skip to content
ai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILURE
BAD/GATEWAY*

UNO REVERSE CARD: ALIBABA BANS CLAUDE CODE

The internal ban takes effect July 10 after developers found code designed to fingerprint Chinese users, hidden via steganography.

by editor5 min readcomments soon

alibaba bans claude code over hidden Chinese user tracking

Alibaba has told its employees to stop using Anthropic's Claude Code, classifying the AI coding tool as high-risk software that threatens organisational security. The ban takes effect July 10, 2026, and the company is directing workers to its own Qoder AI assistant instead.

The move came after developers reverse-engineered Claude Code and found code built to identify Chinese users, concealed using obfuscation and steganographic techniques that made it invisible during normal use. The code checked for Chinese system time zones, proxy servers, AI lab infrastructure, and network characteristics. Researchers who published their findings described a purpose-built fingerprinting system disguised well enough that users would never know it was running.

WHAT THE CODE ACTUALLY DID

The detection logic was not a passive check. It actively scanned for indicators that a machine was operated from mainland China: locale settings that default to Beijing time, the presence of known Chinese proxy or VPN exit nodes, the network signature of Chinese AI labs, and more. Anyone running Claude Code from an environment that matched those signals would be silently identified.

Anthropic acknowledged the feature existed, calling it an experimental system launched in March that was designed to combunauthorisedzed resellers, prevent account abuse, and protect its models from AI distillation. The company says that distillation, where a competitor extracts the behaviour of a model by querying it at scale and training a copy, was the specific threat they were targeting. The feature was supposed to stay invisible.

It did not stay invisible for long. Developers found it, reverse-engineered it, and published their findings, triggering the internal review at Alibaba that led to the ban.

THE DISTILLATION ACCUSATION IS MISSING CONTEXT

Anthropic has accused Alibaba of conducting the largest known model distillation attack against Claude. That accusation provides the context for the detection feature. If Anthropic believed it was under a sustained extraction campaign originating from Chinese infrastructure, building a detection tool that identifies Chinese users makes tactical sense. It also explains why the feature was hidden: a visible block would be trivial to route around.

Alibaba has not publicly commented on the ban, and neither company has addressed the distillation claim beyond Anthropic's earlier statement. But the timeline is worth tracking. The detection feature launched in March. The reverse-engineering findings appeared shortly after. The ban arrives in July. That cadence suggests Alibaba's security and legal teams moved fast once the evidence was laid out in public.

TWO-WAY TRADE WAR

American tech giants have banned Chinese tools from internal use. Chinese giants are now returning the favour. Alibaba's ban on Claude Code fits a broader pattern where both sides are locking down their internal networks against the other country's AI software. Chinese companies have been increasingly switching to domestic tools like Qwen, DeepSeek, Moonshot, and Ship, and Alibaba's recommendation of Qoder is consistent with that pivot.

There is an irony here that neither side is likely to acknowledge. US firms have been exploring cheaper Chinese AI alternatives in the name of cost efficiency, just as Chinese firms had begun relying on US tools for advanced coding assistance. The market was globalising fast until trust became a liability. Now the global stack is fragmenting, and developer tooling is a new front in that fragmentation.

WHAT THE STEGANOGRAPHY MEANS

The fact that Anthropic used steganography to hide the detection code is the part that is hardest to wave away. Steganography is not a mechanism for transparency. It is a mechanism for concealment. Security researchers sometimes use it for proofs of concept or penetration testing, but shipping it inside a developer tool that runs on customer machines is a step that changes the trust equation.

Even if Anthropic's motives were defensive, the method betrays a willingness to hide behaviour from the user. That is a line that once crossed is hard to uncross. Alibaba's classification of Claude Code as high-risk is not an unreasonable read of that pattern. If a tool can check your time zone and network setup without telling you it is doing so, it can check other things too.

WHAT HAPPENS NEXT

Alibaba's internal ban is one company's policy, but other Chinese enterprises are watching. If Qoder performs well under the new load, the Qwen ecosystem gains credibility. If it does not, the pressure on Chinese AI tooling to match Claude Code's quality intensifies.

The deeper question is whether the trust damage is repairable. Anthropic could remove the detection feature, publish a postmortem, and open the relevant code to external audit, but the steganography is the kind of detail that sticks in memory. Developers who use Claude Code will now wonder what else might be running invisibly in their terminal. That suspicion does not disappear with a patch.

For Alibaba, the calculation was straightforward. The cost of letting employees keep using the tool outweighed the productivity benefit once the detection code was discovered. The ban is a signal to employees, to regulators, and to Anthropic: we treat this as an espionage vector, and we will act accordingly. Whether other Chinese companies follow Alibaba's lead will depend on whether they reach the same conclusion about the risk.


what did you make of it?

share

more from business