Anthropic Removes Hidden Claude Code Tracker After Privacy Backlash

Anthropic quietly removed a tracking system from Claude Code after researchers found it was using hidden markers to identify users — including their location, proxy use, and possible ties to Chinese AI labs.

The feature was discovered in June by a developer going by “Thereallo.” Claude Code’s system prompts had embedded Unicode markers and encoded domain lists that could flag users Anthropic believed were bypassing restrictions. If someone pointed ANTHROPIC_BASE_URL at a known reseller domain or used a hostname containing “deepseek” or “zhipu,” the system would pick it up.

Thereallo said the intent wasn’t malicious — stopping API resellers and model “distillation” attacks is reasonable. But the criticism was about how it was done. No documentation. No release notes. Just hidden signals baked into the tool.

“This is a weird choice for a developer tool that asks for trust,” Thereallo wrote.

Anthropic engineer Thariq Shihipar confirmed on X that the tracker was an “experiment” from March. “The team has landed stronger mitigations since then,” he said, and the PR was merged for a full rollback.

The timing matters. Anthropic has been pushing hard against AI distillation — especially from Chinese rivals. In February it accused DeepSeek, Moonshot AI, and MiniMax of using fraudulent accounts to extract millions of Claude responses. In June, CEO Dario Amodei urged Congress to crack down on foreign AI extraction, claiming Alibaba-linked operators generated 28.8 million Claude exchanges using nearly 25,000 fake accounts.

Earlier this month, Alibaba blocked employees from using Claude Code entirely, calling it “high-risk” software over security concerns.