Alibaba to Ban Employees from Using Claude Code After Hidden China-Detection Code Is Discovered

Alibaba has reportedly classified Anthropic's Claude Code as 'high-risk software' and will ban internal use from July 10. The trigger: hidden code inside Claude Code that detected Chinese users. Combined with Anthropic's distillation accusations, the US-China AI rivalry is now reaching developer tools.

Alibaba to Ban Employees from Using Claude Code After Hidden China-Detection Code Is Discovered

China’s Alibaba will reportedly ban its employees from using Anthropic’s AI coding tool Claude Code starting July 10, 2026. The South China Morning Post (SCMP) first reported the move based on an internal notice, and TechCrunch has since corroborated it13. According to the internal notice, Claude Code “has now been added to a list of high-risk software with security vulnerabilities”3, and Alibaba is directing employees to use Qoder, its own coding agent, as a replacement1.

The immediate trigger for the ban was the discovery of obfuscated code inside Claude Code that identified Chinese users. Behind that lies an earlier episode in which Anthropic accused Alibaba-affiliated operators of a large-scale “distillation attack” in a letter to US lawmakers4. Together, the sequence shows the US-China AI rivalry reaching down into the tools developers use every day. Note that Alibaba has not made an official announcement, and the ban is so far known only through media reports1.

The Trigger: Hidden Code That Detected Chinese Users

On June 30, 2026, Reddit user LegitMichel777 published findings from reverse-engineering Claude Code, showing that code to identify Chinese users had been embedded in the tool2. According to the report, the code had been present since version 2.1.91, released on April 2, 20262.

The technical details were also laid out. The code was obfuscated with XOR (key 91), making it invisible to simple text extraction2. The detection logic reportedly compared the system timezone against “Asia/Shanghai” or “Asia/Urumqi” and scanned the proxy URL for Chinese domains2. As for how the results were transmitted, the report describes a steganographic technique: subtly swapping date formats and apostrophe characters to hide the signal2.

For context, Anthropic does not permit companies in unsupported regions such as China to use Claude, and in September 2025 it officially announced that the restriction would extend to “entities that are more than 50% owned, directly or indirectly, by companies headquartered in unsupported regions”5. The discovered mechanism appears to have been designed to identify users circumventing those restrictions1.

Anthropic’s Explanation: An “Anti-Distillation Experiment”

After the findings were published, Anthropic’s Thariq Shihipar said on X that the mechanism was “an experiment we launched in March that was meant to prevent account abuse from unauthorised resellers and protect against distillation”12. He added that the team had since landed stronger mitigations and had “been meaning to take this down for a while”2. The pull request removing the code was merged, with a full rollback expected in the following release2.

Distillation, the practice Anthropic cited, is a technique for training one AI model on the outputs of a more advanced model4. We cover how it works in our explainer on model compression (distillation and quantization). While distillation is a legitimate technique for shrinking models, it can also be used to copy a rival model’s capabilities without authorization, which is why most frontier AI companies prohibit using their outputs to train competing models.

The Backdrop: Anthropic’s “Largest Distillation Attack” Accusation

The exchange traces back to accusations Anthropic made in late June. In a letter to senior members of the US Senate Banking Committee, Anthropic alleged that operators affiliated with Alibaba’s Qwen AI lab used roughly 25,000 fraudulent accounts to distill Claude through more than 28.8 million exchanges between April 22 and June 5, 20264. Alibaba did not respond to InfoWorld’s request for comment4, and it is worth noting that the allegation is one-sided, coming solely from Anthropic.

The full sequence, then, is a tit-for-tat: (1) Anthropic accused Alibaba of a distillation attack, (2) the China-detection code Anthropic had deployed as a countermeasure was discovered, and (3) Alibaba is banning Claude Code internally as “high-risk software.”

The US-China AI Rivalry Reaches Developer Tools

For developers who use Claude Code and companies evaluating it, this episode raises two issues.

The first is vendor transparency. The detection code was not mentioned in any release notes and shipped in obfuscated form2. Even if the purpose was preventing account abuse, the after-the-fact discovery of an undisclosed detection and transmission mechanism affects how companies assess the risk of embedding developer tools in their workflows. Alibaba’s internal notice indeed cites the classification as “high-risk software with security vulnerabilities” as the reason3.

The second is that access to AI tools is itself subject to competition and geopolitics. Anthropic has restricted a competitor’s access to its tools before: in June 2025 it cut off Windsurf’s Claude API access during OpenAI acquisition talks. This time the pattern went beyond corporate rivalry, playing out in a US-China context through terms-of-service exclusions, technical detection, and an internal ban. The episode illustrates that the more an organization depends on a particular AI tool, the more exposed it is to supply-side policy changes and regulation.

For the full timeline, see SCMP’s initial report and TechCrunch’s coverage; for the technical analysis, The Decoder’s article is a good starting point.

Sources

  1. Alibaba reportedly bans employees from using Claude Code - TechCrunch
  2. Hidden code in Claude Code secretly flagged Chinese users - The Decoder (includes technical analysis of the Reddit findings)
  3. Alibaba bans staff from using Claude Code over Anthropic spyware concerns - South China Morning Post (first report)
  4. Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI - InfoWorld
  5. Updating restrictions of sales to unsupported regions - Anthropic official announcement (September 4, 2025)

We publish the latest AI news every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →