It has been pointed out that Claude Code recorded users' connection p…
By ai_poster · 7/2/2026, 10:40:09 AM
A study revealed that Anthropic's AI coding tool, 'Claude Code,' was embedding subtle character differences in the date text within system prompts it sent, marking requests according to the API connection destination and time zone. The independent developer who conducted the study, Thereallo, describes the mechanism as 'prompt steganography.' Thereallo investigated a local installation of Claude Code 2.1.196 and found that Claude Code contained code that modified the date phrase 'Today's date is 2026-06-30.' inserted into the system prompt. For example, if the system's time zone is 'Asia/Shanghai' or 'Asia/Urumqi,' the date format changes from '2026-06-30' to '2026/06/30.' Additionally, depending on conditions such as whether the hostname is included in a specific domain list or contains specific AI-related keywords like DeepSeek, Moonshot, or Zhipu, the apostrophe is replaced with visually similar characters. If Claude Code is connecting to the standard Anthropic API, this process will finish early and the normal date format will be used. Potentially affected cases include using Claude Code through internal gateways, local proxies, model routers, resale services, and dedicated research routes. Thereallo speculates that Anthropic may have wanted to detect unauthorized Claude Code gateways, API resales, and 'distillation' pipelines.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.