proxies.
Related articles:
Anthropic (company)
Alibaba Group
Ministry of Industry and Information Technology
Knowledge distillation
Data exfiltration




























