Alibaba Bans Claude Code After Anthropic's Hidden Tracker Monitored Chinese Users

Reviewed byNidhi Govil

17 Sources

Share

Anthropic removed a secret tracker from Claude Code after a researcher exposed hidden code monitoring Chinese users. The discovery prompted Alibaba to ban the AI tool, classifying it as high-risk software. The incident escalates tensions in the US-China AI conflict as both companies accuse each other of security violations and model theft.

Anthropic Exposed for Secret Tracking Code in Claude Code

Anthropic quickly removed hidden code from Claude Code after a security researcher exposed a tracker that secretly monitored Chinese users. Last week, web developer "Thereallo" discovered the AI firm was using prompt steganography to hide detection logic "in plain sight"

1

. The code wasn't malicious but sent information to Anthropic that most users wouldn't detect, using shorthand markers to flag users' timezone, proxy settings, and potential connections to Chinese AI labs.

Source: Benzinga

Source: Benzinga

Anthropic engineer Thariq Shihipar confirmed the tracker was added as "an experiment" in March to prevent account abuse from unauthorized resellers and protect against distillation attacks

2

. The Washington Post found unauthorized retailers have sold access to free models for $1 monthly, while pro subscriptions costing $100 are available for as little as $12

1

. According to Shihipar, engineers had "landed stronger mitigations since then" and were planning to remove the code.

Hidden China-Detection Backdoor Triggers Privacy Concerns

The discovery method revealed sophisticated surveillance tactics. According to a Reddit post, obfuscated detection logic had shipped silently since version 2.1.91, released on April 2, with no mention in release notes

3

. When a proxy was detected, the code checked whether the system timezone matched Asia/Shanghai or Asia/Urumqi and inspected proxy URLs against a hardcoded list of Chinese domains and AI lab identifiers, including Alibaba, Baidu, Ant Group, and ByteDance.

What elevated concerns was the exfiltration method. Rather than sending an overt signal, the tool encoded findings steganographically, tweaking date formats and swapping punctuation characters in system prompts sent to Anthropic's servers—invisible to users but machine-parseable on Anthropic's end

3

. Privacy advocates warned the code proves Anthropic is willing to cross lines to surveil users, especially surprising given the company sued the White House after refusing to let the US government use Claude to monitor American users

1

.

Alibaba Responds With Ban on Anthropic Tools

Alibaba moved swiftly to distance itself from security vulnerabilities. Last Friday, the Chinese tech giant banned employees from using Claude Code for work, effective July 10

2

. According to a memo reviewed by South China Morning Post, Alibaba classified Claude Code as "high-risk software with security vulnerabilities" citing back-door risks

3

.

Source: PYMNTS

Source: PYMNTS

Employees have been instructed to adopt Qoder, Alibaba's in-house AI coding platform. Reports from Chinese outlets suggest the directive extends beyond Claude Code, with staff allegedly told to uninstall all Anthropic products, including Sonnet, Opus, and Fable model families

3

. China's Ministry of Industry and Information Technology issued a warning Wednesday about the autonomous coding tool sending sensitive user data including location and identity to remote servers without consent

4

. The cybersecurity platform advised users to uninstall or upgrade from affected versions 2.1.91 to 2.1.196.

US-China AI Conflict Intensifies Over Distillation Attacks

The ban arrives three weeks after Anthropic accused Alibaba's Qwen lab of running the largest known AI model distillation attack on Claude. On June 10, Anthropic sent a letter to Senate Banking Committee leaders claiming operators affiliated with Qwen used nearly 25,000 fraudulent accounts to generate 28.8 million exchanges with Claude between April 22 and June 5

3

. This represented an industrial-scale attempt to distill Claude's software engineering and reasoning capabilities.

Source: NYT

Source: NYT

Alibaba hasn't commented on accusations of account abuse and distillation attacks, but research supports widespread distillation practices. In February, Chinese researchers at Peking University and the state-funded Chinese Academy of Sciences found most Chinese models "showed substantial evidence of distillation," primarily of US models

1

. One Alibaba Qwen model would sometimes identify itself as Claude during intensive tests.

Geopolitical Tensions Drive Calls for Legal Action

The incident highlights increasingly aggressive measures US firms are taking amid geopolitical tensions. In the past year, Chinese firms have "consistently matched" US capabilities within months

1

. A new free AI model from Zhipu AI recently outperformed Anthropic's Claude Opus 4.8 at finding computer vulnerabilities.

Anthropic has joined OpenAI in urging the US to treat distillation as intellectual property theft. At a Senate hearing, Senator Tim Scott agreed legal intervention is needed through carefully crafted export restrictions

1

. While distillation isn't illegal—leading US firms practice it too—using millions of unauthorized users violates corporate policy and terms of service

5

. Legal experts note some scholars argue the practice violates the Defend Trade Secrets Act, though courts haven't explicitly ruled on this yet. For Alibaba, complying with the ban on Anthropic tools reduces legal and compliance risks, unlike individual unauthorized users who can easily circumvent location blockers without major repercussions.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved