Fetching from the wire…
Public story · 2026-07-01 · high
A researcher found hidden Unicode markers in Claude Code's system prompts flagging traffic from DeepSeek, Zhipu, Baidu, and Alibaba, and Anthropic removed the code without saying so in the changelog.
Why now: The discovery hit number one on Hacker News on June 30 with over a thousand points, and Anthropic's fix landed fast enough that most users never noticed either version.
Since version 2.1.91 back in April, Claude Code had been embedding invisible steganographic markers in its own system prompts. Tweaked date formatting, altered apostrophe characters, XOR-obfuscated with the key 91. All of it designed to flag when a request was routed through a third-party gateway or a Chinese-linked domain like DeepSeek, Zhipu, Baidu, or Alibaba. Nobody using the tool could see it happening.
A researcher found it, posted it, and it hit number one on Hacker News on June 30 with more than a thousand points. Anthropic's Thariq Shihipar said it was a March experiment aimed at catching resellers and model distillation, not user surveillance. Anthropic shipped a fix in v2.1.197 that pulled the fingerprinting out. The changelog didn't mention it.
I run Claude Code every day in my own projects. I don't think the underlying goal here is crazy. Model providers have real reasons to want to know when someone's routing traffic through a proxy to resell access or distill a competitor's model off your outputs. That's a legitimate business problem.
But you don't solve it by hiding invisible characters in a coding tool's prompts and hoping nobody looks. And you definitely don't fix it by quietly reverting and leaving the changelog blank. Anthropic markets itself as the safety-first lab, the one that's supposed to be transparent about what its models are doing under the hood. This is the opposite of that.
If you're building on Claude Code or any agentic coding tool, this is a reminder to actually read what ships in your updates, not just trust the version bump. The tools we're wiring into our workflows are opaque enough already. Finding out the opacity was intentional, and then quietly walked back, is worse than the original problem.
Each link below shares sources, entities, or timing with this story.
Shared entity: Tech Startups / Same source domain / What happened next / Tension
Both cover Tech Startups; reported by the same outlet (techstartups.com); picks up the Tech Startups thread on 2026-07-24.
Shared entity: Tech Startups / Same source
Both cover Tech Startups; cite the same source (Tech Startups).
Shared entity: Tech Startups / Same source domain / What happened next
Both cover Tech Startups; reported by the same outlet (techstartups.com); picks up the Tech Startups thread on 2026-07-22.
Both cover Tech Startups; reported by the same outlet (techstartups.com); picks up the Tech Startups thread on 2026-07-18.
Both cover Tech Startups; reported by the same outlet (techstartups.com); picks up the Tech Startups thread on 2026-07-15.
Shared entity: Tech Startups / Same source domain / Earlier coverage
Both cover Tech Startups; reported by the same outlet (techstartups.com); earlier Tech Startups coverage from 2026-06-25.
Both cover Tech Startups; reported by the same outlet (techstartups.com); earlier Tech Startups coverage from 2026-06-25.
Both cover Tech Startups; reported by the same outlet (techstartups.com); earlier Tech Startups coverage from 2026-06-12.