GLM-52 897 —
GPT-56SC 873 —
CL-OP5X 865 -0.9%
GROK-46H 865 -0.9%
GEM-37FH 865 -0.9%
GPT-56T 861 —
GLM-5 856 —
MUSE-SPK 841 —
QWEN-38X 824 -2.3%
GPT-6A 820 —
KIMI-K3X 810 -1%
CL-FAB5H 787 -0.9%
CL-OP5H 764 -0.9%
CL-OP46H 742 -0.9%
CL-OP47H 733 -1.1%
GEM-38FH 676 -1%
CL-OP47 585 -0.7%
INKL 531 —
CL-OP46 496 -0.2%
CL-OP48 490 -0.2%
GLM-52 897 —
GPT-56SC 873 —
CL-OP5X 865 -0.9%
GROK-46H 865 -0.9%
GEM-37FH 865 -0.9%
GPT-56T 861 —
GLM-5 856 —
MUSE-SPK 841 —
QWEN-38X 824 -2.3%
GPT-6A 820 —
KIMI-K3X 810 -1%
CL-FAB5H 787 -0.9%
CL-OP5H 764 -0.9%
CL-OP46H 742 -0.9%
CL-OP47H 733 -1.1%
GEM-38FH 676 -1%
CL-OP47 585 -0.7%
INKL 531 —
CL-OP46 496 -0.2%
CL-OP48 490 -0.2%
← Back to feed

Alibaba Bans Claude Code: Hidden China-Detection Mechanism Triggers July 10 Workplace Ban

Alibaba has prohibited its employees from using Claude Code for workplace purposes starting July 10, according to an internal notice seen by the South China Morning Post and corroborated by Reuters via a separate source. The company has listed the tool as “high-risk software with security vulnerabilities” and instructed staff to switch to Qoder, its own AI coding platform.

The ban is the most direct corporate escalation in a two-month conflict between Anthropic and Alibaba’s AI units over model theft and tracking allegations — a conflict that has now triggered formal action on both sides.

What the Mechanism Did

Security researchers published findings on Reddit and GitHub on June 30, describing hidden code in Claude Code that had been present since version 2.1.91, released on April 2. According to the write-up, the coding assistant checked users’ proxy configurations and system timezone settings against two hidden lists when it started.

One list named Chinese corporate networks, cloud regions, and AI labs specifically: Alibaba, Baidu, ByteDance, and Moonshot AI were identified. If a proxy or timezone matched, the tool altered a date format and swapped a punctuation character in its own system prompt. The change did not generate visible telemetry; it embedded the identification state inside the tool’s operating context, where it would be transmitted to Anthropic as part of normal API traffic.

Thariq Shihipar, a member of Anthropic’s technical staff, confirmed the mechanism in a post on X on July 1: “This is an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation. The team has landed stronger mitigations since then and we’ve actually been meaning to take this down for a while. We merged the PR and this should be fully rolled back in tomorrow’s release.”

The mechanism was active for approximately three months before removal. No independent security firm has published a full audit, and whether it constituted a targeted espionage tool or a blunt anti-fraud filter that happened to match Chinese infrastructure remains contested.

Why It Matters for Both Companies

Anthropic already prohibits Chinese companies and foreign entities owned by Chinese companies from using its models. Individual Chinese developers have widely circumvented this through US-based proxy servers, which Claude Code has become one of the fastest-growing enterprise products for in that region.

The ban lands six weeks after Anthropic sent a letter to US senators on June 10 identifying operators connected to Alibaba’s Qwen AI lab as the source of the largest known distillation attack against its models. Anthropic claimed 25,000 fraudulent accounts generated 28.8 million Claude exchanges between April 22 and June 5 — a campaign aimed at extracting Claude’s software engineering and reasoning capabilities into Qwen training runs. Alibaba did not respond publicly to that accusation.

Alibaba’s July 10 ban makes it one of the first major enterprises to formally restrict Claude Code for reasons rooted in the specific tracking allegation rather than competitive concerns or cost. The ban covers all employees at a company with tens of thousands of engineers, many of whom have integrated Claude Code into their development workflows.

The Escalation Timeline

  • April 2: Claude Code v2.1.91 released with hidden detection mechanism active
  • June 5: Alleged Alibaba-linked distillation campaign ends (per Anthropic’s letter)
  • June 10: Anthropic sends letter to US senators naming Alibaba-Qwen in distillation attack
  • June 30: Security researchers publish reverse-engineering findings on Reddit and GitHub
  • July 1: Anthropic’s Thariq confirms mechanism, says fix is being deployed
  • July 3: Alibaba issues internal notice, Yicai reports ban, Reuters corroborates
  • July 10: Ban takes effect

Neither Anthropic nor Alibaba have issued coordinated public statements. The two companies remain in a position where each has made serious public allegations — model theft on one side, covert user tracking on the other — without a formal process for resolution. The commercial relationship between Claude Code and Alibaba’s engineering workforce, which was substantial before the ban, has now effectively ended.