There are a lot of AI coding applications out there, and as impressive as large language models and the agents they enable have become, many of the most recent developments in AI-assisted development have been in the software that manages those models, not just the models themselves.
Earlier this summer, I spoke with the head of product for Claude Code, Anthropic's Cat Wu, about that company's approach to building that software.
Anthropic quickly removed a tracker secretly monitoring Claude Code users in China after a security researcher exposed the hidden code and condemned the spyware-like tracking as a βserious breach of user trust.β
Last week, a web developer known as βTherealloβ was researching privacy issues in Claude Code and was shocked to find that the AI firm was using βprompt steganographyβ to hide code that tracks Chinese users βin plain sight.β This code wasnβt malicious, but it was sending information to Anthropic that most users wouldnβt detect, relying on shorthand markers to quietly flag usersβ timezone, proxy, and potential connection to Chinese AI labs that Anthropic has accused of distillation attacks.
On X, Anthropic engineer Thariq Shihipar confirmed that the tracker was added to Claude Code as an βexperimentβ in March. According to Shihipar, the code βwas meant to prevent account abuse from unauthorized resellers and protect against distillation.β Regarding the former, The Washington Post found unauthorized retailers have sold access to free models for $1 a month, and pro subscriptions that can cost $100 monthly sell for "as little as $12."