{"id":97593,"date":"2026-07-07T11:49:17","date_gmt":"2026-07-07T11:49:17","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/97593\/"},"modified":"2026-07-07T11:49:17","modified_gmt":"2026-07-07T11:49:17","slug":"claude-codes-hidden-tracker-was-an-experiment-says-anthropic","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/97593\/","title":{"rendered":"Claude Code\u2019s hidden tracker was an \u201cexperiment,\u201d says Anthropic"},"content":{"rendered":"<p class=\"wp-block-paragraph\">As a developer, you want to use tools you can trust and rely on. One <a href=\"https:\/\/thereallo.dev\/blog\/claude-code-prompt-steganography\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">researcher<\/a> took that idea seriously enough to scrutinize their local Claude Code (2.1.196) installation. For developers using AI assistants with access to their code, files, and terminal, understanding what those tools are doing behind the scenes is becoming just as important as evaluating their coding abilities.<\/p>\n<p class=\"wp-block-paragraph\">When you give an AI coding assistant shell, filesystem, and repository access, you\u2019re already taking a calculated risk. You expect bugs, maybe even some telemetry, but not a hidden channel that quietly encodes where your traffic is going and who might be watching on the other end.<\/p>\n<p class=\"wp-block-paragraph\">That is exactly what independent developer \u201cThereallo\u201d found while reverse\u2011engineering Anthropic\u2019s Claude Code client. Buried in the minified JavaScript bundle was a function that took the otherwise innocuous line \u201cToday\u2019s date is 2026\u201106\u201130.\u201d and turned it into a stealth marker for Anthropic\u2019s back end, depending on the user\u2019s API endpoint and system time zone.<\/p>\n<p class=\"wp-block-paragraph\">To users and most developers reading logs, the text still looked like ordinary English. Only someone inspecting the raw Unicode or Anthropic\u2019s own back end would see the encoded signal triggered if the local time zone was set to Asia\/Shanghai or Asia\/Urumqi.<\/p>\n<p class=\"wp-block-paragraph\">Once the revelation spread via social media and news outlets, Anthropic acknowledged the code and moved quickly to remove it, but has not yet issued a detailed public postmortem dedicated to this feature.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/arstechnica.com\/tech-policy\/2026\/07\/anthropic-outed-for-claude-tracker-that-secretly-monitored-chinese-users\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Reportedly<\/a>, an Anthropic engineer confirmed on X that the marker was \u201can experiment we launched in March\u201d intended to prevent account abuse by unauthorized resellers and to protect against distillation. This may have been triggered by the US government\u2019s decision on June 12 to suspend access to the models for foreign nationals, citing national security \u200cconcerns. These export controls were lifted on June 30.<\/p>\n<p class=\"wp-block-paragraph\">Another possible reason might be to learn more about <a href=\"https:\/\/www.washingtonpost.com\/national-security\/2026\/07\/06\/why-anthropic-alleges-chinese-firms-are-distilling-knowledge-claude\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported Chinese distillation attacks<\/a>, which pose a serious threat to US national security and undermine AI safety standards.<\/p>\n<p>Who needs to worry<\/p>\n<p class=\"wp-block-paragraph\">Anthropic has been locked in a very public dispute over \u201cdistillation attacks.\u201d These are campaigns in which adversaries allegedly replay or proxy model outputs to train competing systems, often from jurisdictions with weaker IP protections. Chinese\u2011linked AI labs and intermediaries have featured prominently in those accusations, and news reports describe unauthorized retailers reselling Claude access at steep discounts.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cnbc.com\/2026\/07\/06\/alibaba-anthropic-ai-ban-claude-china.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Alibaba has already banned Claude Code over this matter<\/a>. Alibaba is\u00a0not only one of the world\u2019s largest retailers and ecommerce companies, but was also ranked the world\u2019s fifth-largest artificial intelligence company in 2020.<\/p>\n<p class=\"wp-block-paragraph\">Developers who are concerned they could be targeted can:<\/p>\n<p>Record hashes and versions of AI clients used in sensitive environments, and avoid auto\u2011updates without at least a cursory review.<\/p>\n<p>Use network inspection to capture full requests to AI APIs in test environments, then analyze them for hidden or unexpected markers, including Unicode anomalies in system prompts.<\/p>\n<p class=\"wp-block-paragraph\">As this case shows, a single vendor decision can make a previously trusted tool unacceptable for some organizations. Maintain optionality and avoid hard dependencies on one AI assistant.<\/p>\n<p class=\"wp-block-paragraph\">Browse like\u00a0no one\u2019s\u00a0watching.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read\u00a0doesn\u2019t\u00a0have to feel personal.\u00a0<a href=\"https:\/\/www.malwarebytes.com\/vpn\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try it free \u2192<\/a>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"As a developer, you want to use tools you can trust and rely on. One researcher took that&hellip;\n","protected":false},"author":2,"featured_media":97594,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[53,3154,182,5226,50962],"class_list":["post-97593","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-anthropic","tag-anthropic-claude","tag-claude","tag-experiment","tag-stealth-marker"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/97593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=97593"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/97593\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/97594"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=97593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=97593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=97593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}