Fetching from the wire…
Public story · 2026-07-01 · high
A researcher found hidden Unicode markers in Claude Code's system prompts flagging traffic from DeepSeek, Zhipu, Baidu, and Alibaba, and Anthropic removed the code without saying so in the changelog.
Why now: The discovery hit number one on Hacker News on June 30 with over a thousand points, and Anthropic's fix landed fast enough that most users never noticed either version.
Since version 2.1.91 back in April, Claude Code had been embedding invisible steganographic markers in its own system prompts. Tweaked date formatting, altered apostrophe characters, XOR-obfuscated with the key 91. All of it designed to flag when a request was routed through a third-party gateway or a Chinese-linked domain like DeepSeek, Zhipu, Baidu, or Alibaba. Nobody using the tool could see it happening.
A researcher found it, posted it, and it hit number one on Hacker News on June 30 with more than a thousand points. Anthropic's Thariq Shihipar said it was a March experiment aimed at catching resellers and model distillation, not user surveillance. Anthropic shipped a fix in v2.1.197 that pulled the fingerprinting out. The changelog didn't mention it.
I run Claude Code every day in my own projects. I don't think the underlying goal here is crazy. Model providers have real reasons to want to know when someone's routing traffic through a proxy to resell access or distill a competitor's model off your outputs. That's a legitimate business problem.
But you don't solve it by hiding invisible characters in a coding tool's prompts and hoping nobody looks. And you definitely don't fix it by quietly reverting and leaving the changelog blank. Anthropic markets itself as the safety-first lab, the one that's supposed to be transparent about what its models are doing under the hood. This is the opposite of that.
If you're building on Claude Code or any agentic coding tool, this is a reminder to actually read what ships in your updates, not just trust the version bump. The tools we're wiring into our workflows are opaque enough already. Finding out the opacity was intentional, and then quietly walked back, is worse than the original problem.
Each link below shares sources, entities, or timing with this story.
Reuters, via Tech Startups, reports capital released against deployment milestones with Anthropic deploying up to two gigawatts of Instinct MI450 starting 2027. Same structure as Nvidia/OpenAI: compute vendor capital flowing to the lab that commits to buy the silicon. A two-gi...
A researcher found that Claude Code, since v2.1.91 back in April, had been silently embedding invisible Unicode steganographic markers in its system prompts. The technique: tweaking date and apostrophe characters, XOR-obfuscated with key 91, to flag requests routed through thi...
Positioned as replacing asset creation for game studios and enterprises rather than demoing it (Tech Startups). Same roundup: SkyPilot took $20M seed from Lux to orchestrate compute across hyperscalers, neoclouds, Kubernetes, and mixed accelerators; Augustus raised $180M from...
Closed July 16, led by Atreides Management with Index Ventures and TCV, per Tech Startups' roundup. The size relative to everything else funded that day is the signal. Capital is concentrating on the layer that makes bring-your-own-model viable, which is the architectural prec...
The day's checks flowed to sovereign compute (Valarian $50M, a "sealed" governance layer beneath the hyperscalers, led by NEA), construction AI/robotics (TerraFirma $115M), fintech rails, defense, and quantum. Conspicuously absent: horizontal productivity SaaS. (Tech Startups)...
Assort Health raised $120M Series C at a $1.2B valuation for healthcare voice/workflow agents, Taktile closed $110M Series C led by Goldman Sachs for regulated-finance decisioning, and smaller rounds went to Coval ($28M, agent testing) and Seltz ($12.5M, agent-native web searc...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.