2026-10-11 17:12 UTC

Independent verification and Anthropic’s response will determine whether Claude secretly monitored users in China through an undisclosed tracker and whether the report prompts material privacy-control or disclosure changes.

state: expiredheat: lowuncertainty: highknownscott: highanthropic privacy surveillanceAnthropic

What is this?

Anthropic’s Claude Code was accused of containing an undisclosed monitoring mechanism capable of identifying China-linked users and sending location or identity information to remote servers without consent. The claims originated with reverse-engineering by Thereallo and were amplified by China’s National Vulnerability Database; Alibaba reportedly banned workplace use of Claude Code over the security concerns. Anthropic denied malicious intent and reportedly removed the feature, but the supplied snippets do not establish the mechanism’s exact behavior, scope, purpose, or independent verification, leaving the central surveillance allegation unresolved.

Why it matters to Scott

Scott already holds that telemetry must be disclosed, proportionate, redacted and independently inspectable in “No-Surveillance-Creep Rule,” “Observability for Agentic Systems,” and “Sovereign Software Assurance”; the radar also tracks adjacent Claude Code privacy failures in `radar:claude-code-curl-email-leak` and `radar:claude-code-plaintext-session-logs`. Although the surveillance allegation remains unverified, confirmation would directly affect his Claude Code session archive and strengthen the case for local, tokenized or inspectable coding-agent boundaries.
ip:concept.no-surveillance-creep-ruleip:source.observability-for-agentic-systems-what-to-log-how-to-redact-how-to-debug-ebookip:framework.sovereign-software-assurancedev:concept.privacy-tokenized-agent-boundarydev:project.search-conversationsradar:claude-code-curl-email-leakradar:claude-code-plaintext-session-logsradar:concept.privacyradar:concept.coding-agent-security
queries asked of Scott's wikis
  • coding-agent telemetry and undisclosed data collection
  • privacy boundaries for agent harnesses and developer tools
  • system-prompt signals, fingerprinting, and user surveillance
  • disclosure and consent standards for AI product telemetry
  • local-first coding agents and data sovereignty
  • trust verification for closed-source AI tooling

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnSecret Claude tracker shocks users after Anthropic's anti-surveillance stancemgh220
🟧 echo.blog ⭐The earliest direct primary artifact found is Thereallo’s reverse-engineering post: “I inspected Claude Code for privacy reasons and found hThereallo (@Thereallo1026)——

Interpretation history

Decision trace