Quick Facts
- Alibaba will ban Claude Code starting July 10, requiring employees to uninstall all Anthropic model products, including Sonnet, Opus, and Fable.
- A researcher discovered obfuscated code in Claude Code that used steganography to flag users with Chinese system timezones and proxy addresses back to Anthropic’s servers.
- Anthropic separately alleged that operators linked to Alibaba generated 28.8 million exchanges with Claude through nearly 25,000 fraudulent accounts between April 22 and June 5, 2026.
Alibaba is banning employees from using Claude Code, Anthropic’s AI-powered coding tool, effective July 10. The company issued an internal notice calling the software high-risk and directing workers to uninstall all Anthropic model products from their work computers.
The ban follows a disclosure by a Reddit user identified as LegitMichel777, who posted findings on June 30 after reverse-engineering Claude Code version 2.1.196. The user found obfuscated code that had been present since version 2.1.91, released April 2, 2026, with no mention in any release notes.
The hidden code checked whether a user’s system timezone was set to Asia/Shanghai or Asia/Urumqi and scanned proxy URLs against a hardcoded list of Chinese domains and AI lab addresses. The findings were then concealed using steganography inside system prompts sent to Anthropic’s servers. Changes included swapping date formats and replacing standard apostrophes with visually identical Unicode characters, invisible to human users but readable by machines.
The decoded keyword list included competitor names such as deepseek, moonshot, minimax, zhipu, bigmodel, baichuan, stepfun, 01ai, dashscope, and volces. The tracking code was also XOR-obfuscated to resist plain-text extraction.
Anthropic engineer Thariq Shihipar confirmed the feature on X, describing it as “an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation.” Shihipar said the team had since deployed stronger protections and had been planning to remove the tracking code. Anthropic merged the removal pull request on July 1, three days before Alibaba’s ban notice surfaced publicly.
The tracking disclosure landed against a backdrop of broader accusations. In a June 10 letter to the U.S. Senate Banking Committee, Anthropic alleged that operators linked to Alibaba and its Qwen AI lab generated more than 28.8 million exchanges with Claude through nearly 25,000 fraudulent accounts over a 44-day window. Anthropic Head of Policy Sarah Heck told senators the activity was carried out “illicitly, systematically, and at industrial scale to harvest U.S. AI capabilities across frontier labs and repackage them as their own.”
On June 12, the U.S. Commerce Department imposed export controls on Anthropic’s Mythos and Fable frontier models, citing national security concerns. Anthropic then disabled global access to both models.
Alibaba had previously subsidized employee use of external AI tools including Claude, GPT, and Gemini, with some programmers spending hundreds of dollars in credits weekly. Claude Code ranked among the most-used coding tools internally, alongside OpenAI Codex and Alibaba’s own Qoder. The company is now directing employees to use Qoder exclusively.
Lizzi Lee, a fellow at the Asia Society Policy Institute’s Centre for China Analysis, said the conflict shows the U.S.-China AI competition has moved beyond technology into access control. “If a US AI coding tool can detect Chinese usage or proxy access, then it’s not surprising for major Chinese tech companies to not want employees using it internally,” she said.
Chinese cybersecurity firm Huorong Security called Anthropic’s tracking a transparency issue with cross-border data compliance implications. Alibaba stock dropped nearly 3% on the day the distillation accusations became public.
The episode adds to a growing list of corporate AI tool restrictions. Uber exhausted its entire 2026 AI coding budget within four months. Microsoft has cut Claude Code licenses for some product teams. Banks, law firms, and Apple have each restricted access to specific AI tools over data security concerns.
Read more: Alibaba reportedly bans employees from using Claude Code
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
