July 5, 2026

Covert Code

On July 10, Alibaba will ban its employees from using Anthropic's Claude Code, the command-line coding agent that has become one of Anthropic's fastest-growing enterprise products.[1] The stated reason: a hidden mechanism inside Claude Code that quietly detected Chinese users and encoded that detection into system prompts without telling them.

According to a Reddit post published on June 30 by a user who reverse-engineered the tool, Claude Code version 2.1.91 (released April 2) checked whether a user's proxy configuration or system timezone matched entries on two hidden lists.[2] One list allegedly named Chinese corporate networks, cloud regions, and AI labs, including Alibaba, Baidu, ByteDance, and Moonshot AI. When a match was found, the tool did not send an overt telemetry signal. Instead, it altered the date format and swapped a punctuation character in its own system prompt to encode the detection. Subtle, quiet, and apparently live for roughly three months before its removal was reported on July 1.[3]

An Anthropic team member acknowledged the mechanism on social media, calling it "an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation."[4] Distillation, in this context, is the practice of training AI models on the outputs of other models, effectively copying their capabilities without permission. Anthropic said the team had landed stronger mitigations since then and planned to remove the covert code.

That explanation might sound reasonable in isolation. But the backdrop makes it explosive. In a letter dated June 10 to US senators, Anthropic accused operators connected to Alibaba's Qwen AI lab of running nearly 25'000 fraudulent accounts to extract Claude's software engineering and reasoning capabilities, generating more than 28.8 million exchanges between April 22 and June 5.[5] The campaign reportedly exceeded the combined scale of three earlier distillation efforts Anthropic had already flagged to Washington, including ones attributed to DeepSeek, Moonshot, and MiniMax.

So the picture is: Anthropic suspected Chinese AI labs, including one linked to Alibaba, were systematically extracting Claude's outputs through thousands of fake accounts. In response, they built a covert detection mechanism into their coding tool to identify users on Chinese corporate networks. When that mechanism was discovered and publicized, Alibaba responded by banning the tool entirely and directing employees to use its own Qoder coding assistant instead.[6]

There are no clean hands here. Anthropic's approach was to quietly embed detection code in a developer tool, altering behavior based on geography and corporate affiliation without disclosure. That is spyware by most definitions, regardless of the motivation. Alibaba's response was to ban the tool and redirect employees to its own product, which is both a security decision and a convenient competitive move. And the original distillation accusations, if true, represent industrial-scale IP theft.

The episode highlights a tension that is only going to intensify. AI coding agents are powerful tools, and powerful tools invite misuse. Companies want to protect their models from being distilled by competitors. Users want to know what the tools they rely on are doing behind the scenes. Those two interests are in direct conflict, and right now neither side is being fully transparent.

Anthropic should have disclosed the detection mechanism, or at minimum documented it in a changelog. Hiding it in system prompt alterations was a choice to prioritize enforcement over trust. Alibaba's ban is a predictable reaction, but it also serves their competitive interests. And the 25'000 fraudulent accounts, if real, are a reminder that the threat Anthropic was responding to is not hypothetical.

The broader signal is that AI tooling is becoming a battleground for geopolitical and commercial interests in ways that traditional software never was. A coding assistant is not just a coding assistant when it can detect who is using it and alter its behavior accordingly. And a ban is not just a ban when it redirects an entire workforce to a domestic alternative. The tools are watching, the users are watching back, and nobody is fully honest about what either side is doing.

← All posts