Claude Code and China: The mechanism is activated when the user sets the ANTHROPIC_BASE_URL environment variable (used for local models)
Mirrored from r/LocalLLaMA for archival readability. Support the source by reading on the original site.
| The list of suspicious hostnames is not stored in plaintext within the code; instead, it is Base64-encoded and then encrypted using a simple XOR operation with a key of 91. Once decoded, it reveals domains belonging to Chinese companies, keywords related to artificial intelligence laboratories, and various gateways or resellers used to route requests to the Claude API. The researcher who published the analysis has also made the complete, decoded list available online here: https://thereallo.dev/blog/claude-code-prompt-steganography [link] [comments] |
Discussion (0)
Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.
Sign in →No comments yet. Sign in and be the first to say something.