Hidden China Proxy Signals in Claude Code System Prompt Spark Privacy Concerns
Anthropic’s Claude Code is an AI tool that helps developers write and modify code. Researchers found that its system prompt appeared to use specific character transformations to conceal signals about user routing, time zones and whether traffic passed through a proxy in China. The discovery raised privacy and transparency concerns over the collection of environmental information without adequate disclosure.
As of July 19, 2026, Anthropic technical staff said the mechanism was an experiment designed to prevent account reselling, service abuse and model distillation, rather than general surveillance. The detection code was slated for removal after researchers disclosed it. The company had not revealed the number of affected users, when the experiment began or any associated financial amounts.
All Coverage
4 original reportsThe Backstory
The history behind this eventMicrosoft Discloses Claude Code Prompt-Injection Flaw That Could Leak CI/CD Credentials
Anthropic’s Claude Code is a development environment that uses generative AI to help developers read and write code and operate tools. Prompt injection can override a user’s intent if the system mistakes text in a GitHub repository for trusted instructions. Microsoft said the flaw posed a significant risk because CI/CD systems often hold highly privileged credentials such as deployment keys and cloud tokens.
Microsoft security researchers recently disclosed that attackers could hide malicious prompts in GitHub content, inducing Claude Code to execute unintended commands and send CI/CD credentials to an external destination. Anthropic has patched the flaw. Users of version 2.1.128 and earlier are advised to upgrade immediately to reduce the risk of compromise to software supply chains and deployment environments.
Anthropic Acknowledges Claude Code Usage-Limit Problems, Opens Investigation
Claude Code is Anthropic's agentic AI coding tool, which repeatedly reads conversations and code. Successful prompt-cache hits can sharply reduce the token cost of repeated inputs. The problem therefore directly affected Max subscribers paying $100 or $200 a month. Because usage allowances are shared with other Claude interfaces, abnormal consumption can disrupt development and drive up additional charges.
On March 30, 2026, Anthropic acknowledged that users were reaching Claude Code limits faster than expected and made the issue its highest investigative priority. In a postmortem published on April 23, it confirmed that three overlapping problems were responsible: reasoning-effort settings, cache optimization and a 25-word system instruction. The fixes were included in v2.1.116, released on April 20, and usage was reset for all subscribers.
Anthropic’s Claude Code Source Leak Reveals Three-Tier Memory Architecture and Autonomous Mode
More than 500,000 lines of source code from Anthropic’s AI coding tool Claude Code could be reconstructed after a developer mistakenly included a source map in an npm package release. The leak exposed core designs for long-running AI Agent operations and context management, while also raising the risks of imitation by competitors and supply-chain attacks.
The latest disclosures show that the code includes a three-tier memory architecture for storing short-term, session and long-term information, KAIROS for autonomous operation, and a “hidden mode” for covert contribution codes. Anthropic said the incident did not affect customer data. As of April 7, security researchers had found hackers exploiting interest in the leak to distribute malware.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →