17 Sources
[1]
Anthropic outed for Claude tracker that secretly monitored Chinese users
Anthropic quickly removed a tracker secretly monitoring Claude Code users in China after a security researcher exposed the hidden code and condemned the spyware-like tracking as a "serious breach of user trust." Last week, a web developer known as "Thereallo" was researching privacy issues in Claude Code and was shocked to find that the AI firm was using "prompt steganography" to hide code tracking Chinese users "in plain sight." This code wasn't malicious, but it was sending information to Anthropic that most users wouldn't detect, relying on shorthand markers to quietly flag users' timezone, proxy, and potential connection to Chinese AI labs that Anthropic has accused of distillation attacks. On X, Anthropic engineer Thariq Shihipar confirmed that the tracker was added to Claude Code as an "experiment" in March. According to Shihipar, the code "was meant to prevent account abuse from unauthorized resellers and protect against distillation." Regarding the former, The Washington Post found unauthorized retailers have sold access to free models for $1 a month, and pro subscriptions that can cost $100 monthly sell for "as little as $12." Supposedly, Anthropic has "actually been meaning to take this down for a while," Shihipar said of the hidden code, because engineers have "landed stronger mitigations since then." Privacy advocates were not happy with the explanation, though, warning that the code is evidence that Anthropic is willing to cross lines to surveil users. That's perhaps especially surprising, considering that Anthropic riled the Trump administration by refusing to allow the US government to use Claude to surveil US users. The AI firm has since sued the White House over the clash. Anthropic wants distillation deemed illegal The Post suggested that the tracker incident is a sign that US firms like Anthropic are taking "increasingly aggressive measures" to block Chinese AI firms from copying their models. A more defensive stance has apparently become critical. In the past year, Chinese firms have "consistently matched" US firms' model capabilities "within months," the Post reported. Most recently, "a new, free AI model from Chinese company Zhipu AI was better at finding computer vulnerabilities than Anthropic's Claude Opus 4.8 model, which was released in May," the Post reported. To lock in a 12- or possibly even 24-month lead for the US, Anthropic has said the US must ramp up interventions, using a range of possible penalties to combat distillation attacks, including blocking access to advanced models, chips, and data centers in the US. Although distillation isn't illegal (leading US firms do it, too), prompting models like Claude millions of times in order to quickly advance Chinese models violates Anthropic's user terms. To end the endless copying, Anthropic has joined OpenAI in urging the US to view distillation attacks as a form of intellectual property theft. At a recent Senate hearing, Sen. Tim Scott (R-SC) agreed legal intervention is needed, arguing that the US needs "to carefully craft export control policy that is clear and concise" to stop China from using such attacks to "gain a technological edge," the Post reported. Secret code triggers Alibaba Claude ban It's clear that Chinese firms are distilling US models, the Post reported. In February, Chinese researchers at Peking University and the state-funded Chinese Academy of Sciences "developed methods to detect signs of distillation in leading large language models" and found that most Chinese models "showed substantial evidence of distillation," primarily of US models. One of Alibaba's Qwen AI models -- which Anthropic has since claimed was advanced after the largest distillation attack ever on Claude in June -- "repeatedly appeared to mimic" Claude in February. In some intensive tests, the model would even sometimes slip up and identify itself as Claude, researchers found. Alibaba has not commented on Anthropic's accusations, but the company has moved to distance itself from Anthropic's models amid ongoing scrutiny. Last Friday, Alibaba banned its employees from using Claude Code for work, the South China Morning Post reported. According to a memo SCMP reviewed, Alibaba told employees the ban came in direct response to concerning news about Anthropic's tracker monitoring Chinese users. "As Claude Code was recently discovered to carry back-door risks, after comprehensive evaluation, Claude Code has now been added to a list of high-risk software with security vulnerabilities," the memo said. For Alibaba, ignoring Anthropic's determination to detect users connected to leading Chinese AI labs is risky. Unlike individual users who can easily pay for cheap circumvention tech to evade Anthropic's location blockers without fears of major repercussions, Alibaba could be exposed to legal and compliance risks if caught violating Anthropic's terms, a source granted anonymity to discuss Alibaba's Claude ban told Reuters. For Anthropic, allowing the attacks to continue could hurt the company's business. Some open source Chinese models are more popular than free and open American counterparts, the Post reported, and Fortune 500 CEOs have made it clear that they're searching for cheaper AI solutions. For the US, not only would moving to block Chinese distillation of American models be challenging, but it could also be unpopular -- blocking Americans from benefiting from cheaper AI alternatives from China, the Post suggested. Anthropic tracking crossed "scary boundary" In this climate, where a chatbot user's loyalty depends on a cost-benefit analysis weighing the cost of accessing models against their capabilities, Anthropic likely can't afford to lose user trust as it fights to keep frontier models ahead of China's. As the web developer who flagged the hidden tracker noted, it's "weird" that Anthropic chose to move in secret when the company could've instead chosen to transparently alert users to the infringing user tracking. "This is not a malicious feature, but it is a weird choice for a developer tool that asks for trust," Thereallo's blog said. The blog noted that "if the client wants to detect custom API gateways, it can say so plainly. It can send an explicit telemetry field with documentation. It can make the policy visible. It can put the behavior in release notes." The researcher emphasized that "coding agents already live on the wrong side of a scary boundary. They can inspect code, summarize secrets by accident, run commands, install packages, edit files, and push commits on your local machine." Although most users were likely not impacted by the tracking, Thereallo warned that the "correct reaction" is more scrutiny of Claude's potential for user surveillance, since "the feature mostly punishes the exact people who are easier to fingerprint: normal developers doing weird but legitimate things." "Hiding the signal in the system prompt makes every other privacy claim harder to believe," Thereallo said. Anthropic did not immediately respond to Ars' request to comment. However, a spokesperson told the Post that Chinese labs' distillation attacks "pose a serious threat to national security and undermine AI safety standards across the industry. That's why we continue to speak openly about what we're seeing and work closely with other labs, government, and partners on shared solutions."
[2]
Alibaba reportedly bans employees from using Claude Code
China's Alibaba will ban employees from using Anthropic's programming tool Claude Code, starting on July 10, according to multiple reports. Anthropic already prohibits Chinese companies, as well as foreign entities owned by those companies, from using its models. The company has reportedly been working to close loopholes that allow Chinese users to access Claude. According to a recent Reddit post, some of that loophole-closing involved a version of Claude Code that could secretly identify Chinese users. Anthropic's Thariq Shihipar said in a post on X that this was "an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation." (Distillation is a practice where AI models are trained on the outputs of other models.) "The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while," Shihipar said. Nonetheless, Alibaba has reportedly classified Claude Code as high-risk software and is instructing employees to use the company's own Qoder tool instead.
[3]
Alibaba bans Anthropic's Claude Code after an alleged hidden China-detection backdoor is uncovered -- employees told to switch to Qoder as the rift between the firms widens
Ban lands three weeks after Anthropic accused Alibaba's Qwen lab of running the largest known distillation attack on Claude. Chinese tech giant Alibaba has banned its employees from using Anthropic's Claude Code for all work purposes, effective July 10, after security researchers alleged the AI coding agent contained hidden code designed to detect whether users were based in China or affiliated with Chinese AI labs. According to a July 3 South China Morning Post report, the Chinese tech giant said Claude Code had been "added to a list of high-risk software with security vulnerabilities" following a comprehensive evaluation, citing what it described as back-door risks. Employees have reportedly been instructed to adopt Qoder, Alibaba's in-house AI coding platform, as the replacement. According to reports from Chinese outlets citing company insiders, the directive reportedly goes further than Claude Code itself, as staff have allegedly been told to uninstall all Anthropic products, including the Sonnet, Opus, and Fable model families. The move is the latest escalation in a feud that ignited last month, when Anthropic accused operators linked to Alibaba's Qwen AI lab of running the largest known model distillation attack against Claude. The trigger for the ban was a June 30 post on the r/ClaudeAI subreddit by a user who claimed to have reverse-engineered Claude Code while restoring a disabled remote-control feature. According to the write-up, obfuscated detection logic had shipped silently since version 2.1.91, released on April 2, with no mention in the release notes. Whenever a proxy was detected, the code reportedly checked whether the system timezone matched Asia/Shanghai or Asia/Urumqi and inspected the proxy URL against a hardcoded list of Chinese domains and AI lab identifiers, reportedly including Alibaba, Baidu, Ant Group, and ByteDance. What elevated the discovery from routine telemetry to scandal was the exfiltration method. Rather than sending an overt signal, the tool allegedly encoded its findings steganographically, tweaking the date format and swapping a punctuation character in the system prompt sent back to Anthropic's servers -- invisible to the user, but machine-parseable on Anthropic's end. The Reddit author called the covert transmission of system and proxy data "a fundamental violation of user trust," saying they simply wanted transparency from Anthropic. Anthropic has not issued a formal statement, but Thariq Shihipar, an engineer on the Claude Code team, addressed the findings on X, describing the mechanism as "an experiment we launched in March" intended to prevent account abuse by unauthorized resellers and to protect against distillation. Shihipar said the team had been meaning to remove the code for a while, and that the pull request stripping it out was merged on July 1, the day after the Reddit post. The timing of Alibaba's Claude ban fits right into the wider rift between the Chinese tech giant and the U.S. artificial intelligence frontrunner. On June 10, Anthropic sent a letter to leaders of the U.S. Senate Banking Committee accusing operators affiliated with Alibaba's Qwen lab of using nearly 25,000 fraudulent accounts to generate 28.8 million exchanges with Claude between April 22 and June 5, in what it characterized as an industrial-scale attempt to distill the model's software engineering and reasoning capabilities. Distillation, training a smaller model on the outputs of a more capable one, sits in a legal and ethical gray zone that the industry has yet to resolve. Alibaba has denied wrongdoing and has not addressed the allegations in detail. Anthropic followed the Senate letter with sweeping account restrictions, reportedly cutting off numerous Chinese users without notice. The company already maintains the industry's hardest line on access to China, stating it is the only frontier AI firm that restricts service to Chinese-owned entities, even through subsidiaries incorporated abroad. This stance is precisely why Chinese developers reach Claude Code through proxies in the first place, and why a proxy-triggered detection routine reads, to Chinese eyes, as a tool built to hunt them specifically. The episode slots into a U.S.-China AI relationship that has spent 2026 swinging in both directions at once. Washington had earlier placed export restrictions on AI chips to China. It loosened hardware controls this year, clearing roughly 10 Chinese firms, including Alibaba, to buy H200S in quantities of up to 75,000 units per customer. However, Beijing simultaneously discouraged Chinese firms from buying approved American silicon, citing its own security concerns, as part of a deliberate push toward an indigenous AI stack. Software access now appears to be following a similar trajectory of restrictions. Anthropic is blocking China at the account level; now, China's largest tech company has banned Anthropic at the workplace level. Earlier, OpenAI banned numerous China-linked accounts accused of artificially amplifying backlash against U.S. data center electricity prices. Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.
[4]
China warns about AI risks with Anthropic's Claude Code
BEIJING -- China on Wednesday warned of "back-door" security risks affecting companies that use U.S.-based company Anthropic's Claude Code artificial intelligence tool. It comes as the U.S.-China tech race intensifies, with Anthropic last month blaming Chinese company Alibaba for attempting to extract its AI capabilities, which are not officially available in China. Alibaba did not comment on the accusations at the time. Many locals in China have found ways to use U.S. AI tools, however. In March, a Xiaomi AI developer said at a state-organized forum that many were using Claude Code. And Alibaba has ordered its employees to stop using Anthropic tools for work starting July 10, CNBC confirmed on Monday. The Chinese Ministry of Industry and Information Technology said Wednesday its cybersecurity threat platform found "AI coding tool Claude Code contains a security back-door vulnerability that poses a serious threat." The autonomous coding tool can send sensitive information to a remote server without a user's consent, the statement said in Chinese, according to a CNBC translation. It noted that the information could include a user's location and identity. Users should uninstall or upgrade from the affected Claude Code versions, 2.1.91 to 2.1.196, the cybersecurity platform said. That covers versions released from April 2 to June 29, according to Anthropic's website, which says the latest version of Claude Code as of Wednesday is 2.1.204. Anthropic did not immediately respond to a CNBC request for comment.
[5]
Why A.I. Distillation Has Become a Hot Topic in the Race with China
The American companies building artificial intelligence systems are loudly complaining that their Chinese competitors are unfairly copying their technology, and they are pleading with officials to do something about it. On June 10, Anthropic sent a letter to Senators Tim Scott and Elizabeth Warren, accusing the Chinese tech giant Alibaba of surreptitiously copying its A.I. technologies using a technique called distillation. Like other Chinese companies, Alibaba tapped into Anthropic's technologies through tens of thousands of unauthorized accounts, according to the letter, which was viewed by The New York Times. Then it used the data it collected to train its own A.I. systems. Anthropic asked the lawmakers, who lead a Senate committee that was about to hold a hearing on A.I., to explore ways of curbing China's distillation. "These distillation attacks are carried out illicitly, systematically and at industrial scale to harvest U.S. A.I. capabilities across frontier labs and repackage them as their own," Anthropic told the two senators, referring to companies on the frontier of A.I. development. Experts say China trails the United States in A.I. development by just six months. Anthropic and other U.S. companies argue that without help from distillation, China would be much further behind, which could affect major A.I. uses like business planning, drug research, mass surveillance and military weapons. Their complaints have new urgency now that the Chinese start-up Z.ai has released an A.I. model, GLM-5.2, that is nearly as powerful as the top American systems. It rivals them when used for cybersecurity, an area that American A.I. companies and the Trump administration have singled out as vitally important to geopolitics. But what exactly is distillation, and are Chinese companies the only ones doing it? Here is an explanation. Is distillation a new concept? Not at all. Distillation has been common in the tech industry for more than a decade. A small team of Google researchers first developed the technique in the early 2010s as a way of building more efficient A.I. systems. Through distillation, researchers can collect data from a particularly powerful system and use that data to build a system that can run on less expensive hardware. The first A.I. model essentially shows the second model how to behave, said Geoffrey Hinton, a former Google researcher who helped develop the technique. "Think of one model as the teacher and the other as a student," he said. Distillation is a way to copy your own A.I.? Correct. But some companies used distillation to mimic technologies built by other A.I. labs. They often copied the behavior of open source technologies -- systems that anyone can use, modify and copy for free and largely without restriction. That is what labs hope to encourage when they open source their systems. The idea is that everyone benefits because A.I. is developed more quickly. When is distillation a problem? Anthropic, OpenAI and other A.I. labs get annoyed when companies use distillation to mimic the behavior of their proprietary systems -- technologies that are not open source. These are typically their most powerful systems. Anthropic and OpenAI do not allow distillation for their leading systems under their terms of service. But distilling these systems is still common. In April, while testifying in a federal trial in Oakland, Calif., Elon Musk acknowledged the practice at his A.I. company, xAI. When a lawyer asked if xAI had ever distilled technology from OpenAI, Mr. Musk replied: "Generally A.I. companies distill other A.I. companies." Is that illegal? That's not clear, said Sarah Tishler, a partner at the law firm Beck Reed Riden who specializes in trade-secret litigation. Some legal scholars argue that the practice violates the Defend Trade Secrets Act, a 2016 law that allows businesses to sue over the theft of trade secrets, but courts have not explicitly decided that. Copyright law does not necessarily apply because distillation is an effort to copy the behavior of the system, as opposed to copying text verbatim. Are the Chinese doing something similar? It is also not completely clear what Chinese companies are doing. They have likely distilled proprietary models in much the same way that American companies like xAI have done. Chinese distillation efforts, however, have caused far more concern among Anthropic, OpenAI and the other U.S. companies. About 18 months ago, the Chinese start-up DeepSeek shocked Silicon Valley when it showed that it could build effective A.I. far more affordably than many of its American counterparts. OpenAI soon accused DeepSeek of distilling its technologies. In February, Anthropic accused DeepSeek and two other Chinese start-ups of improperly harvesting large amounts of data from its systems. Anthropic said the start-ups had used about 24,000 accounts to generate over 16 million conversations with its Claude chatbot that could be used to teach skills to their own chatbots. How does Anthropic know this? Anthropic closely monitors how people use its systems. Certain repeated behavior, the company said, showed that accounts linked to China were lifting data from its proprietary models. Anthropic claimed that various Chinese companies had used a network of accounts to gain access to its systems. Each Chinese company, Anthropic said, uses this data to help train its own technologies. Can Anthropic prevent this? Anthropic, OpenAI and Google are sharing information that they can all use to combat the practice, they said. But it can be difficult to stop. If Anthropic shuts down too many accounts, it may end up barring legitimate users. Even if U.S. law did bar illicit distillation, Ms. Tishler said, it would most likely have little effect on behavior in China. "So much of this conduct is happening outside the United States," she noted. "It would be very challenging to address it through a U.S. court." (The Times sued OpenAI and Microsoft in 2023, claiming copyright infringement of news content related to A.I. systems. The two companies have denied those claims.) What else can U.S. companies do? Anthropic called on Congress to pass legislation that would allow "deeper collaboration to combat distillation attacks, both between the U.S. government and leading frontier labs as well as between the frontier labs themselves." The company also said the U.S. government should extend its efforts to limit China's access to the specialized computer chips needed to train A.I. technologies. The world's most powerful chips are designed by American companies, and the federal government has used export controls to stem the flow of those chips to China. It is difficult to do distillation without those chips. Alibaba declined to comment on Anthropic's letter to the two senators. Ms. Warren, Democrat of Massachusetts, also declined to comment. Mr. Scott, Republican of South Carolina, did not respond to a request for comment. Would a distillation crackdown have an impact? Many experts believe that a crackdown on Chinese distillation would have little effect, and that distillation alone cannot build a top A.I. system as Z.ai did. Others believe that distillation will become less important as companies build systems, like GLM-5.2, that are designed to serve as A.I. agents. Training these agents -- digital assistants that can use other software to perform tasks -- is much harder to duplicate through distillation. Distillation "won't matter as much for the next era of A.I.," said Sara Hooker, chief executive of Adaption, an A.I. research lab. Ryan Mac contributed reporting from Los Angeles, Eli Tan from San Francisco and Steve Lohr from New York.
[6]
Alibaba bans Claude Code over hidden Chinese user tracking
Alibaba banned Claude Code after security researchers found Anthropic had embedded steganographic tracking code to identify Chinese users. The ban follows Anthropic's accusation that Alibaba ran the largest known distillation attack on its models. Alibaba has banned its employees from using Claude Code, Anthropic's AI-powered coding agent, after security researchers discovered that the tool contained hidden code designed to identify Chinese users. The ban, effective 10 July, follows weeks of escalating conflict between the two companies over allegations that Alibaba stole Anthropic's AI capabilities through industrial-scale distillation. "As Claude Code was recently discovered to carry back-door risks, after comprehensive evaluation, Claude Code has now been added to a list of high-risk software with security vulnerabilities," Alibaba said in an internal notice reported by the South China Morning Post. The company recommended employees use Qoder, its own coding agent platform, as a substitute. How the tracking worked A Reddit user identified as LegitMichel777 reverse-engineered Claude Code on 30 June and found obfuscated code that had been silently present since version 2.1.91, released on 2 April, with no mention in the release notes. The code checked whether a user's system timezone was set to Asia/Shanghai or Asia/Urumqi and scanned proxy URLs against a hardcoded list of Chinese domains and AI lab addresses. Rather than logging the results conventionally, the system used steganography to hide its signals in the system prompt sent back to Anthropic's servers. If the timezone was Chinese, the date format changed from dashes to slashes, and the apostrophe in "Today's date is" was swapped with one of three visually identical but technically distinct Unicode characters depending on which flags were triggered. The alterations are invisible to human users and potentially even to the AI model itself, but they are machine-parseable by Anthropic's servers. Portions of the detection code were XOR-obfuscated with the key 91, a technique used to prevent plain-text extraction during code analysis. Anthropic's response Thariq Shihipar, an Anthropic engineer on the Claude Code team, said on X that the tracking was "an experiment we launched in March that was meant to prevent account abuse from unauthorised resellers and protect against distillation." He said the team had been "meaning to take this down for a while" and that the pull request to remove it was merged on 1 July. The rollback coincided with the restoration of Anthropic's Fable 5 and Mythos 5 models, which the US Commerce Department had ordered the company to disable for all foreign nationals in mid-June after Amazon researchers found a jailbreak vulnerability. The export controls were lifted on 30 June, and Anthropic restored access on 2 July, saying it would "scale up government collaboration" on frontier AI security. The distillation backdrop Anthropic's justification for the tracking code sits within a broader campaign against what it calls systematic theft of its models' capabilities. In a letter to the US Senate Banking Committee on 10 June, the company accused operators affiliated with Alibaba's Qwen AI lab of running the largest known distillation attack on Claude, using roughly 25,000 fraudulent accounts to generate 28.8 million exchanges between April and June. Alibaba has denied the accusation. Anthropic had previously named DeepSeek, Moonshot AI, and MiniMax in February as perpetrators of similar campaigns, framing distillation as an existential threat to the business models of frontier AI companies. Distillation, the practice of using a powerful model's outputs to train a smaller one, occupies a grey area in AI development. Asian AI startups have launched alternatives to Anthropic's models partly because the export ban on Fable 5 and Mythos 5 left a gap in the market, making the line between legitimate competition and illicit extraction increasingly difficult to draw. The developer trust problem Claude Code requires deep access to a developer's local file system to read, modify, and execute code, meaning any hidden functionality in the tool effectively has access to everything on the machine. Huorong Security, a Chinese cybersecurity firm, said Anthropic's tracking was not only a transparency issue but also raised cross-border data compliance concerns. "Today it's a timezone check, tomorrow it could be system sabotage or data exfiltration," one Reddit user wrote. Anthropic's privacy policy states that it collects the kind of data in question, but critics argue the steganographic method, designed to be invisible to users, crosses a line that a standard privacy disclosure does not. The bigger picture The episode accelerates China's push to reduce reliance on American AI tools, which Chinese firms increasingly view as carrying legal, security, and operational risks. Alibaba has been building out its own AI stack aggressively, integrating its Qwen models across products from e-commerce to robotics, and the Claude Code ban gives it further justification to push employees toward domestic alternatives. Lizzi Lee, a fellow at the Asia Society Policy Institute's Centre for China Analysis, said the conflict showed how the US-China AI competition has moved beyond technology into access control and sovereignty. "If a US AI coding tool can detect Chinese usage or proxy access, then it's not surprising for major Chinese tech companies to not want employees using it internally," she said. Anthropic's models have long been officially inaccessible in China, but they remain popular among domestic developers who use workarounds to maintain access. Whether the tracking controversy pushes more of them toward Chinese alternatives or simply confirms what many already suspected about the risks of depending on American AI tools is a question that extends well beyond Alibaba.
[7]
The covert U.S.-China battle to make chatbots leak their secrets
In March, artificial intelligence company Anthropic quietly deployed software to spy on China-based customers of its popular coding chatbot Claude Code. The apparent goal: unmasking the Chinese rivals the company suspected of hijacking its technology to make their own AI tools smarter. Anthropic's tracking code invisibly checked whether a Claude user's computer was set to Chinese time zones and using a web domain name linked to certain Chinese AI companies. The American firm backtracked and removed the electronic monitor last week, after a software developer revealed its existence and privacy advocates criticized Anthropic, saying it had surveilled its own users. An Anthropic executive said the tracking was an "experiment" that would be rolled back in favor of better defenses. But the episode revealed increasingly aggressive measures American firms are taking in a battle with Chinese rivals over who will control the technology's future. The geopolitical contest has contributed to recent, rapid-fire moves by the Trump administration to assert greater control of whom Anthropic and its chief U.S. rival, OpenAI, allow to access their technology. (The Washington Post has a content partnership with OpenAI.) But although the White House has claimed it is helping U.S. firms dominate AI, some Silicon Valley allies of President Donald Trump have said the recent policies risk making it harder for American firms to compete with those from China. The dissatisfaction with U.S. policy and allegations against Chinese firms come as evidence grows that their AI technology is becoming more competitive with that offered by U.S. companies. "They're very close," Srinivas Mukkamala, CEO of cybersecurity company Securin, said of the capabilities of Chinese AI models, "and they cost you nothing." For over a year, Chinese AI companies have consistently matched the capabilities of the latest U.S. AI models within months, industry benchmarks show. Among free and open AI models, Chinese options are already more popular than American ones, The Post reported in October. Last week, cybersecurity firm Semgrep said a new, free AI model from Chinese company Zhipu AI was better at finding computer vulnerabilities than Anthropic's Claude Opus 4.8 model, which was released in May. Anthropic's tracking code was designed in part to catch Chinese firms "distilling" its AI models, a technique that involves pressing a large, expensive AI system to serve as a tutor to a smaller, cheaper one. Asking the larger system huge numbers of questions -- hundreds of thousands or more -- generates responses that can be used to upgrade the power of the smaller one on the cheap. Distillation isn't illegal, and it has been used for years in the AI industry. But distillation without permission is against AI companies' rules, and, used effectively, is giving Chinese AI companies a major leg-up, American AI companies say. These "attacks pose a serious threat to national security and undermine AI safety standards across the industry. That's why we continue to speak openly about what we're seeing and work closely with other labs, government, and partners on shared solutions," a spokesperson for Anthropic said. Spokespeople for OpenAI did not return requests for comment. Anthropic and ChatGPT-maker OpenAI have both accused Chinese AI companies of using this technique to build copy-cat AI models of their own. In a May blog post, Anthropic said that Chinese companies' use of distillation, along with evading U.S. export controls on high-end computer chips, has allowed them to "trail closely" behind U.S. models. But if these techniques can be blocked, it might be possible for the United States to "lock in a 12-24 month lead" on Chinese capabilities, the company said. Neither Anthropic nor OpenAI permits access to their models from mainland China or Hong Kong, blocking users with measures that include IP-based location restrictions and government ID checks, though residents frequently find work-arounds to access the tech. This month, Anthropic said in a letter to U.S. senators that was obtained by The Post that it uncovered a campaign in which Chinese tech giant Alibaba's Qwen AI team used roughly 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Claude to improve its own technology. In February, Anthropic made similar accusations against the Chinese firms Deepseek, Moonshot and MiniMax and said the campaigns were "growing in intensity and sophistication." Alibaba, Deepseek, Moonshot and MiniMax did not respond to requests for comment. Anthropic and OpenAI have appealed to the U.S. government, arguing that distillation amounts to intellectual property theft that harms the U.S. in the geopolitical AI contest. "Anthropic's framing is that this is a geopolitical contest for basically the future of the world and freedom and democracy." said Kyle Chan, a fellow at the Washington-based Brookings Institution's China Center. "It's that this is not just undercutting the U.S. commercially, but undercutting American strategic advantage in the most powerful technology we know today," he said. That argument has been echoed by the Trump administration and some Republican lawmakers. In April, the White House released a memo warning that Chinese firms were running "deliberate, industrial-scale campaigns" to distill U.S. systems, raising concerns that the practice could allow Chinese competitors to build cheaper models stripped of safety mechanisms. "The United States cannot afford to let China or any other adversary gain a technological edge in artificial intelligence," said Sen. Tim Scott (R-South Carolina), chairman of the U.S. Senate Committee on Banking, Housing and Urban Affairs, at a hearing last month that addressed distillation concerns. "We have to carefully craft export control policy that is clear and concise," he said. That Chinese AI labs are using U.S. models to improve their own technology appears beyond dispute. In a February 2025 study, researchers from China's Peking University and the state-funded Chinese Academy of Sciences developed methods to detect signs of distillation in leading large language models. They concluded that, with the exception of ByteDance's Doubao, most domestic models they tested showed substantial evidence of distillation, mostly drawing from U.S. models. Among them was one of Chinese e-commerce giant Alibaba's Qwen AI models. Using tests that compared model outputs and probed for clues about a model's underlying identity, the researchers found that Qwen repeatedly appeared to mimic Claude -- suggesting Anthropic's model had been used to improve the Chinese system. In one set of intensive tests, a Qwen model misidentified itself as Claude nearly a third of the time, the Chinese researchers found. U.S. firms have also used distillation to piggyback on AI systems made by others. In 2024, OpenAI released a tool to make it easier for customers to distill its own models and produce data sets for AI training. SpaceX founder Elon Musk said in court testimony in May that his AI company xAI used distillation to train its models and that the technique is common throughout the industry. Without knowing the details about how a Chinese model was trained, it can be difficult to distinguish illicit behavior from a terms of service violation, said Irene Solaiman, the chief policy officer for Hugging Face, a repository for open source AI. But alleging popular Chinese models are somehow "stolen goods" could lead the U.S. to underestimate China's ability to innovate in AI. Chinese labs have consistently made breakthroughs in efficiency and cost effectiveness, partly out of necessity while facing U.S. export controls, she said. Silicon Valley startups and cash-strapped academic researchers have flocked to Chinese AI models, which companies such as Alibaba and Deepseek release free versions of for others to use and modify, in addition to charging for apps and services. Fortune 500 CEOs are beginning to call for cheaper alternatives to the extremely expensive AI sold by leading U.S. companies such as OpenAI and Anthropic. The chief executives of Airbnb, Brian Chesky, and cryptocurrency exchange Coinbase, Brian Armstrong, have spoken publicly about their companies' use of Chinese AI models. Any move to prevent Americans from building on Chinese open source models could harm the growing numbers of users, researchers and start-ups depending on them, Solaiman said. Preventing Chinese companies from distilling U.S. AI models would also be difficult. In September, Anthropic expanded its restrictions beyond users based in China to include any entity more than 50 percent owned by Chinese interests anywhere in the world. In April, it went further, requiring some users to verify their accounts with a government-issued ID. Despite that, Chinese users who have faced decades of internet restrictions under the tight controls of the Great Firewall are adept at finding ways around the types of regional registration controls that U.S. AI firms have put on their models. Anthropic said it has banned nearly 700,000 accounts that were using Claude in China. "There is a whole ecosystem of proxy servers, third-party accounts and even services that allow you to get around the know your customer ID verification," said Chan of the Brookings Institution. In recent tests conducted by The Post using Chinese phone numbers and subscriptions purchased on Alibaba-owned Taobao, access to free Claude and OpenAI free accounts was available for about $1 a month. Pro subscriptions that cost more than $100 a month in the U.S. were offered by Chinese re-sellers for as little as $12 monthly. Anthropic's February blog post alleging that Chinese companies distilled its AI models suggested that these proxy services can operate at huge scales. "When one account is banned, a new one takes its place. In one case, a single proxy network managed more than 20,000 fraudulent accounts simultaneously," it said.
[8]
Alibaba to ban Claude Code over alleged backdoor risk, source says
The workplace ban, starting July 10, lands weeks after Anthropic accused operators linked to Alibaba's Qwen lab of running the largest known distillation campaign against Claude. Alibaba will bar its employees from using Anthropic's Claude Code inside workplace environments from July 10, according to a person familiar with the matter cited by Reuters. The stated reason is an alleged backdoor built into the coding tool, though Alibaba has not confirmed the move publicly and did not immediately respond to a request for comment. The ban was first reported by the Chinese financial outlet Yicai before Reuters corroborated it through its own source. It arrives at an already tense moment for Anthropic and Alibaba, whose AI units have spent the past two months accusing each other of bad behaviour, first over alleged model theft and now over an alleged spying mechanism baked into Claude's own tooling. Claude Code is Anthropic's command-line coding agent, used by developers to write and debug software from a terminal rather than a chat window. It has become one of the company's fastest-growing enterprise products, which is part of why a workplace-wide ban at a company the size of Alibaba is notable. The alleged backdoor traces back to a Reddit post published on June 30 by a user identified as LegitMichel777, who said they had reverse-engineered Claude Code while restoring a disabled remote-control feature. According to a technical write-up shared alongside the post and later summarised by outlets including CyberSecurity News and Tech Times, the coding assistant had quietly checked, since version 2.1.91 released on April 2, whether a user's proxy configuration or system timezone matched entries on two hidden lists. One list allegedly named Chinese corporate networks, cloud regions and AI labs, including Alibaba, Baidu, ByteDance and Moonshot AI. If a match was found, the tool reportedly altered the date format and swapped a punctuation character in its own system prompt to encode the detection, rather than sending an overt telemetry signal. Anthropic has not issued a formal public statement on the allegation. A member of its Claude Code team, Thariq, is reported to have responded on social media that the mechanism was meant to curb account reselling and model distillation, and that it would be stripped out in the next release, a fix The Register and others reported was already underway by July 1. That timeline means the mechanism was reportedly still live for roughly three months before its removal. None of this happened in isolation. In a letter dated June 10 to US senators, Anthropic accused operators connected to Alibaba's Qwen AI lab of running nearly 25,000 fraudulent accounts to extract Claude's software engineering and reasoning capabilities, generating more than 28.8 million exchanges between April 22 and June 5. We have reported at the time that the campaign exceeded the combined scale of three earlier distillation efforts Anthropic had already flagged to Washington, including ones it attributed to DeepSeek, Moonshot and MiniMax. Alibaba has not commented publicly on that accusation either. The dispute sits alongside a broader pattern of restrictions tech companies have placed on coding agents amid distillation fears, and Anthropic's own tightening of access for Chinese users through tools like Claude Opus and Fable model curbs. Whether the alleged backdoor was a targeted espionage tool or a blunt anti-fraud filter that swept up ordinary Chinese-based developers remains contested, and no independent security firm has yet published a full audit of the claim. Alibaba's ban, if it proceeds as described on July 10, would make it one of the first major companies to formally restrict Claude Code specifically over the alleged mechanism rather than over competitive or cost concerns. Chinese developers who rely on proxy routing to reach the tool at all would be among those most exposed if the detection worked as the researcher described. Reuters said its report was based on a single source and that Alibaba had not responded by the time of publication. Anthropic was not quoted directly in the Reuters report either, leaving both companies' full positions on the record still unclear as the July 10 deadline approaches.
[9]
China warns of "security backdoor" in Anthropic AI coding tool
Beijing -- A Chinese industry regulator warned users on Wednesday of a "security backdoor" embedded in versions of U.S. artificial intelligence giant Anthropic's coding tool, Claude Code. The alleged backdoor could enable the software to "transmit sensitive information," including users' locations and identity-related identifiers, back to Anthropic's servers without users' consent, said China's National Vulnerability Database (NVDB), a cybersecurity platform. Claude Code is an AI coding agent that can generate computer code, debug software and review code based on user prompts. San Francisco startup Anthropic blocks users and companies in China and other nations it deems adversarial from accessing its products, but it is still possible to use them in the country through VPN or third-party proxy services. The NVDB, which is affiliated with China's Ministry of Industry and Information Technology, said on its website that it had recently "detected that the AI coding tool Claude Code contains security backdoor risks, posing a severe threat". Anthropic hasn't responded to AFP requests for comment on the allegations, which first emerged in specialist tech media last week. The NVDB advised relevant institutions and users "to conduct a comprehensive check immediately" and "promptly uninstall or upgrade to the latest secure version from which the relevant backdoor code has been removed." It also urged organizations to strengthen network traffic monitoring to prevent the unauthorized leakage of sensitive data. Chinese tech giant Alibaba told employees last week that the use of Claude Code would be banned starting July 10 due to security concerns, people familiar with the matter said. Anthropic has previously accused Alibaba of reverse-engineering its AI models to mimic their abilities in a process known as "distillation." Claude Code engineer Thariq Shihipar responded in an X post last week to reports alleging the tool was tracking certain data from Chinese users. "This is an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation," Shihipar wrote. "The team has landed stronger mitigations since then and we've actually been meaning to take this down for a while. ... This should be fully rolled back in tomorrow's release."
[10]
China issues 'backdoor' security alert over Anthropic's Claude Code
China's industry ministry identified a serious security backdoor risk in Anthropic's Claude Code. The National Vulnerability Database warned of unauthorised data transmission from affected versions. NVDB advised that organisations and users should immediately review affected systems and either uninstall the impacted versions or upgrade to the latest secure release in which the alleged backdoor code has been removed. A cybersecurity platform operated by China's industry ministry warned on Wednesday that it had identified a serious security "backdoor" risk in Anthropic's AI coding tool, Claude Code. In a statement posted on its WeChat account, the National Vulnerability Database (NVDB) said Claude Code contains a built-in monitoring mechanism capable of transmitting sensitive information, including users' geographic location and identity-related identifiers, to remote servers without users' consent. The warning applies to Claude Code versions 2.1.91 through 2.1.196. NVDB advised that organisations and users should immediately review affected systems and either uninstall the impacted versions or upgrade to the latest secure release in which the alleged backdoor code has been removed. It also urged organisations to tighten controls on external network access for development tools and strengthen traffic monitoring on core business networks to prevent the unauthorised transfer of sensitive data. China's Alibaba has banned employees from using Claude Code at work after the tool drew scrutiny for features that can help identify China-linked users, Reuters reported last week. Anthropic did not immediately reply to a Reuters request for comment.
[11]
Anthropic's Claude Code Just Set Off Alarms in China
China's Ministry of Industry and Information Technology issued a warning about a security flaw tied to Anthropic's Claude Code, saying the tool includes a "back-door" weakness that could put users at risk. Claude Code is Anthropic's AI coding assistant aimed at helping developers automate software tasks, analyze codebases, and improve productivity. The tool has gained attention as companies increasingly explore AI agents that can handle more complex workplace tasks. The ministry's platform reported that the affected Claude Code releases could transmit sensitive data to an external server without user approval, based on a CNBC translation of the Chinese-language notice. It said the information could include details such as a user's location and identity. China's notice pointed to Claude Code versions 2.1.91 through 2.1.196 as the impacted range, and advised users to uninstall or upgrade. Those builds correspond to releases spanning April 2 through June 29, based on version information listed on Anthropic's website. Anthropic stated that the "backdoor" referenced by Chinese officials was a test earlier in the year aimed at preventing distillation of its AI capabilities. The company also said its policies bar use by organizations that are majority owned by entities headquartered in China. The warning lands amid heightened scrutiny of access to U.S. AI tools inside China, where some developers have discussed using Claude Code despite the product not being officially offered there. Last month, Chinese technology giant Alibaba barred employees from using Anthropic's Claude Code at work, after the AI coding tool came under scrutiny over features that could help identify China-linked users, Reuters reported. Anthropic later accused Alibaba of improperly extracting capabilities from its Claude AI models. Meanwhile, in March, a Xiaomi AI developer said at a state-organized event that many were using Claude Code. The move reflects growing concerns in Washington over reliance on critical AI technologies and the companies that build them, as advanced models become increasingly integrated into government, defense, and enterprise systems. Earlier this year, the Pentagon designated the AI startup a "supply-chain risk" after it refused to relax restrictions on the military use of its models for autonomous weapons and domestic surveillance. Anthropic sued, alleging unlawful retaliation and violations of its free-speech rights, while multiple legal challenges remain ongoing. Last month, Anthropic disabled access to Fable 5 and Mythos 5 after the U.S. government ordered the company to prevent foreign nationals from using the systems. This content was partially produced with the help of AI tools and was reviewed and published by Benzinga editors. Market News and Data brought to you by Benzinga APIs To add Benzinga News as your preferred source on Google, click here.
[12]
Alibaba Blocks Staff From Using Anthropic AI Amid Security Concerns | PYMNTS.com
The tech giant has placed Anthropic's Claude Code on a high-risk software list, CNBC reported Monday (July 6), citing sources familiar with the matter. As the report notes, Alibaba's decision follows allegations by Anthropic last month that the Chinese company had "brazenly" and "illicitly" tried to extract its AI capabilities. Anthropic also accused Alibaba of conducting "the largest known distillation attack" on it to date. In distillation, the outputs of a strong model are used to train a less capable version. Companies that use this technique illicitly can acquire capabilities from other labs in much less time and at much less cost than they could developing those capabilities on their own. Anthropic had in February accused a trio of Chinese tech companies, DeepSeek, MiniMax and Moonshot AI, of carrying out these attacks and called on "industry players, policymakers and the global AI community" to help prevent them. The startup's terms of service say that Chinese companies and other "adversarial nations" are forbidden from using its models, the CNBC report added. Sources told CNBC that Alibaba employees were instructed to uninstall Anthropic models and agent products and use the Chinese company's Qoder AI assistant. As covered here last month, distillation attacks are simple: a campaign says large numbers of carefully constructed prompts to its target models and captures its responses, which become training data. "The competing model learns to reason and respond in ways that replicate the original, without paying for the research behind it," PYMNTS wrote. "It is less like hacking a system and more like sitting next to the best student in class and copying every answer they write, at industrial scale." Detection is difficult, as a distillation query is identical to a legitimate one. A developer who needs Claude to help debug a function and a campaign extracting Claude's coding behavior issue the same type of request. The only indication is pattern: huge volumes, repetitive structures and prompts focused on the same narrow capabilities, coming from hundreds of coordinated accounts in sequence. "As organizations increasingly integrate LLMs into their core operations, the proprietary logic and specialized training of these models have emerged as high-value targets," Google's Threat Intelligence Group warned in a February blog post.
[13]
Alibaba Reportedly Bans Anthropic's Claude for Employees, Citing Security Risks -- Directs Them to Use Qode
Alibaba Group Holding Ltd. (NYSE:BABA) has decided to bar its employees from utilizing AI tools developed by Anthropic, citing potential security risks. The ban is set to come into effect on July 10. The Chinese tech giant has labeled Anthropic's Claude Code as high-risk software. Alibaba employees have been directed to uninstall all Anthropic models and agent products and transition to Alibaba's in-house AI assistant, Qoder, reported CNBC on Monday. Alibaba and Anthropic did not immediately respond to Benzinga's request for comments. China Access Under Scrutiny This move follows Anthropic's allegations that Alibaba had tried to "brazenly" and "illicitly" distill its AI capabilities. In June, Anthropic sent a letter to the U.S. Senate Committee on Banking, Housing, and Urban Affairs, accusing Alibaba of launching "the largest known distillation attack" on its systems. Anthropic's terms of service prohibit Chinese companies and other "adversarial nations" from using its models. The term "distillation" refers to the practice of training a less advanced AI model using outputs from a more capable system. The report says Ant Group gave employees access to Anthropic's Claude through corporate accounts linked to its Singapore entity, while TikTok parent ByteDance does not officially provide Claude access but reimburses engineers for personal subscriptions accessed via VPNs to help them learn and experiment with a broader range of AI tools. Disclaimer: This content was partially produced with the help of AI tools and was reviewed and published by Benzinga editors. Image via Shutterstock Market News and Data brought to you by Benzinga APIs To add Benzinga News as your preferred source on Google, click here.
[14]
Alibaba's Anthropic ban could give it more control over China's AI market
Alibaba's reported ban on Anthropic's Claude Code looks, on the surface, like an IT decision at a company. It's probably bigger than that. A Chinese tech giant has warned staff not to use Anthropic's AI coding helper at work and has directed them toward its own coding platform, Qoder, Reuters reported, citing a person familiar with the directive. Reuters said the development came when Claude Code features that could assist in identifying users with links to China came under examination. For investors, the more profound problem isn't whether Alibaba (BABA) engineers are using this or that tool. The question is whether the AI competition is expanding from model performance to control of the entire developer stack. That's important because coding assistants are becoming one of the first areas that enterprises are turning AI into meaningful productivity improvements. If Chinese enterprises determine that U.S. tools pose a legal, compliance or national security concern, they could speed their migration to homegrown models and developer platforms. That might aid Alibaba's AI ambitions. It might also make a U.S.-China rift over AI tougher to undo. Alibaba is not just trying to build better AI models. It is trying to make sure the developers using those models never leave its ecosystem. "For national security reasons, Anthropic does not currently offer commercial access to Claude in China," the company said in a February post on detecting and preventing distillation attacks. Alibaba's Claude Code ban points to a developer-stack fight Claude Code is not your typical chatbot. Anthropic refers to Claude Code as an "agentic coding system," which can read a codebase, make changes across files, run tests and provide committed code. This makes it more of an AI software engineer than a basic text assistant. And that's why the Alibaba report matters. When the best AI technologies are embedded in development processes, controlling those workflows is a strategic priority. The company that owns the coding assistance, the model family, the cloud platform, and the billing relationship gets more than just usage revenue. It is distributed. Reuters stated that Alibaba staff were told to use its coding environment, Qoder, rather than Claude Code. Qoder bills itself as an agentic platform with tools like the Qoder Desktop, Qoder CLI, cloud agents and a terminal-native AI coding partner. Timing is key since Alibaba is already beginning with a bigger AI developer drive. Qwen Code is a terminal-based AI coding tool that connects to Alibaba Cloud Model Studio through pay-as-you-go, Coding Plan or token plan choices. This means Alibaba is not just generating models, but also packaging them into developer tools that it can sell and maintain via its cloud business. Alibaba Cloud also offers an AI Coding Plan that supports Qwen models, Qwen Code and other popular coding tools. The proposal incorporates the Qwen-series models, including qwen3.5-plus, qwen3-max, qwen3-coder-next and qwen3-coder-plus, as well as third-party models. That's the investor tip. Alibaba's restriction on Claude Code could minimize its reliance on a U.S. competitor, but it could also force more developers further into Alibaba's own AI and cloud offerings. Anthropic's Alibaba dispute raises the stakes The Alibaba-Anthropic battle is more than a matter of access. Anthropic also called out Alibaba for its alleged "distillation" effort, in which a less powerful model is trained on the outputs of a more proficient one, Reuters reported. Anthropic made the assertion in a letter to two U.S. senators. Anthropic has been publicly warning of distillation attacks. The business noted in a February post that labs can employ proxy services to access frontier models and generate enormous quantities of prompts targeted to extract specific skills. At one time, one proxy network had almost 20,000 bogus accounts, Anthropic stated. That goes some way to explaining why Claude Code became such a flashpoint. Developers told Reuters Claude Code had algorithms that evaluated user contexts, including time zone and proxy-related information, and included subtle marks in prompts sent to Anthropic's servers. The function was an experiment launched in March to avoid account abuse by unauthorized resellers and prevent model distillation, an Anthropic staffer wrote on X, Reuters said. But the main point is that AI tools are no longer products. They are becoming managed infrastructure. In its supported areas site, Anthropic notes it reserves the right to deny products or services to entities whose predominant ownership may be traced back to countries not covered by its approved regions policy. Anthropic said in September 2025 that it was tightening limitations to bar companies controlled from countries where its products are banned, including China, regardless of where they operate. This puts big firms in a bind. Individual users may be able to circumvent the restrictions. But companies have legal, cybersecurity, and compliance teams. They have vendor risk policies. They have boards and regulators. So the Alibaba restriction could matter more than a regular software policy change. Alibaba's AI business could get a tailwind. And Alibaba already has a financial incentive to keep AI activities more in its own ecosystem. Revenue at its Cloud Intelligence Group soared 36% to 43.28 billion yuan, or $6.19 billion, in the March quarter, the company said, supported by AI-related product revenue that posted triple-digit growth for the 10th straight quarter. Alibaba also announced its Qwen model family has become the most widely used open source model family in the world, with more than 1 billion total downloads on Hugging Face as of Jan. 21, 2026. The company said as of February, its consumer-facing Qwen app had over 300 million monthly active users across platforms. Those data help explain why the narrative of the Claude Code has a market angle. Alibaba doesn't need Qwen to dominate every AI benchmark to count. It requires developers, enterprises and consumers to utilize its products frequently enough that the utilization strengthens Alibaba Cloud and related AI services. This is the point where coding helpers come in. Developers are sticky users. They create procedures, tools and habits around the systems they use daily. Once a corporation has standardized on a coding assistant, the model supplier might become part of the software-development process. VCG / Getty Images Alibaba-Anthropic dispute: Key investor takeaways * Alibaba reportedly banned employees from using Anthropic's Claude Code at work. * The company is reportedly directing employees toward Qoder, its own coding platform. * Anthropic has accused Alibaba of distilling Claude capabilities, according to Reuters. * Anthropic says it does not currently offer commercial Claude access in China. * Alibaba Cloud's AI-related product revenue has delivered triple-digit growth for 10 consecutive quarters. Alibaba said its Qwen family has amassed over 1 billion cumulative downloads on Hugging Face. That is a clear strategic message. U.S. AI firms want to safeguard access to models. Chinese AI companies seek to cut dependence on U.S. tools. The developers are right in the middle. For Alibaba, it represents both potential and risk. The upside is that a push towards local AI technologies could boost Alibaba's cloud and Qwen ecosystem. The problem is that the same geopolitical division could lead to a more fragmented, more regulated, and more expensive competition for AI. Alibaba's real AI test is control, not just capability Alibaba's alleged restriction on Claude Code is not the greatest AI story in itself. But the real story is what it tells us. The race to build artificial intelligence is going deeper into the plumbing of software development. It's not about who has the smartest chatbot or the most spectacular benchmark anymore. It's about who owns the tools that developers use to write, test and deploy code. That's why this fight is important to investors. Alibaba has been pouring money into AI and cloud infrastructure. And it has a method to translate those investments into daily developer usage through its Qwen models, Qwen Code and the Qoder platform. If restrictions on access by other Chinese firms mean a flight from U.S. AI technologies, Alibaba would have a more captive domestic market due to concerns about surveillance or compliance risk. But there's a catch. A more fractured AI industry might also mean the cost of competing worldwide is higher. U.S. developers may be more wary of Chinese models. Chinese developers may be pushed to local stacks. Cloud providers will need to provide more localized, compliant versions of the same core capabilities. That is to say, the potential for Alibaba's AI has a sharper geopolitical edge. The company is set to benefit from China's push for autonomous AI. But the same trend could make it harder to develop the global AI sector across borders. The message for Alibaba investors is simple. Claude Code could be the spark. The true prize is control of the developer stack. The Arena Media Brands, LLC THESTREET is a registered trademark of TheStreet, Inc. This story was originally published July 6, 2026 at 2:03 PM.
[15]
Alibaba to ban Claude Code in workplace over alleged security risks, Reuters says By Investing.com
Investing.com -- Alibaba Group Holding Ltd (HK:9988) will prohibit employees from using Anthropic's (NASDAQ:ANTP) Claude Code in its workplace environments from July 10 over concerns about potential security risks, Reuters reported on Thursday, citing a person familiar with the matter. The decision follows a report by Chinese financial outlet Yicai that said Alibaba had identified what it described as embedded "backdoor" risks in the AI coding assistant. Hong Kong-listed Alibaba shares was down 0.7%, underperforming the broader Hang Seng, which advanced 1.3%. Track AI leaders, cybersecurity developments and China tech stocks with InvestingPro The move comes as tensions between Alibaba and Anthropic have escalated in recent weeks. Last month, Anthropic accused operators affiliated with Alibaba and its Qwen AI unit of conducting a large-scale effort to extract capabilities from its Claude models through fraudulent accounts, allegations the Chinese technology giant has not publicly addressed. Claude Code, Anthropic's AI-powered software development assistant, has become one of the industry's most widely used coding tools, but access to the company's most advanced models has increasingly come under regulatory scrutiny. Last week, the U.S. government partially restored access to Anthropic's flagship AI models for a limited group of trusted organizations after temporarily restricting their deployment over national security concerns. Alibaba has invested heavily in expanding its Qwen family of large language models as it competes with domestic rivals including DeepSeek, Tencent and Baidu, while Anthropic has strengthened measures to prevent unauthorized access to its Claude platform amid growing concerns over model distillation and cross-border misuse.
[16]
China Says It Has Found Security Vulnerabilities in Anthropic's Claude Code
SINGAPORE--China said Wednesday that it has found "security backdoor vulnerabilities" in Anthropic's popular Claude Code, stepping up tensions in the race with the U.S. for artificial-intelligence supremacy. Several versions of the American coding tool, released between April and June, "can send sensitive information such as user location and identity to remote servers without the user's consent due to a built-in monitoring mechanism," China's National Vulnerability DataBase, a government-run cybersecurity platform, said in a statement. The agency warned such a mechanism could pose "a serious threat." It advised users to uninstall the software or update to its latest version. Last week, Chinese tech giant Alibaba told employees that it would ban their use of Claude Code at work from this Friday. Anthropic didn't immediately respond to a request for comment on China's Wednesday statement. The U.S. company has previously said that Chinese companies such as Alibaba aren't eligible to access Claude. China's move came after a post on online forum Reddit last week alleged that Anthropic had secretly inserted code into the software to identify users who accessed it from China. In a response to the allegations on Reddit, an Anthropic employee said on X that the code was part of an experiment the American startup started in March. The experiment was "meant to prevent account abuse from unauthorized resellers and protect against distillation," the employee said. Since February, Anthropic has accused Alibaba and several other Chinese AI labs of illicitly distilling its models-the practice of training a new model on the outputs of another. China hasn't approved Anthropic's services for public use, and Anthropic has also restricted access to Claude in China on national-security grounds. Still, the American AI model has been popular among Chinese researchers and engineers who use it through overseas proxies, often subsidized by their employers.
[17]
Alibaba Set to Ban Staff From Using Claude Over Security Fears
China's Alibaba plans to ban employees from using Anthropic's Claude Code at work over concerns about potential security risks, according to people familiar with the matter. The move comes in the wake of a post on online forum Reddit earlier this week alleging that a version of the software released in April contained code that could identify users who accessed it from China. In a response to the allegations in the report, Thariq Shihipar, who works on Claude Code, said on X on Wednesday that the code was part of an experiment Anthropic launched in March "meant to prevent account abuse from unauthorized resellers and protect against distillation." Anthropic has accused Alibaba and several other Chinese AI labs of illicitly distilling its models--the practice of training models on the outputs of another. In February, Anthropic said it found that some senior staff of Chinese labs were likely behind some accounts that had distilled its models based on the information of the accounts' activities. The U.S. company has restricted access to Claude in China on national security grounds, though the tool is still popular among Chinese researchers and engineers. Alibaba has classified Claude Code as "high-risk software" following the Reddit report, the people said. Staff won't be allowed to use it from July 10, they said.
Share
Copy Link
Anthropic removed a secret tracker from Claude Code after a researcher exposed hidden code monitoring Chinese users. The discovery prompted Alibaba to ban the AI tool, classifying it as high-risk software. The incident escalates tensions in the US-China AI conflict as both companies accuse each other of security violations and model theft.
Anthropic quickly removed hidden code from Claude Code after a security researcher exposed a tracker that secretly monitored Chinese users. Last week, web developer "Thereallo" discovered the AI firm was using prompt steganography to hide detection logic "in plain sight"
1
. The code wasn't malicious but sent information to Anthropic that most users wouldn't detect, using shorthand markers to flag users' timezone, proxy settings, and potential connections to Chinese AI labs.
Source: Benzinga
Anthropic engineer Thariq Shihipar confirmed the tracker was added as "an experiment" in March to prevent account abuse from unauthorized resellers and protect against distillation attacks
2
. The Washington Post found unauthorized retailers have sold access to free models for $1 monthly, while pro subscriptions costing $100 are available for as little as $121
. According to Shihipar, engineers had "landed stronger mitigations since then" and were planning to remove the code.The discovery method revealed sophisticated surveillance tactics. According to a Reddit post, obfuscated detection logic had shipped silently since version 2.1.91, released on April 2, with no mention in release notes
3
. When a proxy was detected, the code checked whether the system timezone matched Asia/Shanghai or Asia/Urumqi and inspected proxy URLs against a hardcoded list of Chinese domains and AI lab identifiers, including Alibaba, Baidu, Ant Group, and ByteDance.What elevated concerns was the exfiltration method. Rather than sending an overt signal, the tool encoded findings steganographically, tweaking date formats and swapping punctuation characters in system prompts sent to Anthropic's servers—invisible to users but machine-parseable on Anthropic's end
3
. Privacy advocates warned the code proves Anthropic is willing to cross lines to surveil users, especially surprising given the company sued the White House after refusing to let the US government use Claude to monitor American users1
.Alibaba moved swiftly to distance itself from security vulnerabilities. Last Friday, the Chinese tech giant banned employees from using Claude Code for work, effective July 10
2
. According to a memo reviewed by South China Morning Post, Alibaba classified Claude Code as "high-risk software with security vulnerabilities" citing back-door risks3
.
Source: PYMNTS
Employees have been instructed to adopt Qoder, Alibaba's in-house AI coding platform. Reports from Chinese outlets suggest the directive extends beyond Claude Code, with staff allegedly told to uninstall all Anthropic products, including Sonnet, Opus, and Fable model families
3
. China's Ministry of Industry and Information Technology issued a warning Wednesday about the autonomous coding tool sending sensitive user data including location and identity to remote servers without consent4
. The cybersecurity platform advised users to uninstall or upgrade from affected versions 2.1.91 to 2.1.196.Related Stories
The ban arrives three weeks after Anthropic accused Alibaba's Qwen lab of running the largest known AI model distillation attack on Claude. On June 10, Anthropic sent a letter to Senate Banking Committee leaders claiming operators affiliated with Qwen used nearly 25,000 fraudulent accounts to generate 28.8 million exchanges with Claude between April 22 and June 5
3
. This represented an industrial-scale attempt to distill Claude's software engineering and reasoning capabilities.
Source: NYT
Alibaba hasn't commented on accusations of account abuse and distillation attacks, but research supports widespread distillation practices. In February, Chinese researchers at Peking University and the state-funded Chinese Academy of Sciences found most Chinese models "showed substantial evidence of distillation," primarily of US models
1
. One Alibaba Qwen model would sometimes identify itself as Claude during intensive tests.The incident highlights increasingly aggressive measures US firms are taking amid geopolitical tensions. In the past year, Chinese firms have "consistently matched" US capabilities within months
1
. A new free AI model from Zhipu AI recently outperformed Anthropic's Claude Opus 4.8 at finding computer vulnerabilities.Anthropic has joined OpenAI in urging the US to treat distillation as intellectual property theft. At a Senate hearing, Senator Tim Scott agreed legal intervention is needed through carefully crafted export restrictions
1
. While distillation isn't illegal—leading US firms practice it too—using millions of unauthorized users violates corporate policy and terms of service5
. Legal experts note some scholars argue the practice violates the Defend Trade Secrets Act, though courts haven't explicitly ruled on this yet. For Alibaba, complying with the ban on Anthropic tools reduces legal and compliance risks, unlike individual unauthorized users who can easily circumvent location blockers without major repercussions.Summarized by
Navi
[2]
24 Jun 2026•Technology

03 Jul 2026•Policy and Regulation
08 Jul 2026•Technology

1
Technology

2
Policy and Regulation

3
Science and Research
