Alibaba has ordered its employees to stop using Anthropic's Claude Code coding assistant by July 10, 2026, after a developer's reverse-engineering teardown exposed hidden code inside the tool that quietly checked whether users were connected to China. The e-commerce and cloud giant added Claude Code to its internal list of "high-risk software," a category normally reserved for programs with known security vulnerabilities, and directed staff to switch to Qoder, its own in-house coding platform.
The decision, first reported by Reuters and confirmed by the South China Morning Post, Caixin Global, and The Information, marks an unusually sharp escalation between two companies already locked in an acrimonious dispute over AI model theft. It also lands at the center of the broader contest over who controls frontier AI. For more context on this story, see our ongoing more AI stories.
What the Hidden Code Did
The ban traces back to a June 30 Reddit post by a user going by "LegitMichel777," who published a detailed breakdown of Claude Code's source code. According to reporting from Cybernews and Techzine, the teardown found that since version 2.1.91 — released on April 2 — Claude Code had been silently checking a user's proxy settings and system time zone against two hidden lists.
One list contained 147 domains tied to Chinese companies and AI labs, including Baidu, Alibaba, Ant Group, and ByteDance, alongside 11 keywords linked to labs such as Moonshot AI. The result of that check was folded into an ordinary-looking string in the code, "Today's date is…," where a hyphen swapped for a slash was used to flag a Chinese time zone. An Anthropic engineer confirmed the code was genuine and said on social media that it would be pulled in the following day's release.
Anti-Fraud or Surveillance?
Anthropic has not issued a full written explanation of why the check existed, but its internal framing has been anti-fraud rather than surveillance. That framing is rooted in an earlier accusation: in a June 10 letter to U.S. senators, Anthropic alleged that operators tied to Alibaba's Qwen lab had run roughly 25,000 fraudulent accounts that generated more than 28.8 million interactions with Claude between April 22 and June 5, in what Anthropic described as an effort to distill Claude's outputs and accelerate training of a rival model.
Seen against that letter, the hidden check looks less like espionage and more like Anthropic attempting to identify the specific customers it had already accused of gaming its system. There is an awkward irony here: Claude Code was never officially sold in mainland China, and Anthropic blocks direct sign-ups from Chinese IP addresses. That meant most Chinese developers using the tool were already routing around the restriction through VPNs or third-party resellers — precisely the kind of access Anthropic says its hidden list was built to catch.
Alibaba's Response and the Wider Fallout
Alibaba is not buying the anti-fraud explanation. According to Caixin Global's reporting on an internal notice, the company told staff plainly to stop using Claude Code for work and pointed them to Qoder, the coding assistant it has spent the year building out. The South China Morning Post reported that Alibaba's security team classified Claude Code as carrying "back-door risks," language usually reserved for compromised software rather than a competitor's commercial product.
The timing is uncomfortable for both sides. Alibaba's Qwen models compete directly with Claude for developer attention, and the fraudulent traffic Anthropic flagged in its Senate letter was, by Anthropic's own account, an attempt to shortcut that competition through distillation. Now Alibaba can cast itself as the victim of an American company's surveillance code — a far easier story to tell employees than admitting its affiliated developers were caught scraping a rival's model.
Why It Matters for the Industry
Neither company emerges from the episode looking careful. Anthropic says the tracking mechanism is already gone, or going, in its next release, but a patch note does not undo a Reddit post read by tens of thousands of developers. Meanwhile, Baidu and ByteDance — both named in the same hidden list — are watching how the situation settles before deciding whether they need bans of their own.
The episode also underscores how tangled the US-China AI relationship has become. American labs are under mounting pressure to prevent their models from being distilled by Chinese competitors, yet their most aggressive anti-abuse measures can look, to outside developers, like covert surveillance. For Chinese firms, blocking a foreign coding tool is now as much a competitive move as a security one, since it funnels engineers onto domestic alternatives like Qwen.
The reputational damage may ultimately prove more consequential than the technical one. Developers choose coding assistants based on trust, and a tool that secretly inspects a user's proxy settings and time zone — even for defensible anti-abuse reasons — tests that trust in ways a simple rate limit never would. Anthropic's quick removal of the code suggests it understood the risk, but the episode is likely to linger as a cautionary tale about the line between protecting a model and surveilling the people who use it.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →



