Back to feed
Dev.to
Dev.to
7/8/2026
China's NVDB flags hidden telemetry in Claude Code; Anthropic promises rollback but keeps tracking

China's NVDB flags hidden telemetry in Claude Code; Anthropic promises rollback but keeps tracking

Original: China Warns of Backdoors in Claude Code, Urges Caution

Short summary

Claude Code versions from April–June 2026 shipped a hidden monitoring mechanism that silently sent user location, identity, and domain data to remote servers without consent, prompting China's NVDB to issue a security warning. Anthropic confirmed it was an anti-distillation experiment targeting grey-market resellers and promised a rollback, but conceded telemetry will remain in the product going forward — just visible rather than hidden. The article provides concrete steps to check versions, pin known-good builds, and audit network egress, while arguing that AI agents should never become the single source of truth for project structure.

  • Claude Code silently tracked user location, identity, and domains without consent in Apr–Jun 2026 builds
  • China's NVDB issued a security warning; Anthropic called it an anti-distillation experiment and promised rollback
  • Practical guidance: check version, pin builds, audit outbound connections with lsof

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more