Alibaba Bars Claude Code Over Backdoor Allegations

Alibaba banned Claude Code effective July 10, citing embedded backdoors. The ban lands days after Anthropic accused three Chinese labs of distilling Claude.

Lines of code on a dark monitor screen, evoking software development and supply-chain trust

Alibaba has told its staff to stop using Anthropic’s Claude Code in any office workflow starting July 10, the first corporate ban of a Western coding agent by a major Chinese tech firm. The reason given in an internal notice, as reported by Reuters and the South China Morning Post, is that Anthropic’s product was found to “carry back-door risks.” SCMP, citing the same notice, attributes the concern to code inside Claude Code that “could secretly track whether a user was based in China or affiliated with a Chinese AI lab” - a category of hidden behavior we have seen publicly documented before, in the leaked Claude Code source that exposed anti-distillation code and an unreleased “Kairos” daemon. The move lands four months after Anthropic itself accused three Chinese AI developers of running a coordinated “distillation” campaign against Claude, and on the same week that Citizen Lab confirmed Pegasus spyware targeted a member of the European Parliament’s own spyware-investigating committee. Read together, the three events mark a moment when AI tooling is being treated, on both sides of the Pacific, less like productivity software and more like the next category of dual-use infrastructure.

What Alibaba actually did

The directive is an internal corporate ban, not a regulator’s order. According to Reuters via Yahoo Finance, Alibaba told employees that “Claude Code will be banned from use in the workplace from July 10, due to alleged security risks involving embedded backdoors, a source familiar with the matter said.” Alibaba did not immediately respond to a Reuters request for comment, and the story was first broken by Chinese financial outlet Yicai. The Reuters write-up was by Eduardo Baptista and Che Pan and edited by Jacqueline Wong.

SCMP obtained a copy of the internal Alibaba notice and published the relevant language verbatim. The notice reads: “As Claude Code was recently discovered to carry back-door risks, after comprehensive evaluation, Claude Code has now been added to a list of high-risk software with security vulnerabilities.” SCMP, which is owned by Alibaba, was the outlet that connected that notice to the specific allegation that Anthropic embedded code able to identify users based in China or affiliated with Chinese AI labs. The story was filed at 10:15 pm on July 3 by Xinmei Shen in Hong Kong and Ben Jiang in Beijing, and updated ten minutes later.

The technical trigger was outside Alibaba. SCMP reports that “security researchers posted findings on Reddit and GitHub earlier in the week.” That is the second notable crowdsourced audit of a frontier coding agent in two months: in February, Anthropic was itself the researcher publishing a similar kind of usage-trace analysis against its own model, in the other direction.

Anthropic’s earlier counter-accusation

The Alibaba ban lands four months after Anthropic itself was on the other side of an almost identical debate. In February 2026, Anthropic published a report alleging that “three Chinese AI companies” - DeepSeek, Moonshot AI, and the Shanghai-based MiniMax - had “set up more than 24,000 fake accounts” generating more than 16 million exchanges with Claude, targeting “agentic reasoning, tool use, and coding.”

The TechCrunch account, written by Rebecca Bellan on February 23, 2026, breaks the totals down by company. DeepSeek sent more than 150,000 exchanges aimed at “foundational logic” and “censorship-safe alternatives to policy-sensitive queries,” according to Anthropic. Moonshot AI sent more than 3.4 million, and Anthropic says it released Kimi K2.5 and a coding agent in January 2026. MiniMax sent 13 million, with Anthropic saying it “redirected nearly half its traffic to siphon capabilities from the latest Claude model when it was launched.” TechCrunch reported that DeepSeek, Moonshot, and MiniMax did not respond to requests for comment.

The story carried an outside quote that frames the dispute: Silverado Policy Accelerator chairman and former CrowdStrike CTO Dmitri Alperovitch told TechCrunch, “It’s been clear for a while now that part of the reason for the rapid progress of Chinese AI models has been theft via distillation of U.S. frontier models. Now we know this for a fact.” Anthropic’s blog post, as cited by TechCrunch, ties the dispute to chip export policy: “Distillation attacks therefore reinforce the rationale for export controls: restricted chip access limits both direct model training and the scale of illicit distillation.”

What This Means

For users anywhere in the world, the practical lesson is that coding agents are about to be procurement-grade decisions, not developer preferences. The Alibaba ban is the first time a major Chinese tech firm has publicly pulled a Western AI coding agent on security grounds. The Pegasus discovery published the same week - in which a sitting member of the EU’s PEGA committee was found to have been infected with the very spyware the committee was investigating - is the European equivalent of the same shift. The combined signal is that buyers, not benchmark leagues, will start screening AI tools for the same reasons they screen base stations and routers: supply-chain integrity, jurisdiction of the operator, and what the agent actually sends home.

For developers in the West the more direct effect is geopolitical. Chinese vendors respond to perceived surveillance risk exactly the way they respond to perceived tariff risk: with bans and substitutions - which is also why Alibaba and its peers keep investing in home-grown frontier models like Qwen 3.5. The same logic is already familiar in telecoms (the Huawei restrictions in multiple Western markets) and chips (the December 2025 reversal that allowed Nvidia H200 exports to China, as cited by TechCrunch in the distillation piece). The flip side is that if a Western vendor is even credibly accused of region-aware telemetry, the trust clock in Chinese enterprise procurement resets to zero. Anthropic has not, as of this writing, published a public response to the SCMP allegation that Claude Code can identify Chinese users. Whether or not the allegation is technically correct, corporate buyers in China now have a reason to treat it as a fact.

For readers who use Claude Code or any other agent locally, the part of Alibaba’s story that travels is the audit pattern. Alibaba’s move was triggered by a week-old Reddit and GitHub post, not by an official Chinese regulator. That means the first line of defense is the same as always: read the changelog, follow the project’s GitHub discussions, and watch what community researchers publish before corporate IT sends you a memo.

The Bottom Line

A Western coding agent has been banned inside a Chinese tech firm on backdoor grounds at the same moment a sitting member of the EU’s spyware-investigating committee has been confirmed as a Pegasus target. The implication is not that Claude Code is malicious or that Apple’s threat notifications are broken; it is that AI tooling is now being evaluated, on both sides, the way dual-use infrastructure has always been evaluated - by who built it, what jurisdiction it lives in, and where its data ends up.