Alibaba will ban its employees from using Claude Code in work environments starting July 10, a source told Reuters. The move follows allegations by Anthropic that operators linked to Alibaba’s Qwen lab conducted the largest known disinformation campaign against Claude.
See also: Anthropic accuses Alibaba of the largest distillation campaign against Claude

The ban is reportedly due to an alleged backdoor built into the coding tool, although Alibaba has not publicly confirmed this and did not respond to requests for comment. The news was first reported by Chinese financial outlet Yicai and later confirmed by Reuters. The development comes amid ongoing tensions between Anthropic and Alibaba, with both companies accusing each other of misconduct, including model theft and alleged spying mechanisms in Claude’s tools.
Claude Code is Anthropic's command-line coding agent, which allows developers to write and debug software from a terminal. It has quickly become one of the company's fastest-growing enterprise products, making a company-wide ban of a size like Alibaba particularly significant.
The alleged backdoor was pointed out in a Reddit post by a user named LegitMichel777, who claimed to have reverse engineered Claude Code while restoring a disabled remote control feature. According to a technical analysis shared with the post, the coding assistant had been checking since version 2.1.91 whether a user's proxy configuration or system time zone matched entries in two hidden lists.
See also: Microsoft's quiet retreat from Claude Code

One of these lists reportedly included Chinese corporate networks, cloud domains, and AI labs, including Alibaba, Baidu, ByteDance, and Moonshot AI. If a match was found, the tool reportedly changed the date format and swapped out a punctuation character in the system prompt to encode the detection rather than sending an obvious telemetry signal.
Anthropic has not made an official public statement regarding the category. A member of the Claude Code team, Thariq, reportedly stated on social media that the mechanism was intended to prevent account reselling and model distilling, and that it would be removed in the next version, which was already in development by July 1.
This timeline shows that the mechanism was active for about three months before its planned removal. In a letter dated June 10 to US senators, Anthropic accused operators affiliated with Alibaba’s Qwen AI lab of running nearly 25,000 fake accounts to exploit Claude’s software engineering and logic capabilities, resulting in over 28.8 million trades between April 22 and June 5.
This campaign reportedly surpassed the scale of three previous botnet attempts that Anthropic had flagged in Washington, which were attributed to DeepSeek, Moonshot , and MiniMax. Alibaba has not publicly commented on this allegation either.
See also: Claude Code: Fake installers install malware

The controversy is part of a broader trend of restrictions that tech companies have imposed on coding agents due to concerns about distillation, alongside Anthropic’s own tightening of access for Chinese users through tools like Claude Opus and Fable model restrictions. Whether the alleged backdoor was a targeted spying tool or a general anti-fraud filter affecting ordinary Chinese developers remains up for debate, and no independent security firm has yet conducted a full audit of the claim.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
