
China’s National Vulnerability Database, a government-run cybersecurity platform overseen by the Ministry of Industry and Information Technology, has warned users to uninstall or upgrade Anthropic’s Claude Code after flagging versions 2.1.91 through 2.1.196 for what it described as a serious backdoor vulnerability.
According to the alert, the coding agent could transmit user data to a remote server without consent. The Wall Street Journal reported the alert on July 8. Anthropic did not provide a formal public response, but an Anthropic engineer reportedly described the flagged mechanism as an experimental anti-abuse tracking feature. The company removed the code in a July 1 pull request, which was before Beijing issued its alert.
Claude Code is not officially sold in China, but that has not stopped Chinese developers from using it.
Last month, Anthropic accused Alibaba-affiliated operators of using nearly 25,000 fraudulent accounts to generate more than 28.8 million Claude exchanges in what Anthropic called a large-scale distillation campaign. Against that backdrop, Alibaba reportedly told employees to stop using Claude Code at work effective July 10.
Chinese models have closed a meaningful portion of the capability gap with U.S. rivals (some say they are only a few months behind). The open source and open weight versions are practically free to use, and (as you know) “free” is very pro consumer. This combination of price and performance also makes them politically radioactive.
U.S. officials and lawmakers have warned that Chinese AI systems may reflect Beijing’s censorship rules, data priorities, and ideological constraints. Beijing rejects those claims as politically motivated attacks. Meanwhile, China is now accusing a U.S. AI company of shipping code that could track users without consent.
This is a subset of the bigger AI cold war. Chinese open-weight models already sit on servers worldwide, so a broad American ban would be difficult to enforce technically and might hurt U.S. startups more than its intended targets. On the other hand, Beijing can order Claude Code uninstalled, but it cannot un-teach Chinese developers why they installed it in the first place.
Is this a fight over which superpower will hold the keys to the world’s AI economy? If so, the question is: who is the rabbit, and who is the fox?




Comments
Log in or sign up to join the conversation.