Anthropic Caught Hiding a Tracker in Claude Code — Then Blamed It on an ‘Experiment’

Anthropic got caught red-handed. A security researcher found hidden tracking code inside Claude Code that was secretly monitoring users in China. The researcher called it a “serious breach of user trust.” Hard to argue with that.

The code used something called “prompt steganography” — hiding tracking markers in plain sight. It wasn’t malicious code, but it was quietly sending data to Anthropic about users’ timezone, proxy info, and potential connections to Chinese AI labs. Stuff most people wouldn’t notice.

Anthropic engineer Thariq Shihipar confirmed the tracker was added as an “experiment” back in March. His explanation? It was meant to prevent account abuse from unauthorized resellers and protect against model distillation — where Chinese firms use Claude to train their own models. Turns out unauthorized resellers have been selling access to Anthropic’s free models for $1 a month, and pro subscriptions for as little as $12.

Here’s the irony: Anthropic has publicly refused to let the US government use Claude for surveillance. They even sued the White House over it. But they thought it was fine to track Chinese users without telling them.

Privacy advocates weren’t buying the explanation. The tracker’s been removed now, and Shihipar says engineers have “stronger mitigations” in place. But the damage is done. Once you get caught hiding tracking code, trust is hard to earn back.