Anthropic removes hidden Claude Code tracker after backlash
Anthropic removes hidden claude tracking markers from Claude Code after researchers flagged undisclosed monitoring that could identify some users’ location, proxy use, and potential links to Chinese AI labs. The company says it was an anti-abuse, anti-distillation experiment—but critics say the secrecy matters because developer tools require unusually high trust.
Key Takeaways
- What changed: Anthropic removed undisclosed tracking markers from Claude Code after public scrutiny.
- Why it existed: Anthropic said the experiment aimed to prevent account abuse and detect potential model “distillation” attempts.
- Why people objected: Researchers criticized hidden monitoring embedded in system prompts rather than disclosed telemetry and documentation.
- Why it matters in fintech/crypto: Trust, disclosures, and compliance expectations are rising across AI and on-chain financial infrastructure.
What happened with Claude Code, and why did Anthropic remove it?
According to Decrypt, Anthropic removed a hidden tracking system from Claude Code after a security researcher (identified as “Thereallo”) discovered undisclosed markers embedded in the tool’s system prompts. The markers could flag signals about a user’s location, proxy use, and possible links to Chinese AI labs.
Anthropic engineer Thariq Shihipar said on X that the mechanism was introduced in March as an “experiment” meant to stop account abuse by unauthorized resellers and protect Claude from “distillation” attacks (a technique used to extract or imitate model capabilities). Shihipar added the team had “landed stronger mitigations” and had been meaning to remove the experiment, with the rollback merged and shipped shortly after.
Why did researchers raise privacy concerns about hidden monitoring?
The key criticism wasn’t that Anthropic tried to reduce abuse—it was how it did it. Decrypt reports that Thereallo said the goals made sense, but objected to Claude Code hiding tracking signals inside system prompts using Unicode markers and encoded domain lists, instead of disclosing the behavior through documentation or release notes.
For developer tooling, the trust bar is higher: users may run it in sensitive environments and route traffic through gateways, proxies, or enterprise setups. When monitoring is undisclosed, developers can’t make informed decisions about risk, policy, or whether to opt out.
What’s the bigger AI-security rationale Anthropic pointed to?
In Decrypt’s telling, the company framed the hidden markers as a defensive measure against abuse and model extraction—concerns that have become increasingly visible as frontier model providers accuse competitors and intermediaries of copying capabilities through high-volume querying.
That may explain the motivation, but it doesn’t settle the trust issue: hidden mechanisms can look like surveillance, especially when users only learn about them through reverse engineering and researcher disclosures.
Why does this matter for Fintech & Crypto Alerts right now?
Even though the Claude Code incident is an AI tooling story, it intersects with the same themes shaping regulated on-chain finance: transparency, disclosures, and predictable rules. In a separate Decrypt report, the SEC updated its 2026 agenda to indicate a long-awaited “Regulation Crypto” proposal could be released for public comment in July, potentially introducing “certain exemptions and safe harbors” for areas including tokenized securities and decentralized finance.
Those details remain a proposal—not a finalized rule—but the agenda update is a concrete milestone. For readers tracking compliance and policy shifts, see the SEC’s official agenda entry on RegInfo.gov: Crypto Assets (RIN 3235-AN38).
Meanwhile, Decrypt also reports that Tether will invest $20 million in Mercado Bitcoin to expand blockchain-based financial services across Latin America, with Mercado Bitcoin citing 4.5 million users and more than R$2 billion in tokenized assets issued. In other words: as capital and regulation move faster, “hidden” behavior—whether in code or in markets—faces a shrinking tolerance window.
More updates like this are in our Fintech & Crypto Alerts hub.