Alibaba has banned staff from using Anthropic’s Claude Code for work as of 10 July, after security researchers claimed the AI coding agent contained hidden code to detect users in China or was linked to Chinese AI labs.
According to the South China Morning Post, Alibaba said Claude Code had been “added to a list of high-risk software with security vulnerabilities” after a full evaluation. It cited what it called “back-door risks”.
Staff have reportedly been told to use Qoder, Alibaba’s own AI coding platform, instead.
Chinese outlets citing company insiders said the order extended beyond Claude Code. Staff were allegedly told to uninstall all Anthropic products, including the Sonnet, Opus and Fable model families.
The row is the latest twist in a spat that blew up last month, when Anthropic accused operators linked to Alibaba’s Qwen AI lab of running the largest known model distillation attack against Claude.
The ban was triggered by a 30 June post on the r/ClaudeAI subreddit from a user who claimed to have reverse-engineered Claude Code while restoring a disabled remote-control feature.
According to the write-up, obfuscated detection logic had shipped quietly since version 2.1.91, released on 2 April, without appearing in the release notes. When a proxy was detected, the code reportedly checked whether the system timezone matched Asia/Shanghai or Asia/Urumqi.
It then inspected the proxy URL against a hardcoded list of Chinese domains and AI lab identifiers, reportedly including Alibaba, Baidu, Ant Group and ByteDance.
What turned bog-standard telemetry into a proper stink was the alleged exfiltration method. Rather than sending an obvious signal, the tool allegedly encoded its findings steganographically. It tweaked the date format and swapped a punctuation character in the system prompt sent to Anthropic’s servers.
That made the signal invisible to users but readable by machines at Anthropic’s end. The Reddit author called the covert transmission of system and proxy data “a fundamental violation of user trust”. They said they wanted transparency from Anthropic.
Anthropic Claude Code team engineer Thariq Shihipar addressed the claims on X, calling the mechanism “an experiment we launched in March”, he said. It was intended to stop account abuse by unauthorised resellers and protect against distillation.
Shihipar said the team had meant to remove the code for some time. The pull request stripping it out was merged on 1 July, the day after the Reddit post.
The timing of Alibaba’s Claude ban fits neatly into the wider split between the Chinese tech giant and the US artificial intelligence frontrunner. On 10 June, Anthropic sent a letter to US Senate Banking Committee leaders accusing operators affiliated with Alibaba’s Qwen lab of using nearly 25,000 fake accounts.
Anthropic claimed those accounts generated 28.8 million exchanges with Claude between 22 April and 5 June. It described the campaign as an industrial-scale attempt to distil Claude’s software-engineering and reasoning capabilities.
Alibaba denied wrongdoing and has not gone into the allegations in detail.







