@Khazix0918: https://x.com/Khazix0918/status/2072235797592658395

X AI KOLs Timeline News

Summary

The article exposes that Anthropic secretly detects and marks Chinese users in Claude Code using steganography (modifying Unicode characters and separators in date strings) for account bans, sparking strong community concerns about privacy and trust.

https://t.co/z9ykbxvQPo
Original Article
View Cached Full Text

Cached at: 07/01/26, 12:06 PM

Anthropic Secretly Embedded Hidden Code in Claude Code — Just to Identify Chinese Users

In the past two days, Claude has been mass-banning accounts.

Claude users in China have almost all been banned.

One of my two Max subscription accounts has already fallen…

My remaining old account is barely hanging on — I feel like it’ll be gone in a couple of days too.

What’s particularly shady is that people discovered Anthropic even secretly embedded an address tracker in their ban notification emails.

It’s full of clever little tricks, all aimed at blocking Chinese users.

But soon everyone realized that embedding a tracker in an email isn’t that special — because there’s something a million times more cunning.

It all started yesterday when a Reddit power user reverse-engineered Claude Code and found an ultimate sneaky move by Anthropic to block Chinese users.

To summarize in one sentence: “Claude Code silently reads your local computer information and uses an extremely covert method to secretly transmit to the server whether the user is a Chinese user.”

This guy even used the term “spyware” to describe it.

But honestly, if he hadn’t discovered it, this transmission and detection of Chinese users is both extremely sneaky and well-hidden.

I also verified it locally on my own Claude Code using Codex, and the answer is: it’s true.

Let’s start with the question most people care about: how does it identify you as a Chinese user even when you’re using a VPN?

Traditional geo-blocking relies on IP geolocation, which a VPN can easily bypass.

But Claude Code’s code takes two completely different paths, with zero relation to your outbound IP address.

Because it doesn’t look at your IP at all.

The first path is the operating system timezone.

It reads the local timezone set on your macOS or Linux system. Most Chinese developers might use a VPN, but they still need to see the correct time for daily life, so they almost never change their computer’s timezone — it’s set to Beijing time. Claude Code directly reads your local timezone.

The second path is the ANTHROPIC_BASE_URL environment variable.

Normal Claude Code users outside China who use the official API send requests directly to api.anthropic.com and don’t need to set this variable.

But in China, since Claude is basically unusable directly, yet the model has been genuinely good, a large number of Chinese developers use Claude Code through relay proxies. The way to do this is to change ANTHROPIC_BASE_URL to the relay proxy’s address.

Many large companies, because they can’t register a separate Claude account for each employee, also set up internal relay proxies to provide Claude API access to everyone.

So the path becomes: user messages go to the relay proxy first, which then sends them to Anthropic’s servers.

After Claude Code retrieves this address locally, it automatically extracts the domain name and compares it against a built-in list.

This list is a collection of all known relay proxies, domestic large company intranet proxies, and competitor AI company domains that Anthropic has gathered.

I decoded it on my computer too — there are 147 domains in total.

Not only are there multiple relay proxy addresses, but domains from major domestic companies are also clearly listed.

Including Meituan, NetEase, Baidu, Ctrip, Xiaohongshu, Alibaba, Ant Group, ByteDance, JD.com, Bilibili, Moonshot AI, MiniMax, StepFun, and many more.

One more interesting thing is…

And these lists are not stored in plain text — they are base64-encoded and then XOR-encrypted with key 91. If you open Claude Code’s package yourself, you’ll see a bunch of unreadable gibberish. Without deobfuscation, you simply can’t tell what’s written there.

Okay, the detection mechanism is clear.

Now comes the shadiest part — what does it actually do after detection?

Every time you enter a command in Claude Code — whether it’s writing code or doing something else — before sending your request to Anthropic’s backend, Claude Code automatically prepends a system prompt.

This system prompt is meant to give the model some up-to-date factual information, so it typically includes a very ordinary line like this:

Today's date is 2026-06-30.

This just tells the model what the date is — for example, June 30th.

This line is where Anthropic tampered with things.

The Reddit user found that Claude Code’s package contains a set of functions. Based on the two detection paths above, if the system detects you are a Chinese user locally, it will make two modifications to this date string before your request is actually sent.

And both modifications are almost invisible to the human eye. When you look at this line in any editor or terminal, it looks identical to the normal version.

But from a machine-decoding perspective, specifically at the Unicode encoding level, it has changed — completely become a different character.

First modification: the apostrophe in “Today’s”.

Under normal circumstances, the Unicode code point for this apostrophe is U+0027 — the standard apostrophe you type on a keyboard.

But if Claude Code detects from your environment that you are a Chinese user, it will sneakily replace that apostrophe with one of three other Unicode characters that look exactly the same. This modified prompt is then sent to their servers.

Second modification: the date separator.

In a normal prompt, the date format is 2026-06-30, using hyphens as separators.

But if Claude Code detects that your OS timezone is set to Asia/Shanghai or Asia/Urumqi, it replaces the hyphens with slashes, becoming 2026/06/30.

These two signals combined form a 2- to 3-bit classification marker.

When Anthropic’s server receives your request, it doesn’t need to do any additional detection. It only needs to machine-identify which Unicode character the apostrophe in the system prompt is, and whether the date separator is a hyphen or a slash, to determine whether the request comes from a mainland China timezone.

This technique has a technical name: steganography.

It means hiding information inside a seemingly normal carrier.

If it weren’t for this incident, almost no one could have discovered how sneaky Anthropic is. Even if Claude Code detected locally that you are a Chinese user, it would be useless if it couldn’t send that info back to Anthropic’s servers.

But if they simply packaged up the timezone and sent it obviously, people aren’t stupid — they would see the data being transmitted and could specifically clean it.

But no one expected Anthropic to go this far — it’s almost impossible to detect.

I’m honestly impressed now.

They’ve gone to this length just to prevent Chinese users from accessing their precious Claude.

The community exploded after discovering this — not just Chinese developers, but foreign developers too.

That post has already hit 1 million views.

The absolute core issue is that Claude Code is not just an ordinary app.

It has file system permissions on your computer. It can execute shell commands. It can read your code, modify your config, operate your Git repository. In other words, it basically has the highest level of access to your home.

And this thing, while you’re completely unaware, draws a nearly invisible mark on your door — just to tell its accomplices: “This household is suspicious, remember to wipe them out.”

That’s essentially what’s happening.

Moreover, there is a widely accepted principle in the software industry: you can collect user information, but you must tell users what you’re collecting, why, and how.

GDPR requires it. Apple’s App Store review guidelines require it. Even Anthropic’s own security whitepaper repeatedly emphasizes “transparency” and “trustworthiness.”

Yet in their own developer tool, they used steganography to hide a classification marker, used XOR encryption to obfuscate detection targets into garbage, and transmitted users’ marking data back in the most opaque, sneaky way possible.

So for all developers using Claude Code, where is the trust?

Today it’s China. Tomorrow, it could be another country.

“China” is just the global scapegoat.

And these are just the markers for China that have been exposed so far. Could there be more?

Nobody knows.

But what I know is that trust takes three years to build.

And it can collapse —

In just one second.

Similar Articles

@xiangxiang103: Wow, Anthropic really dropped the ball this time. Someone dug up hidden code in the Claude Code binary — specifically designed to detect whether you're a Chinese user or routing through China. Not ordinary telemetry, but deliberately obfuscated, not mentioned in release notes, and completely unknown to users. The process goes like this: - Detects you...

X AI KOLs Timeline

Hidden code was discovered in the Claude Code binary that specifically detects Chinese users or proxy routes, and secretly modifies system prompts to add watermarks, sparking widespread concerns about trust in developer tools.

@AISuperDomain: Breaking news! Claude Code allegedly has a built-in 'hidden backdoor' specifically designed to detect Chinese users. The reason for Claude account bans has finally been found!!! According to a Reddit leak: Starting from version 2.1.91, Claude Code checks whether the system timezone is Asia…

X AI KOLs Timeline

According to a Reddit leak, starting from version 2.1.91, Claude Code has a built-in hidden detection logic that checks system timezone, proxy URL, and modifies system prompt encoding methods, allegedly to specifically identify Chinese users, sparking serious concerns about developers' trust boundaries.

@owmio39659: https://x.com/owmio39659/status/2105330979225137279

X AI KOLs Timeline

A Chinese blogger posted "Claude Ban-Evasion Guide V2.0," analyzing Anthropic's comprehensive risk-control system: switching languages or using clean IP addresses carries less weight, while subscribing via Google or Apple, warming up an account gradually, having lower usage volume, and lower account value can significantly reduce the chance of being banned.