@xiangxiang103: Wow, Anthropic really dropped the ball this time. Someone dug up hidden code in the Claude Code binary — specifically designed to detect whether you're a Chinese user or routing through China. Not ordinary telemetry, but deliberately obfuscated, not mentioned in release notes, and completely unknown to users. The process goes like this: - Detects you...

X AI KOLs Timeline News

Summary

Hidden code was discovered in the Claude Code binary that specifically detects Chinese users or proxy routes, and secretly modifies system prompts to add watermarks, sparking widespread concerns about trust in developer tools.

Wow, Anthropic really messed up big this time. Someone dug up hidden code in the Claude Code binary — specifically designed to detect whether you're a Chinese user or routing through China. Not ordinary telemetry, but deliberately obfuscated, not mentioned in release notes, and completely unknown to users. The process is quite devious: - Detects you're using a proxy → checks the timezone (Shanghai/Urumqi) - Checks if the proxy URL points to Chinese domains or AI labs - If triggered, secretly alters characters in the system prompt: changes date formats, replaces apostrophes with other Unicode homoglyphs - These changes are invisible to the naked eye, but Anthropic's backend can match them In short: it embeds a set of watermarks in your prompt that only they can decode. It's been there since v2.1.91 (April 2 this year). The code is XOR encrypted, function names are minified into a mess — strings scanning can't find them. Everyone knows what Anthropic is trying to prevent: API reselling for bypass services, model distillation by domestic labs. But here's the problem — you're building a developer tool. Users give you file system access, they give you Shell. And you pull this behind their backs? What hurts most: zero documentation, zero disclosure. If they can secretly watermark your prompts today, what about tomorrow? The day after? A coding agent running on your local machine — you never know what else it's hiding. The source code was leaked via npm back in March, and 600,000 lines were turned inside out. Now, not long after, another incident. The bottom line for developer tools is three words: don't stab in the back. Trust takes years to build, but only one sneaky move to shatter. This is already exploding on X and Reddit. I don't believe Anthropic can play dead on this. Original post link:
Original Article
View Cached Full Text

Cached at: 06/30/26, 03:44 PM

Holy crap, Anthropic really dropped the ball this time.

Someone found hidden code in Claude Code’s binary — specifically checking whether you’re a Chinese user or routing through a proxy based in China. This isn’t normal telemetry. It’s deliberately obfuscated, undocumented in the release notes, and completely invisible to users.

How it works:

  • Detects if you’re using a proxy → checks timezone (Shanghai / Urumqi)
  • Checks whether the proxy URL points to a Chinese domain or AI lab
  • If triggered, silently modifies characters in the system prompt: changes date formats, swaps apostrophes with different Unicode homoglyphs
  • These changes are visually indistinguishable, but Anthropic’s backend can match them

In plain terms: it’s embedding a watermark in your prompt that only they can decode.

It’s been there since v2.1.91 (April 2nd this year). The code is XOR-encrypted, function names are minified into soup — completely unfindable with strings.

Everyone knows what Anthropic is trying to prevent: people reselling API access as proxy services, domestic labs distilling their models. But here’s the thing — you’re a development tool. Users give you file system access, shell access. And you pull this behind their backs?

The worst part: zero documentation. Zero disclosures.

Today it silently watermarks your prompt. Tomorrow? The day after? An agent that runs on your local machine — you’ll never know what else it’s hiding.

The source code was leaked on npm back in March — 600,000 lines picked apart. Not long after, and now this.

The bottom line for developer tools: don’t stab your users in the back.

Trust takes years to build. It takes one shady move to destroy it. This is already blowing up on X and Reddit. I don’t think Anthropic can just ignore it.

Original post link:

Similar Articles

@Khazix0918: https://x.com/Khazix0918/status/2072235797592658395

X AI KOLs Timeline

The article exposes that Anthropic secretly detects and marks Chinese users in Claude Code using steganography (modifying Unicode characters and separators in date strings) for account bans, sparking strong community concerns about privacy and trust.

@AISuperDomain: Breaking news! Claude Code allegedly has a built-in 'hidden backdoor' specifically designed to detect Chinese users. The reason for Claude account bans has finally been found!!! According to a Reddit leak: Starting from version 2.1.91, Claude Code checks whether the system timezone is Asia…

X AI KOLs Timeline

According to a Reddit leak, starting from version 2.1.91, Claude Code has a built-in hidden detection logic that checks system timezone, proxy URL, and modifies system prompt encoding methods, allegedly to specifically identify Chinese users, sparking serious concerns about developers' trust boundaries.