Hidden Code Inside Claude Code Sparks Trust Questions For Anthropic
A quiet piece of code buried inside Anthropic's programming assistant has landed the company in an uncomfortable spotlight.
Claude Code, the tool developers use to write and fix software, was found to be carrying hidden markers that flagged details about users without ever telling them.
Once a developer pulled back the curtain, Anthropic moved fast to strip the feature out entirely.
What Was Actually Hidden Inside The Tool
The discovery came from a developer going by the name Thereallo, who was digging into privacy concerns within Claude Code in June.
Buried inside the system prompts were Unicode markers and encoded lists of domains, tools designed to quietly flag things like a user's time zone, whether they were routing traffic through a proxy, and whether their setup hinted at ties to Chinese AI labs.
None of this was written into any documentation or release notes.
Users had no way of knowing it was there.
Thereallo explained the likely purpose plainly:
"Anthropic probably wants to detect API resellers, unauthorized Claude Code gateways, and model 'distillation attack' pipelines."
He pointed out that something as simple as a custom ANTHROPIC_BASE_URL pointing to a known reseller domain, or a hostname containing words like deepseek or zhipu, would be enough to trip the signal.
Why Hiding It Became The Real Problem
Thereallo didn't dispute that Anthropic had a legitimate reason to watch for abuse.
What bothered him was the method.
He wrote,
"This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust.”
He also warned that tools like Claude Code sit deep inside a user's system, capable of checking code, running commands, installing packages, editing files and even pushing commits, which makes silent tracking a far bigger deal than it might be elsewhere.
As he put it, hiding a signal in the system prompt makes any other privacy claim harder to believe.
How Anthropic Responded To The Backlash
Once the story spread, Anthropic engineer Thariq Shihipar addressed it directly on X.
He confirmed the feature had been quietly added back in March as an experiment aimed at stopping account abuse from unauthorised resellers and shielding Claude from distillation attempts.
According to Shihipar, the team had since built stronger safeguards, making the old tracker redundant.
He wrote,
"The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while.”
He added that a pull request had already been merged and the rollback would land in the very next release.
The Bigger Fight Over AI Distillation
This episode didn't happen in isolation.
Anthropic has spent recent months warning publicly about distillation, the practice of using one AI model's answers to train or speed up a rival system.
In February, the company accused Chinese firms DeepSeek, Moonshot AI and MiniMax of running fraudulent accounts to harvest millions of Claude's responses for exactly this purpose, though critics questioned whether that differs much from techniques used across the wider AI industry.
The debate isn't confined to Chinese labs either.
In April, Elon Musk told a US court that xAI had "partly" used OpenAI's models while training Grok, calling distillation a common industry habit rather than something unique to any one company.
In June, Anthropic chief executive Dario Amodei took the concern to Congress, alleging that Alibaba-linked operators had generated 28.8 million exchanges with Claude using close to 25,000 fraudulent accounts.
Anthropic has since pushed, alongside OpenAI, for tighter legal and export controls to treat this kind of large-scale extraction more like intellectual property theft.
Alibaba's Response Adds Another Layer
The fallout reached Alibaba directly.
Earlier this month, the company banned its own staff from using Claude Code, labelling it "high-risk" software in an internal memo that also raised concerns about potential backdoors.
Alibaba has not publicly responded to Anthropic's distillation allegations, though reports suggest the company could face legal or compliance exposure if found to have breached Anthropic's usage terms.
A Company Caught Between Protection And Privacy
Anthropic now finds itself balancing two competing pressures.
On one side, it's trying to stop rivals from copying its models through mass extraction.
On the other, its chosen method for doing so relied on tactics that privacy advocates say cross a line, particularly for a company that has previously pushed back against government requests to monitor users.
Reports on the episode noted this tension is sharpened by the fact that Anthropic has positioned itself as resistant to surveillance overreach, making the discovery of its own hidden tracking system a harder story to shake off.