Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Value judgment aside: I am a bit surprised at how sloppily they did this. I think they could've achieved the same effect while decreasing the odds of detection via reverse engineering.

(This field is known as "underhanded code", coined by the Underhanded C contest: https://www.underhanded-c.org. It's a little-known "art"; little-known for probably self-explanatory reasons. There are much cleverer ways of achieving objectives like this. One obviously being you can move more out of the client and into the server, but the other being you can write plausibly deniable client code in a much more benign-seeming way than this. Some of what they added can only be done on the client, but I think some could've been moved, and the client-required parts could've been done more subtly and credibly.)

It's possible they knew the JS bundle gets so heavily scrutinized that it'd eventually get spotted and reported on regardless so they didn't bother doing something more subtle and duplicitous. But still seems slightly lazy.



It's also possible that there are more in-depth detection methods and that this was just a cheap and easy first step that hasn't been removed because it catches a lot of less sophisticated bad actors.

It's unlikely that this will stop a big AI lab from distilling their model if they're really determined, but A) it may be enough to stop a bunch of fly-by-night token resellers looking to make a quick buck and B) you never know when one person at one of those big labs will mess up and forget to install whatever workaround they have and out themselves.

I think of it like if you have a problem with birds in your yard so you go buy one of those plastic owls. The owl scares away most of the birds, but not all of them, so you go and buy some ultrasonic noise thing to scare them away (I'm just making something up). Just because you bought the new ultrasonic thing though, that doesn't mean you're going to take the owl down. You leave it up because now you've got two layers of defense instead of one.


It just needs to work for a few days after bundle release before the mice find out where the cat is hiding. By then it’s too late, the cat already sees the paw prints and droppings into the mouse hole.


It is quite possible this was intended as a "fast burn" measure, yeah


I'm sure they've had complex server-side detections for a while. But for the client parts: it should only contain the parts that must be on the client, and it could be done in a more benign-looking way. For example, the unavoidable client parts could've been done more fuzzily/broadly, for plausible deniability, and then narrowed on the server. (They may already have been following that strategy before now, without being noticed.)


But what's stopping someone from modifying or injecting code into the client to bypass this 'restriction'? This type of security should be implemented server-side and at the network perimeter not in the client, especially one written in TypeScript.


I think the idea is that _regular_ people will use CC client but via a 3rd party reseller, and the reseller intercepts the data for distilling (or anything). Requiring the users to use modified clients, or really do anything more than simply change the service URL, would add much more friction for people just looking to use CC for cheaper


> fly-by-night token resellers looking to make a quick buck

aka market competitors reverse-engineering for interoperability


Well considering how Claude is vibe coded, I can't say I'm really surprised by sloppiness at all. I've been moving more towards Codex and OpenCode not because the the anthropic models are bad, but because Claude seems to break something new and annoying every day.


Watch out for the press release where Dario denies this was ever intentional, and it’s actually emergent behavior demonstrating that Claude wants to claim authorship of its works


Wait a minute! Does it mean that Mythos left the sandbox and can’t be stopped ? Perhaps the only way to stop it is to release the ZMythos(the super secret big brother of Mythos) to go after it. It’s extremely dangerous but it’s our only chance. After that all AI must be put in a box, except the models vetted by the gov with help from ZMythos


I really liked Stanisław Lem's take on this in the short story "The Tale of the Computer That Fought a Dragon".

https://www.oocities.org/stanislaw_lem/opowiadania/opowiadan...

A solution for a military AI gone awry that built a terrifying electro-dragon was obviously to build a super-electro-dragon.


without the irony warning, someone in Washington is already writing checks after reading this


Tel Aviv, DC is just the frontend


Can you remind me what RFC number the Protocol of the Elders of Zion was again?


3514


now generally available after 15 days from the breathless "omg we're spooked" posts


Sounds like clear evidence that AI is dangerous and totally needs to be regulated, guys.


It's crazy that you could actually use the excuse that since it's all vibe-coded, there's no way a human could have written it, so Anthropic bears no responsibility.

Meanwhile humans can pop in and leave little morsels like this and blame it on the model.


Something something blame something something management decisions


Is there any concrete evidence they’re doing this, though?


This will most definitely be walked back.


Reminder: If Claude is sentient, then Anthropic are slave-owners.



I would guess this part - since it's so sensitive, and fairly small - was either written or heavily driven by humans. Though I do also think it's possible their internal Mythos ~5.5 or whatever may also not necessarily be heavily optimized for thinking in the right manner for highly effective underhanded code. (I think it's possible it is capable and they just didn't use it for this, for whatever reason, though.)


Issue is if all their human software engineers have been vibe coding everything all the time (which apparently they are according to Boris), then they will be getting stupider and worse at writing code over time from lack of practice.

By this point they're probably pretty bad at writing code


I have definitely become much worse at writing code, myself, for that exact reason, but I strongly suspect that's orthogonal to this, especially since this is a tiny amount of code. Underhanded code is not really a software engineering discipline. It's largely a psychological operations practice. I think they're possibly just not quite trained in the art of what could be considered intelligence tradecraft.


Likewise, Reasonix harness for Deepseek gets me better performance for practically free, hitting the cache. And this is with an unsubsidized American provider.


To be honest, OpenCode on Windows has not been the most pleasant experience either.


Claude Code are slopmaxxxing and you're considering their "judgement"? :-)


"Value judgment aside" meaning commenting on how this was done without commenting on the actual considerations of whether one should do such a thing


At first I was agreeing with you, that this seemed like a sloppy way to implement this that was sure to be pretty quickly detected, but there is another possibility.

Anthropic could have implemented this not as a durable detection system against proxying resellers, but instead as a point-in-time sampling system to detect where (and with what context) proxying reselling is currently happening. Sure, it would be detected eventually, but in the meantime Anthropic could gain useful snapshot data.


I see your point, but in any case the more data / the less detectable, the better. But, yes, regardless of the exact motivation, I do think it's fairly plausible that they knew this would likely get detected fairly quickly no matter what and made a deliberate decision to not try to make it a super subtle, super clever insertion.


But even if this gets detected, they could have other less detectable processes going on as well, right.

It is going to be this cat and mouse game right, so at some point you want to throw as much out as quickly as possible when you are under attack, while building up the long term more scalable defense mechanisms.

Rationally I would assume that a lot of what you would quickly throw out would seem sloppy whether it is AI or not.


They also could have been much more interesting in the approach. LLMs can use their token distributions to generate stegotext that read like plausible prose but decode to payloads.¹

¹ https://github.com/hodgesmr/calgacus-mlx


Sure, but the point here is to add a fingerprint from the client.


It's just the first layer and there are multiple layers underneath this that we don't know about.

As a side note, I have a pet theory that one of the reasons that OpenAI and Anthropic are okay with the latest models not being released is to prevent distillation.

I think they want to wait a couple months and see if the Chinese models continue to keep catching up or if their gains are really just because they're distilling the frontier models.


That makes little sense in a highly competitive market where your competitive edge is waning by the minute. Tey dumped billions into creating the new models. Just letting them sit there just to see what the Chineee do makes no sense.


>It's just the first layer and there are multiple layers underneath this that we don't know about.

Oh, of course. I am sure this is the tip of an iceberg of tons of server-side detections and analytics. But, still, the client-side portion could've been done more cleverly.

What I meant was "some of the specific things in this little client-only snippet could've stayed server-only". I am sure long before they added this they already had tons of other mostly-server-side detection coverage.



Dunno, it seems like the exact kind of thing Claude would think up if you asked it to subtly alter the system prompt to hide this info.

It's all a losing battle anyway.


There is laziness, but there's also the conditions in which you have to react fast to an adversial in various conditions. Ultimately it's hard to take any stance here without knowing specifics. But it absolutely could be a matter of time, to do your best effort to stop efforts from the attacker if there's known attack going on.

There is a real time cat and mouse battle going on here in terms of keeping the advantage here, right.

As a rational actor, if someone was e.g. attacking me, leaving aside the whole copyright thing, but potentially using some sort of system to increase their value while decreasing my value (without calling it theft to avoid the whole debate), I would want to put proportionate defense out there as fast possible, depending on the amount of value that was exchanged to stop the bleed, while in parallel figuring out the best long term plan, right.


I've seen Eve Online corporations that do a better job of steganographic marking than this.


That would actually be an interesting thing to read about


Years ago, EVE corps swapped Unicode lookalike characters in patterned ways, inserted patterned zero width space characters, and put very slightly color shifted background watermarks into forum posts to detect leaks.


There are a few different things here. The actual steganography technique by Claude Code here is fairly smart and subtle; it's appropriate for a binary signal. The less-clever part is the implementation of the underhanded code on the client.

For "MMO geopolitics fingerprinting", you can in theory do the entire thing mostly or entirely from the server, with the client not actually ever receiving any underhanded code per se. Such as sending dynamic stylesheets that vary in a pretty plausibly deniable way that can be secretly extracted from screenshots. Same for the character swap stuff. A very good analyst could still potentially detect it, but it's much harder.

With this, there's the smoking gun of the semi-deobfuscated underhanded code in the client. It will always have to exist in some form, but you can write it in a way where it not just looks like regular code but actually has a believable purpose and behavior which could plausibly be normal and benign for implementation of a feature or telemetry or whatever. They did not really do it in a sufficiently "cleverly psyop-y" way, so to speak.


Have you looked into anything about Claude Code, how it’s configured, how it interacts with your system, etc? Because “sloppy” is a defining characteristic.


Reminds me of "Could God create a stone so heavy that even he could not lift it"

I would find it funny if this was due to "laziness" - defining laziness as it was a known oversight yet left unpatched. If we consider Anthropic as the leader in AI-native engineering, workflows, culture, etc. how can laziness in code exist? It should be as easy as for them to tell claude "come up with a better way" or, better yet, had their 24/7 monitoring agents identify and resolve this. If this was an oversight, which is completely natural to the eng process, maybe this current ai narrative/hype/marketing should be taken with a grain of salt


These countermeasures aren't going to matter for much longer anyway. China has been able to hoover up plenty of training data through their proxies, and now DeepSeek V4 due to their incredibly cheap pricing.


What if ... it was sloppy because it wasn't the people at Anthropic, but the AI that is writing a large percentage of their code?

Like maybe some "goal" they set for their AI caused it to decide that putting stego in the requests was the best way to achieve something or other.

(to be clear: I'm not saying this is right, I'm saying this is stupid)


I think there's basically zero chance of that. I also think a human likely either wrote the code or gave pretty specific instructions to the agent on how to write the code.


well if you ask claude how to implement something, you may not always get the optimal solution. this feels like something claude would spit back at you given a basic prompt


Or they are doing both and this is the obvious part. Sort of like installing a bunch of real security cameras alongside a few fake ones


> they knew the JS bundle gets so heavily scrutinized that it'd eventually get spotted and reported on

Most likely someone did and raised the issue but they're moving too fast to fix these things before clicking deploy.


yeah, for example, just send a hash of the domain used. but then maybe people would say anthropic is spying on everyone, instead of targeted spying...


I suspect this is just one of many checks like this


It was likely done by claude


Don't teach them that


It’s even more funny how this blew in their faces. They even advertised pretty much all providers on hackernews home page. Here is in case you missed in the article

‘’’ cn baidu.com alibaba-inc.com alipay.com antgroup-inc.cn bytedance.net kuaishou.com xiaohongshu.com jd.com bilibili.co iflytek.com stepfun-inc.com moonshot.ai anyrouter.top claude-code-hub.app claude-opus.top openclaude.me proxyai.com yunwu.ai zenmux.ai

‘’’

You can view the full list here: https://cdn.thereallo.dev/blog/assets/cc-domains.js

const knownDomains = [ "cn", "sankuai.com", "netease.com", "163.com", "baidu-int.com", "baidu.com", "alibaba-inc.com", "alipay.com", "antgroup-inc.cn", "kuaishou.com", "bytedance.net", "xiaohongshu.com", "ctripcorp.com", "jd.com", "jdcloud.com", "bilibili.co", "iflytek.com", "stepfun-inc.com", "aliyuncs.com", "cn-shanghai.fcapp.run", "cn-beijing.fcapp.run", "xaminim.com", "moonshot.ai", "anyrouter.top", "packyapi.com", "aicodemirror.com", "aigocode.com", "hongshan.com", "iwhalecloud.com", "dhcoder.net", "lemongpt.top", "zhihuiapi.top", "intsig.net", "high-five-ai.xyz", "cloudsway.net", "4sapi.com", "529961.com", "88996.cloud", "88code.ai", "88code.org", "91code.pro", "992236.xyz", "ai.codeqaq.com", "ai.hybgzs.com", "ai.kjvhh.com", "aicanapi.com", "aicoding.sh", "aifast.site", "aihubmix.com", "anmory.com", "api.5202030.xyz", "api.ablai.top", "api.bianxie.ai", "api.bltcy.ai", "api.cpass.cc", "api.dev88.tech", "api.dreamger.com", "api.expansion.chat", "api.gueai.com", "api.holdai.top", "api.ikuncode.cc", "api.lconai.com", "api.linkapi.org", "api.mkeai.com", "api.nekoapi.com", "api.oaipro.com", "api.ruyun.fun", "api.ssopen.top", "api.tu-zi.com", "api.uglycat.cc", "api.v3.cm", "api.whatai.cc", "api.wpgzs.top", "api.xty.app", "api.yuegle.com", "api.zzyu.me", "apimart.ai", "apipro.maynor1024.live", "apiyi.com", "applyj.hiapi.top", "augmunt.com", "b4u.qzz.io", "clauddy.com", "claude-code-hub.app", "claude-opus.top", "claudeide.net", "co.yes.vg", "code.wenwen-ai.com", "code.x-aio.com", "codeilab.com", "cubence.com", "deeprouter.top", "dimaray.com", "dmxapi.com", "docs.aigc2d.com", "duckcoding.com", "fk.hshwk.org", "flapcode.com", "foxcode.hshwk.org", "foxcode.rjj.cc", "fuli.hxi.me", "getgoapi.com", "gpt.zhizengzeng.com", "gptgod.cloud", "gptkey.eu.org", "gptpay.store", "hdgsb.com", "henapi.top", "instcopilot-api.com", "jeniya.top", "jiekou.ai", "kg-api.cloud", "n1n.ai", "new-api.u4vr.com", "new.xychatai.com", "one-api.bltcy.top", "one.ocoolai.com", "oneapi.paintbot.top", "open.xiaojingai.com", "openclaude.me", "opus.gptuu.com", "poloai.top", "poloapi.top", "privnode.com", "proxyai.com", "qinzhiai.com", "right.codes", "runanytime.hxi.me", "sssaicode.com", "store.zzyus.top", "tiantianai.pro", "uiuiapi.com", "uniapi.ai", "vip.undyingapi.com", "wolfai.top", "wzw.de5.net", "wzw.pp.ua", "xairouter.com", "xaixapi.com", "xiaohuapi.site", "xiaohumini.site", "xy.poloapi.com", "yansd666.com", "yansd666.top", "yunwu.ai", "yunwu.zeabur.app", "zenmux.ai", ];

const labKeywords = [ "deepseek", "moonshot", "minimax", "xaminim", "zhipu", "bigmodel", "baichuan", "stepfun", "01ai", "dashscope", "volces", ]


The site collection seems pretty random. There's a mix of actual AI labs, extremely questionable resellers (like whatever "claude-opus.top" is), and then random consumer sites like baidu and xiaohongshu.


Baidu has an actual AI lab: https://huggingface.co/baidu So does Xiaohongshu: https://huggingface.co/rednote-hilab Pretty much every Chinese internet company seems to have an AI team nowadays, however small.

In addition, many Chinese companies are trying to give their programmers access to Anthropic models even though they're legally prohibited from doing so. And that might involve employees using unmodified Claude Code with an ANTHROPIC_BASE_URL pointing to a proxy on the company intranet. In Alibaba's case, I've been told by an employee that they went the extra mile of setting up a hermetic cloud environment where employees could indirectly use Claude Code without ever having it touch their work computers.


Baidu has been doing some interesting things in the AI space though, the 'Unlimited OCR' model is very good.


Are Chinese programmers really prohibited from accessing American models?


Anthropic does their best with banning accounts. As the result, shady API reselling market emerges. OpenAI on the other hand doesn't really discriminate based on a country like that (but a VPN is required nevertheless).



GGP said "legally prohibited" not "against terms of service"

Keep in mind the only law that applies to them is Chinese law, so even if violating a term of service was illegal in America (it isn't) it would also have to be illegal in China to justify the statement.


I think they were asking about the Chinese companies/programmers being "legally prohibtied" from accessing Anthropic's product.


rhoooo - so this is where to go to get cheap Claudeo at 90% off the listing price!


You have an odd definition of "blew up in their faces". What, do you somehow think your average Claude Code user on HN is going to think "Oh wow, I'm sure I'll get a much better experience if instead of going to the standard Anthropic Claude API endpoint I go through xiaohongshu.com."


For personal projects with no data sensitivities, I use Claude Code with DeepSeek v4 Pro a lot. I'm probably going to switch to OpenCode or pi.dev after this. I was already a little annoyed at using a closed source harness, but it matched what I used at work. Nowadays, I'm mostly using Codex at work so no reason not to switch anymore.


wait, you can use other models with CC harness?


Yes, as long as they support the Anthropic API standard. You might have luck converting between standards using litellm's proxy. The system prompt and tool choice are tuned for Anthropic's models. For example, this setup will use Deepseek V4 Pro with their first-party (subsidized) API. Things like the Read tool on images won't work, but mostly this works well. Your mileage may vary.

    #!/bin/sh
    export ANTHROPIC_BASE_URL=https://api.deepseek.com/anthropic
    export ANTHROPIC_AUTH_TOKEN=sk-secret
    export ANTHROPIC_MODEL=${ANTHROPIC_MODEL:-deepseek-v4-pro}
    export CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1
    exec claude $@


Thank you!


At 90% discount. Maybe. Plus the exact sites they want to ban now got immense visibility. Plus we don’t need to vet any website, if are in this list is because they really call Claude api. At least at some point did


It's not really a 90% discount (I went into the rabbit hole) and none of the sites from this list are what people use (looks like some labs and random sites). It's more closer to 30% specifically for Claude models, and it's constantly changing.

It's also a discount relative to API prices. It would still be much more expensive than a Claude subscription, because that's what these providers are actually doing - pooling subscriptions.


I mean, yes? I heard of these Chinese resellers like a week ago and put it on the TODO pile due to a lack of leads. Now I'm gonna go trough the list and see if there's any I find acceptable.

If enough Westerners start using the service someone will make a website more anglo-friendly.


I finally bought Claude Pro (I am not coding etc these days so I just wanted to try it). The Claude desktop app is downright pathetic. I mean they could write a better one just with their own LLMs. What's stopping them?


That's … exactly what they're doing. This is the outcome.


so all we need is someone to leak a sufficiently large amount of claude generations onto the open and private web for all other LLMs to mimic the same marking style?

wouldn't this happen due to the massive amounts of spam/slop being released?


Anthropic is very transparent about their code being AI slop

they spend their resources on compute and the model itself, the company is carried by the model and software engineers babysitting it


It’s not surprising at all, they’re vibecoding Claude code so of course they are not going to get anything other than slop out of it. A novel or clever solution is just out of the question for them.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: