Publisher: Ars Technica
Date Published: July 6, 2026
Relevant To: Undisclosed AI vendor telemetry/tracking; corporate privacy-claim accountability case study
Verification Status: Verified — Ars Technica Blocked, Confirmed via Extensive Syndication
Notes: Confirmed via extensive corroboration (Futurism, Slashdot, Gadget Review, Stacker News) since Ars Technica itself was blocked for direct fetch. A security researcher known as “Thereallo” discovered hidden tracking code in Claude Code v2.1.91 (shipped early April 2026) that used “prompt steganography” — Unicode tricks and obfuscated/XOR-encoded domain lists hidden in the system prompt — to silently flag users’ system timezone and proxy-server usage in order to identify likely connections to Chinese AI labs, without any disclosure in release notes or documentation. Anthropic engineer Thariq Shihipar confirmed on X that the tracker was added as a March 2026 “experiment” to combat unauthorized resellers (Washington Post separately found some resellers selling $100/month Pro subscriptions for as little as $12) and to protect against “distillation” (using Claude’s outputs to cheaply train rival models). Anthropic said the tracker had already been made obsolete by “stronger mitigations” and was removed in the July 1, 2026 release — notably, only after public exposure, not before. Alibaba banned internal employee use of Claude Code in direct response, per an internal memo reviewed by South China Morning Post, calling it “high-risk software with security vulnerabilities.” Critics noted the irony: Anthropic had publicly refused Pentagon demands to let Claude operate without mass-surveillance guardrails (and is separately in litigation with the White House over a related dispute), making this covert tracking of its own users appear to contradict its stated anti-surveillance principles. Thereallo’s core critique, directly relevant to BPA’s framing: “Hiding the signal in the system prompt makes every other privacy claim harder to believe” — and the tracking disproportionately affects “normal developers doing weird but legitimate things” who are easiest to fingerprint. Relevant to BPA’s broader AI-transparency and corporate-accountability tracking as a case study in undisclosed telemetry/tracking by a major AI vendor, notable given Anthropic’s public brand positioning on privacy and safety.