READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Alibaba Bans Claude Code Starting July 10, Citing Hidden Tracking Code Anthropic Embedded in the Tool

Alibaba Bans Claude Code Starting July 10, Citing Hidden Tracking Code Anthropic Embedded in the Tool
Alibaba has classified Anthropic's Claude Code as high-risk software and will prohibit employees from using it beginning July 10, after security researchers uncovered code that quietly checked whether users were on Chinese corporate networks. Anthropic has not issued a formal public statement, though a team member acknowledged the mechanism and said it would be removed. The ban lands inside an already bitter dispute: Anthropic accused Alibaba-linked operators in June of running nearly 25,000 fraudulent accounts to extract Claude's capabilities.

Since Anthropic and Alibaba began publicly trading accusations in June, the conflict between the two AI companies has escalated into a concrete operational break.

Alibaba sent an internal notice to staff, seen by the South China Morning Post, formally adding Claude Code to its list of high-risk software with security vulnerabilities. All employees are prohibited from using the tool for work starting July 10. Staff are required to uninstall Anthropic models and agent products and switch to Alibaba's in-house AI assistant, Qoder, according to an Alibaba insider who confirmed the move to Caixin.

What the researchers found

The mechanism at the center of this dispute was uncovered by a user identified as LegitMichel777, who posted findings on Reddit on June 30. According to a technical write-up shared alongside that post and later summarized by CyberSecurity News and Tech Times, Claude Code had been quietly checking since version 2.1.91 released on April 2 whether a user's proxy configuration or system timezone matched entries on two hidden lists.

One list allegedly named Chinese corporate networks, cloud regions, and AI labs specifically, including Alibaba, Baidu, ByteDance, and Moonshot AI. If a match was found, the tool reportedly altered a date format and swapped a punctuation character in its own system prompt to encode the detection, rather than sending an overt telemetry signal.

The mechanism was reportedly live for roughly three months before it was flagged.

Anthropic's response

Anthropic has issued no formal public statement on the allegation. A member of its Claude Code team identified as Thariq responded on social media that the mechanism was designed to curb account reselling and model distillation, and that it would be stripped out in the next release. The Register and others reported that a fix was already underway by July 1.

Anthropic documented a real, large-scale abuse problem: in a letter dated June 10 to U.S. senators, the company accused operators connected to Alibaba's Qwen AI lab of running nearly 25,000 fraudulent accounts to extract Claude's software engineering and reasoning capabilities. If that allegation is accurate, Anthropic had a genuine interest in detecting and countering distillation attempts.

But the method it chose to do so, covertly targeting users by corporate affiliation and geographic timezone rather than by observable behavior, is exactly the kind of hidden tracking that enterprises running security reviews cannot tolerate. Whether the intent was legitimate or not, the implementation was covert and undisclosed. Those are two separate questions, and conflating them does neither side any favors.

The Alibaba side of the ledger

Alibaba is not a neutral party either. Anthropic's accusation of nearly 25,000 fraudulent accounts tied to Qwen-affiliated operators, if substantiated, would represent a serious breach of terms of service and potentially an act of deliberate IP theft. That accusation remains an allegation at this point; no charges have been filed and no formal investigation has been announced. But it is the backdrop against which Alibaba is now positioning itself as the aggrieved party over a spyware discovery.

The ban itself may be as much about optics and competitive positioning as it is about genuine security risk. Directing employees toward Qoder, Alibaba's own AI coding assistant, is not a neutral outcome.

Why it matters beyond this dispute

Claude Code is one of Anthropic's fastest-growing enterprise products, according to The Next Web. A company-wide ban at Alibaba, one of the world's largest technology employers, is a concrete commercial setback regardless of the underlying merits.

More broadly, the episode illustrates a structural problem in the U.S.-China AI competition. American AI tools used inside Chinese firms, and Chinese-affiliated accounts used to train on American models, create overlapping security exposures that neither side has cleanly resolved. Covert detection mechanisms are one response to that problem. They are also a reputational liability the moment they are discovered.

The unresolved question as of July 3: Anthropic has said the mechanism will be removed, but has not confirmed whether it has been removed yet, when exactly that update ships, or whether any version of user-geography detection will remain in future releases. Enterprise customers outside China evaluating Claude Code have the same question Alibaba had, and a social media post from a team member is not a disclosure policy.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ReutersAlibaba to ban employees from using Anthropic's coding tool, source says - Reuters
unknown
caixinglobalAlibaba Bans Staff From Using Anthropic AI Tools Over Security Concerns - Caixin Global
unknown
thenextwebAlibaba to ban Claude Code over alleged backdoor risk, source says - TNW
unknown
scmpAlibaba bans staff from using Claude Code over Anthropic spyware concerns