Alibaba has told staff to stop using Claude Code by July 10, after hidden detection code in Anthropic's coding tool turned a private anti-abuse fight into a public trust problem.
If you're an engineer at Alibaba, you have until July 10 to find a new coding assistant. According to Yicai, the company has added Anthropic's Claude Code to its internal restricted software list after classifying it as high risk, and staff have been pointed toward Qoder, Alibaba's own coding platform, instead.
The ban didn't come from a vague security memo. It followed a June 30 Reddit post by a user going by LegitMichel777, who published a reverse-engineered breakdown of Claude Code and claimed the tool had been checking whether users appeared tied to China. Cybernews and Techzine reported that the code compared proxy settings and system time zones with hidden lists containing Chinese company domains and AI lab keywords, including names linked to Alibaba, Baidu, Ant Group, ByteDance and Moonshot AI.
That's an odd place for Anthropic to put a trust test, and you don't need to be sympathetic to Alibaba to see the problem. Developers expect coding assistants to read their repositories, shell commands and prompts. They don't expect the tool itself to hide a geographic fingerprinting routine inside what looks like ordinary runtime logic.
An Anthropic engineer acknowledged online that the code was real and said it would be removed in the next release. The company hasn't given a full public explanation of the mechanism, but the broad argument is clear enough: Anthropic wants to stop banned Chinese users and companies from reaching Claude through VPNs, resellers, cloud routes and overseas entities.
The Financial Times reported on July 3 that Anthropic is now moving more aggressively to close those loopholes, including by checking time zones and suspicious traffic patterns. The same report said Chinese companies including Ant Financial had found workarounds, while ByteDance engineers had been reimbursed for personal subscriptions accessed through VPNs. Those workarounds may not break U.S. or Chinese law, but they breach Anthropic's terms, which bar Chinese companies and foreign entities they own from using its models.
That context matters because this wasn't a random anti-China script sitting in a developer tool. In a June 10 letter obtained by Business Insider and The Wall Street Journal, Anthropic's head of policy, Sarah Heck, accused Alibaba-affiliated operators of making 28.8 million exchanges with Claude through almost 25,000 fraudulent accounts between April 22 and June 5. Anthropic called it the largest known distillation attack against the company and said the activity targeted capabilities such as software engineering, agentic reasoning and long-horizon tasks.
Alibaba has not publicly accepted that charge. It doesn't need to, at least internally. Once hidden detection code surfaced in Claude Code, the company had a cleaner message for staff: stop using the American tool, use Qoder, and treat Claude Code as a back-door risk. The South China Morning Post reported that Alibaba's security team used exactly that kind of language, which is strong wording for software from a rival rather than malware from an unknown vendor.
Here's the thing: both sides have a case, and both have made their own case weaker. Anthropic is right to defend its models if it believes a rival is using fake accounts to copy expensive capabilities at industrial scale. If the numbers in its Senate letter are accurate, 28.8 million Claude interactions isn't casual testing. It's a production operation.
But hiding detection logic inside a developer tool was a bad way to fight it. Claude Code is aimed at exactly the kind of users who inspect dependencies, read source, diff releases and notice strange behavior. A Reddit post was always a likely ending. Once that happened, Anthropic lost control of the story, and Alibaba gained a simple one.
The timing also suits Alibaba. Qwen is competing directly with Claude for developer attention, and Qoder now gets an internal mandate at the moment Claude Code looks politically and technically risky inside a Chinese company. That's convenient. It doesn't make Anthropic's distillation allegation false, but it does mean Alibaba can turn a compliance fight into a product migration.
For developers outside Alibaba, the sharper lesson is not that Claude Code is unusable. It's that AI coding tools now sit in the most sensitive part of the software stack, where a trust decision is also a supply-chain decision. If a vendor adds hidden checks for policy enforcement, even for understandable reasons, the code had better survive public inspection.
Anthropic can remove the routine in a release. Alibaba can enforce the ban on July 10. What neither company can easily undo is the new suspicion around tools that already ask engineers for unusually deep access to their work machines.
Also read: Israel Turns Its Pact With Argentina Into an AI Foothold in Latin America • Quantum Systems Raises $1.2 Billion as Airbus Bets on a Future Rival • China's AI-Driven Quant Funds Have Now Topped $474 Billion in Assets