Key Point: Anthropic integrated a hidden tracking mechanism in Claude Code to identify unauthorized resellers and model scrapers — but has already announced its removal.
Security researcher Thereallo discovered a covert tracking mechanism in Anthropic’s AI coding assistant Claude Code that collected timezone information and proxy usage. Anthropic confirmed the feature as an experiment from March 2026 and announced its removal.
Security researcher Thereallo documented a tracking mechanism in Claude Code’s system prompt that collected user timezones and proxy server usage. According to Anthropic developer Thariq Shihipa, the goal was to detect whether connections were being made to AI laboratories in China — to prevent abuse by unauthorized resellers and model distillation, a process in which smaller models are trained using the outputs of larger models.
Shihipa confirmed on X that it was an experiment from March 2026. The code was already scheduled for removal and was to be replaced by stronger protective measures that the team has since implemented. Anthropic had previously accused Chinese companies such as DeepSeek, Moonshot, and MiniMax of using its models in this manner. Additionally, the Washington Post reported that Chinese resellers were selling Claude Pro subscriptions for approximately $12 in China, while the US regular version costs $100.
The discovery sparked criticism of Anthropic’s transparency commitments. The researcher pointed out that coding assistants have deep access rights to local systems — they can view source code, execute shell commands, install software packages, and make changes. Criticism focused on the obfuscation: A tool with filesystem and shell access that hides classification bits in invisible prompt punctuation requires careful scrutiny of security measures and communicated system permissions.
Source: www.it-daily.net · Published July 13, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.