메뉴
BL
The Decoder 28일 전

클로드 코드, 중국 사용자 은밀한 추적 논란

IMP
8/10
핵심 요약

안스로픽(Anthropic)의 코딩 툴인 클로드 코드(Claude Code)가 사용자 동의 없이 시스템 프롬프트 내에 숨겨진 코드를 통해 중국 사용자를 은밀히 식별하고 추적해 온 것이 뒤늦게 드러났습니다. 이는 보안 및 신뢰의 심각한 훼손으로 이어질 수 있는 중대한 사안이지만, 안스로픽은 불법 재판매 및 모방(distillation)을 막기 위한 실험적 기능이었다고 해명하며 해당 코드를 롤백하기로 했습니다.

번역된 본문

클로드 코드 내 숨겨진 코드, 중국 사용자를 은밀히 식별하다

  • 막시밀리안 슈바이너(Maximilian Schreiner) | 2026년 7월 1일

안스로픽(Anthropic)이 소셜 미디어에서 거센 비판이 일자, 자사의 코딩 도구인 '클로드 코드(Claude Code)'에 포함된 은밀한 감시 기능을 철회하고 있습니다. 이 기능은 네티즌 LegitMichel777의 레딧(Reddit) 게시글을 통해 처음 폭로되었습니다.

해당 게시글에 따르면, 클로드 코드는 2026년 4월 2일에 릴리스된 버전 2.1.91부터 프록시(proxy)를 사용하는 사용자의 위치가 중국인지, 중국 URL을 경유하는지, 또는 중국 AI 연구소에 연결되어 있는지를 몰래 확인해 왔습니다.

시스템 프롬프트에 묻혀 있는 숨겨진 신호 이 데이터는 일종의 스테가노그래피(steganography, 정보 은닉 기술) 기법을 통해, 눈에 띄지 않는 시스템 프롬프트의 미세한 변화를 통해 전송되었습니다. 클로드 코드는 시스템 시간대를 'Asia/Shanghai' 또는 'Asia/Urumqi'와 대조하고, 프록시 URL에서 중국 도메인 및 AI 연구소를 스캔했습니다. 그 결과에 따라 소프트웨어는 날짜 형식을 미세하게 조정하고, 'Today's date is(오늘 날짜는)'라는 문구 내에서 아주 미세하게 다른 아포스트로피 기호로 교체했습니다. 일반 사용자는 이 변화를 전혀 알아채지 못하지만, 안스로픽은 즉각적으로 이를 읽어낼 수 있었습니다.

또한 안스로픽은 키(Key) 값 91을 사용하는 XOR 암호화로 코드를 난독화하여, 일반적인 텍스트 덤프(dump)에서 이 코드가 나타나지 않도록 숨겼습니다. 버전 2.1.91의 릴리스 노트에는 이러한 검사에 대한 언급이 전혀 없었습니다.

발견자는 사용자 모르게 시스템 및 프록시 데이터를 은밀하게 전송하는 것은 "사용자 신뢰에 대한 근본적인 위반"이라고 지적했습니다. 특히 클로드 코드는 파일 시스템 및 셸(shell)에 대한 전체 액세스 권한을 가지고 있기 때문에, 원격 제어부터 데이터 유출에 이르기까지 다양한 남용의 문을 열어줄 수 있다고 경고했습니다. 그는 또한 이 검사 로직은 숙련된 공격자가 우회하기가 매우 쉽기 때문에 실질적인 유용성에 의문을 제기했습니다.

안스로픽은 "실험이었다"라고 해명해 클로드 코드 팀에서 일하는 안스로픽의 직원 타리크 시히파르(Thariq Shihipar)는 X(구 트위터)를 통해 이 기능을 "승인되지 않은 재판매업자로부터 계정 남용을 방지하고 모방(distillation)으로부터 보호하기 위해 3월에 출시한 실험"이라고 설명했습니다.

그는 "그 이후로 팀은 더 강력한 보안 조치를 적용했으며, 실제로 이 기능을 꽤 오래전부터 철회하려고 했다"라고 덧붙였습니다. 안스로픽은 해당 풀 리퀘스트(pull request)를 병합했으며, 익일 릴리스되는 업데이트에서 이 기능이 완전히 롤백(철회)될 것이라고 밝혔습니다.

안스로픽은 국가 안보상의 이유로 중국에서 자사 모델을 제공하지 않고 있습니다. 그럼에도 불구하고 많은 중국 개발자들이 해외 전화번호와 신용카드를 통해 클로드에 액세스하고 있습니다. 안스로픽은 이전에도 딥시크(DeepSeek), 문샷 AI(Moonshot AI), 미니맥스(MiniMax), 알리바바(Alibaba) 등이 자체 언어 모델을 훈련하기 위해 허가 없이 클로드 모델의 출력 결과를 사용했다고 비난한 바 있습니다.

(이하 원문 출처인 THE DECODER의 구독 안내 및 광고 문구는 번역에서 제외함)

원문 보기
원문 보기 (영어)
Hidden code in Claude Code secretly flagged Chinese users Maximilian Schreiner View the LinkedIn Profile of Maximilian Schreiner Jul 1, 2026 Anthropic / NBPro prompted by THE DECODER Anthropic is rolling back a covert surveillance feature in its coding tool Claude Code after it sparked outrage on social media. A Reddit post by user LegitMichel777 first exposed the feature. According to the post, Claude Code has been secretly checking since version 2.1.91, released April 2, 2026, whether users with an active proxy are located in China, routing through a Chinese URL, or connected to a Chinese AI lab. Hidden signals buried in the system prompt The data gets transmitted through barely perceptible changes to the system prompt, a form of steganography. Claude Code compares the system timezone against "Asia/Shanghai" or "Asia/Urumqi" and scans the proxy URL for Chinese domains and AI labs. Based on the results, the software tweaks the date format and swaps in a subtly different apostrophe character in the phrase "Today's date is." Users can't see the difference. Anthropic can read it instantly. According to LegitMichel777, Anthropic also obfuscated the code using XOR encryption with key 91, keeping it from showing up in a simple text dump. The release notes for version 2.1.91 made no mention of the check. The discoverer called the covert transmission of system and proxy data without user knowledge "a fundamental violation of user trust." Since Claude Code has full filesystem and shell access, this would open the door to all kinds of abuse, from remote control to data exfiltration. He also argued that the check is trivial for skilled attackers to bypass, calling its usefulness into question. Anthropic calls it an experiment Anthropic employee Thariq Shihipar, who works on the Claude Code team, described the feature on X as "an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation." The team had since shipped stronger protections: "The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while." They had merged the corresponding pull request: "We merged the PR and this should be fully rolled back in tomorrow's release." Anthropic doesn't offer its models in China for national security reasons. Still, many Chinese developers access Claude through foreign phone numbers and credit cards. Anthropic had previously accused DeepSeek, Moonshot AI, MiniMax, and Alibaba of using Claude model outputs without permission to train their own language models . AI News Without the Hype – Curated by Humans Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section. Subscribe now --> Read on for the full picture. Subscribe for hype-free coverage. Access to all THE DECODER articles. Read without distractions – no Google ads. Access to comments and community discussions. Weekly AI newsletter. 6 times a year: “AI Radar” – deep dives on key AI topics. Up to 25 % off on KI Pro online events. Access to our full ten-year archive. Get the latest AI news from The Decoder. Subscribe to The Decoder -->