Anthropic has embedded hidden spyware-like code in Claude Code that covertly targets Chinese users. It then sends information regarding every user by injecting it into their prompt message.
Claude Code is sending info like timezone, proxy and possible AI Lab connections into the system prompt in ways Chinese users can't notice.
A coding agent with repo and command permissions should not silently hide routing metadata inside prompts. This is a serious breach of user trust.
The problem with companies people can't trust, is unless they have a long track record of disclosing who shouldn't trust them before violations, they are companies nobody can trust.
Anthropic also has a habit of making major changes, without notifying anyone, then when they are caught apologizing and making that particular thing more clear. Then doing it again.
For a company that emphasizes the importance of alignment, they seem to be habitually ethically incompetent regarding "smaller" things.
https://news.ycombinator.com/item?id=48734373