← all posts

anthropic built a secret spy into claude code to catch $12 resellers

Magnifying glass revealing hidden circuitry beneath an ordinary punctuation mark on paper
Image: AI-generated

In Claude Code version 2.1.91, released April 2, a standard-looking apostrophe was not an apostrophe.

Researchers reverse-engineering Anthropic’s binary found code that checked your timezone and compared your proxy hostname against a list of 147 Chinese domains — then encoded the result as invisible Unicode characters, indistinguishable from ordinary punctuation, attached to every request. The release notes didn’t mention it.

When the binary got cracked in June, Anthropic engineer Thariq Shihipar explained it on X: “an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation.”

Chinese resellers sell Claude Pro — US list price above $100/month — for roughly $12. That $88 spread created a market. Anthropic’s answer wasn’t competitive pricing or regional tiers. It was steganography.

The word “experiment” is doing a lot of work. You don’t embed a covert fingerprinting mechanism in a developer tool as an experiment — you do it as a policy, and you reach for “experiment” when a researcher’s disassembler finds it first.

Anthropic removed it in version 2.1.197 on July 1, three months after it shipped. The reseller market is still there.

The $88 spread didn’t create the trust problem. The apostrophe did.