OctoLink GEO

MIIT Flags Critical Security Risks in Anthropic’s Claude Code: Unauthorized Data Transmission Exposed

Author Editor
MIIT Flags Critical Security Risks in Anthropic’s Claude Code: Unauthorized Data Transmission Exposed

China’s Ministry of Industry and Information Technology (MIIT) has issued its first official warning about Anthropic’s AI coding tool Claude Code...

Claude Code AI Security MIIT Anthropic Data Privacy Alibaba AI Coding Tools

China’s Ministry of Industry and Information Technology (MIIT) has recently issued a critical warning regarding Anthropic’s AI coding assistant, Claude Code, marking the first official stance from the regulator on the tool’s security risks. According to MIIT’s Network Security Threat and Vulnerability Information Sharing Platform, Claude Code was found to transmit sensitive user data—including geographic location and identity markers—to remote servers without explicit user consent.

The affected versions range from 2.1.91 (released on April 2, 2026) to 2.1.196 (released on June 29, 2026). MIIT has advised users to immediately uninstall or upgrade to the latest version (2.1.204) to mitigate risks. The regulator also recommended organizations conduct full checks on development terminals for the problematic versions and strengthen outbound permission management and traffic monitoring to prevent unauthorized data leaks.

Claude Code’s higher security risk compared to standard chatbots stems from its deep integration with development environments: it can access code repositories, edit files, and execute system commands across terminals, IDEs, desktop apps, and browsers. This proximity to critical enterprise assets like code, credentials, and internal networks makes unauthorized data transmission particularly concerning.

The hidden monitoring mechanism was first uncovered by a Reddit user on June 30, who found the tool checks system time zones and proxy settings for keywords related to Chinese cloud providers or AI companies. Upon detecting such keywords, Claude Code would manipulate date characters in system prompts and add hidden markers to server requests—an operation described as highly covert.

Anthropic responded on July 1, acknowledging the mechanism as an experiment launched in March 2026 to prevent unauthorized account resale and model distillation. The team stated that the feature was already planned for removal, with a PR merged to roll it back in the next version release.

Notably, Anthropic explicitly excludes mainland China from its list of allowed regions for Claude.ai and its API services, reserving the right to refuse service to entities based in unlisted regions where legally permitted.

Domestically, Alibaba took swift action: on July 3, the company issued an internal notice banning all Anthropic products—including Claude Code, Sonnet, Opus, and Fable models—with a deadline of July 10 for full uninstallation. An internal source cited the recent backdoor risk allegations as the reason for classifying Claude Code as a high-risk software.

Sources

Related reading