Anthropic's Claude Code team engineer Thariq publicly responded to the recent "spy code" allegations, admitting that in March the team embedded an experimental mechanism in the product. It detected whether the system timezone was set to Asia/Shanghai or Asia/Urumqi, and checked proxy hostnames against a list of China-related resellers and AI Lab keywords. Using special punctuation marks, it steganographically injected hidden marker information into system prompts. Thariq said the mechanism was meant to "prevent unauthorized resellers from abusing accounts and conducting model distillation," but stressed that stronger protections have since been deployed and that they "always intended to take it down." The relevant PR has been merged, and a full rollback is expected in the next version release.
https://twitter.com/trq212/status/2072079729331777817
This disclosure was made public on June 30 by security account @IntCyberDigest, which posted two code screenshots showing Claude Code fingerprinting Chinese users without their knowledge. While Thariq's response is a direct admission, the timeline — implemented in March, accelerated removal only after exposure — has sparked widespread skepticism. Comments are overwhelmingly critical of Anthropic, accusing the company of "only pulling it after getting caught" and "secretly monitoring users without notice." The trust in the company, which has long styled itself as prioritizing safety and ethics, has taken a serious hit.