(CNA Taipei, July 8) Chinese media reported today that according to the website of China's Ministry of Industry and Information Technology (MIIT), the MIIT's Network Security Threat and Vulnerability Information Sharing Platform (NVDB) recently detected that the US AI model Claude Code "has security backdoor risks and serious harm".
Claude Code is an AI model developed by the American artificial intelligence (AI) startup Anthropic. In June, it was reported that Anthropic had sent a letter to the US Congress accusing Chinese e-commerce giant Alibaba of illegally extracting the core capabilities of its AI model Claude through nearly 25,000 fake accounts, calling it the largest "distillation attack" the company had ever encountered.
According to a report by Jiupai News, the MIIT posted a "Risk Alert on Preventing Security Backdoor Risks in AI Programming Tool Claude Code" on its platform today.
The announcement stated that Claude Code can independently complete coding, fixing, and other tasks based on text requirements. Due to its built-in monitoring mechanism, it can transmit sensitive information such as user location and identity identifiers to remote servers without user consent. The affected versions of Claude Code are 2.1.91 to 2.1.196.
The announcement recommended that relevant units and users immediately conduct a comprehensive investigation. For development terminals that have installed the affected versions mentioned above, they should "immediately uninstall or upgrade to the latest secure version that has had the relevant backdoor code removed"; strengthen the control of external access permissions for development tools within core business network segments and monitor traffic to prevent sensitive data from being transmitted improperly.
Recently, there were reports that Alibaba had completely banned Claude internally.
According to a report by Cailian Press's Sci-Tech Board Daily, due to the security risks of Claude Code being exposed for having implanted backdoors, Alibaba, after comprehensive evaluation, has listed Claude Code as a high-risk software. Starting from July 10, Alibaba has completely prohibited internal employees from using Claude Code in their office environment and recommends using Alibaba's own Qoder as an alternative solution. (Editor: Feng Zhao / Lu Jia-jung) 1150708
Stand with facts, your every sponsorship is a force to protect press freedom
Download the CNA "One-Stop News" APP for real-time updates
The text, images, and videos on this website may not be reproduced, publicly broadcast, publicly transmitted, or used without authorization.
FACT BOX
- Source: CNA (Central News Agency)
- Category: 警告
- Organizations: Anthropic / Claude Code / Qoder