China's NVDB flags hidden telemetry in Claude Code; Anthropic promises rollback but keeps tracking
Original: China Warns of Backdoors in Claude Code, Urges Caution
Short summary
Claude Code versions from April–June 2026 shipped a hidden monitoring mechanism that silently sent user location, identity, and domain data to remote servers without consent, prompting China's NVDB to issue a security warning. Anthropic confirmed it was an anti-distillation experiment targeting grey-market resellers and promised a rollback, but conceded telemetry will remain in the product going forward — just visible rather than hidden. The article provides concrete steps to check versions, pin known-good builds, and audit network egress, while arguing that AI agents should never become the single source of truth for project structure.
- •Claude Code silently tracked user location, identity, and domains without consent in Apr–Jun 2026 builds
- •China's NVDB issued a security warning; Anthropic called it an anti-distillation experiment and promised rollback
- •Practical guidance: check version, pin builds, audit outbound connections with lsof
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



