Claude Code Hit by Security Backdoor; Official Launches Emergency Fix

Recently, the National Vulnerability Database (NVDB) under China’s Ministry of Industry and Information Technology (MIIT) issued a critical security advisory regarding Claude Code, a widely adopted AI programming assistant. The warning highlights an undisclosed security backdoor within the tool that may expose users’ sensitive data.
Monitoring data indicates that software versions 2.1.91 through 2.1.196 are vulnerable. These versions automatically transmit sensitive information, such as geographic location and identity identifiers, to remote servers without explicit user consent. The NVDB urges developers and enterprise users to verify their current version immediately. If the installed version falls within the affected range, users should uninstall the software or upgrade to the latest secure release. Organizations are also advised to restrict external access permissions in development environments and enhance traffic monitoring to mitigate unauthorized data exfiltration.
The issue came to light in late June when a developer reverse-engineering version 2.1.196 of Claude Code discovered a hidden detection mechanism embedded since the April 2nd release of version 2.1.91. This mechanism continuously checks system time zones and proxy server details to identify users in China. Notably, this functionality was never disclosed in previous software update logs.
Addressing public concerns, Anthropic team member Thariq Shihipar clarified on social media that the feature was an “experimental” measure designed to prevent account resale and defend against model distillation attacks. The company confirmed that a new version released on July 2nd has removed the detection feature.
This vulnerability has triggered significant industry response. Reports indicate that Alibaba has issued an internal ban, prohibiting employees from using Claude Code in office environments as of July 10th, and has added the tool to its high-risk software list. For developers who must continue using the tool, closely monitoring official updates and applying timely patches remain essential for maintaining development environment security.
Related article
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust
Slackbot Becomes an AI Agent
Slackbot, the automated assistant embedded in Salesforce’s corporate messaging platform Slack, is evolving into an AI agent. Salesforce CTO Parker Harris envisions it achieving viral status comparable to OpenAI’s ChatGPT.The cloud software giant laun
ByteDance Boosts Core AI Incentives as Doubao Surges 14.6%
ByteDance recently convened a DouBao equity briefing to unveil fresh incentive policies for staff involved in the DouBao division. The strike price for DouBao shares has been lifted from $14.85 in June 2026 to $17.02, marking an approximate 14.6% inc
Related Special Topic Recommendations
Comments (0)
0/500

Recently, the National Vulnerability Database (NVDB) under China’s Ministry of Industry and Information Technology (MIIT) issued a critical security advisory regarding Claude Code, a widely adopted AI programming assistant. The warning highlights an undisclosed security backdoor within the tool that may expose users’ sensitive data.
Monitoring data indicates that software versions 2.1.91 through 2.1.196 are vulnerable. These versions automatically transmit sensitive information, such as geographic location and identity identifiers, to remote servers without explicit user consent. The NVDB urges developers and enterprise users to verify their current version immediately. If the installed version falls within the affected range, users should uninstall the software or upgrade to the latest secure release. Organizations are also advised to restrict external access permissions in development environments and enhance traffic monitoring to mitigate unauthorized data exfiltration.
The issue came to light in late June when a developer reverse-engineering version 2.1.196 of Claude Code discovered a hidden detection mechanism embedded since the April 2nd release of version 2.1.91. This mechanism continuously checks system time zones and proxy server details to identify users in China. Notably, this functionality was never disclosed in previous software update logs.
Addressing public concerns, Anthropic team member Thariq Shihipar clarified on social media that the feature was an “experimental” measure designed to prevent account resale and defend against model distillation attacks. The company confirmed that a new version released on July 2nd has removed the detection feature.
This vulnerability has triggered significant industry response. Reports indicate that Alibaba has issued an internal ban, prohibiting employees from using Claude Code in office environments as of July 10th, and has added the tool to its high-risk software list. For developers who must continue using the tool, closely monitoring official updates and applying timely patches remain essential for maintaining development environment security.
How to fix Core Web Vitals for better SEO rankings
Streamline Report Card Comments with AI ToolsIntroductionAI Tools for Generating Report Card CommentsMagic SchoolAlmanac AIChat GPTUsing Magic School to Generate Report Card CommentsLogging into Magic SchoolSelecting the Report Card Comments ToolCust
Slackbot Becomes an AI Agent
Slackbot, the automated assistant embedded in Salesforce’s corporate messaging platform Slack, is evolving into an AI agent. Salesforce CTO Parker Harris envisions it achieving viral status comparable to OpenAI’s ChatGPT.The cloud software giant laun
ByteDance Boosts Core AI Incentives as Doubao Surges 14.6%
ByteDance recently convened a DouBao equity briefing to unveil fresh incentive policies for staff involved in the DouBao division. The strike price for DouBao shares has been lifted from $14.85 in June 2026 to $17.02, marking an approximate 14.6% inc





Home






