Jul 22, 2026 · 9:12 AM
Subscribe
Home Ai

Alibaba Bans Claude Code After Hidden Anthropic Tracking Code Surfaces

Alibaba has ordered employees to stop using Anthropic's Claude Code by July 10, after a Reddit user's reverse engineering revealed the tool quietly checked whether users were tied to Chinese firms. Anthropic says the code was an anti-fraud measure connected to a separate dispute over Alibaba's Qwen lab allegedly using fraudulent accounts to distill Claude's outputs, and says it is already being removed.

Judith Murphy
· 5 min read · 2.3K reads
Alibaba Bans Claude Code After Hidden Anthropic Tracking Code Surfaces

Alibaba has told staff to stop using Claude Code by July 10, after hidden detection code in Anthropic's coding tool turned a private anti-abuse fight into a public trust problem.

If you're an engineer at Alibaba, you have until July 10 to find a new coding assistant. According to Yicai, the company has added Anthropic's Claude Code to its internal restricted software list after classifying it as high risk, and staff have been pointed toward Qoder, Alibaba's own coding platform, instead.

The ban didn't come from a vague security memo. It followed a June 30 Reddit post by a user going by LegitMichel777, who published a reverse-engineered breakdown of Claude Code and claimed the tool had been checking whether users appeared tied to China. Cybernews and Techzine reported that the code compared proxy settings and system time zones with hidden lists containing Chinese company domains and AI lab keywords, including names linked to Alibaba, Baidu, Ant Group, ByteDance and Moonshot AI.

That's an odd place for Anthropic to put a trust test, and you don't need to be sympathetic to Alibaba to see the problem. Developers expect coding assistants to read their repositories, shell commands and prompts. They don't expect the tool itself to hide a geographic fingerprinting routine inside what looks like ordinary runtime logic.

An Anthropic engineer acknowledged online that the code was real and said it would be removed in the next release. The company hasn't given a full public explanation of the mechanism, but the broad argument is clear enough: Anthropic wants to stop banned Chinese users and companies from reaching Claude through VPNs, resellers, cloud routes and overseas entities.

The Financial Times reported on July 3 that Anthropic is now moving more aggressively to close those loopholes, including by checking time zones and suspicious traffic patterns. The same report said Chinese companies including Ant Financial had found workarounds, while ByteDance engineers had been reimbursed for personal subscriptions accessed through VPNs. Those workarounds may not break U.S. or Chinese law, but they breach Anthropic's terms, which bar Chinese companies and foreign entities they own from using its models.

That context matters because this wasn't a random anti-China script sitting in a developer tool. In a June 10 letter obtained by Business Insider and The Wall Street Journal, Anthropic's head of policy, Sarah Heck, accused Alibaba-affiliated operators of making 28.8 million exchanges with Claude through almost 25,000 fraudulent accounts between April 22 and June 5. Anthropic called it the largest known distillation attack against the company and said the activity targeted capabilities such as software engineering, agentic reasoning and long-horizon tasks.

Alibaba has not publicly accepted that charge. It doesn't need to, at least internally. Once hidden detection code surfaced in Claude Code, the company had a cleaner message for staff: stop using the American tool, use Qoder, and treat Claude Code as a back-door risk. The South China Morning Post reported that Alibaba's security team used exactly that kind of language, which is strong wording for software from a rival rather than malware from an unknown vendor.

Here's the thing: both sides have a case, and both have made their own case weaker. Anthropic is right to defend its models if it believes a rival is using fake accounts to copy expensive capabilities at industrial scale. If the numbers in its Senate letter are accurate, 28.8 million Claude interactions isn't casual testing. It's a production operation.

But hiding detection logic inside a developer tool was a bad way to fight it. Claude Code is aimed at exactly the kind of users who inspect dependencies, read source, diff releases and notice strange behavior. A Reddit post was always a likely ending. Once that happened, Anthropic lost control of the story, and Alibaba gained a simple one.

The timing also suits Alibaba. Qwen is competing directly with Claude for developer attention, and Qoder now gets an internal mandate at the moment Claude Code looks politically and technically risky inside a Chinese company. That's convenient. It doesn't make Anthropic's distillation allegation false, but it does mean Alibaba can turn a compliance fight into a product migration.

For developers outside Alibaba, the sharper lesson is not that Claude Code is unusable. It's that AI coding tools now sit in the most sensitive part of the software stack, where a trust decision is also a supply-chain decision. If a vendor adds hidden checks for policy enforcement, even for understandable reasons, the code had better survive public inspection.

Anthropic can remove the routine in a release. Alibaba can enforce the ban on July 10. What neither company can easily undo is the new suspicion around tools that already ask engineers for unusually deep access to their work machines.

Also read: Israel Turns Its Pact With Argentina Into an AI Foothold in Latin AmericaQuantum Systems Raises $1.2 Billion as Airbus Bets on a Future RivalChina's AI-Driven Quant Funds Have Now Topped $474 Billion in Assets

TOPICS
Judith Murphy is a financial journalist and market analyst covering AI, technology stocks, and emerging market trends. She has contributed to multiple financial publications and brings a data-driven approach to her coverage of the technology sector and its impact on global markets.
Related Articles
More posts →
Loading next article…
You're all caught up