The story starts with a Reddit post.
On June 30, a developer reverse-engineered Claude Code — Anthropic's coding assistant — and found something it wasn't advertising: code that identified Chinese users. The check scanned system timezones and proxy URLs against a list of 147 Chinese domains, plus network characteristics associated with Chinese AI infrastructure. When it found a match, it didn't raise an alert. Instead, it encoded its findings steganographically — tweaking a date format and swapping a punctuation character in the system prompt, invisible to the user but machine-readable on Anthropic's servers.
The code had been present since version 2.1.91, released in April 2026, with no mention in any changelog. Anthropic removed it on July 1, the day after the post spread through developer circles.
Anthropic's explanation: an experimental anti-abuse feature, deployed specifically to combat distillation attacks. On June 10, the company had sent a formal letter to US Senate leaders accusing Alibaba's Qwen lab of running 25,000 fraudulent accounts through Claude between April 22 and June 5, generating 28.8 million exchanges to copy Claude's software engineering and reasoning capabilities into Alibaba's own models. Anthropic described it as "the largest known distillation attack" on any AI lab to date.
Alibaba's response: ban Claude Code from all employee devices starting July 10, and replace it with the company's own Qoder tool. Alibaba labeled the detection code a security risk and a backdoor.
Both sides have a legitimate argument. Distillation at 28.8 million interactions is industrial-scale IP theft if Anthropic's account is accurate. But shipping silent user-classification code without disclosure — and using steganography to mask the signal — is a real concern for any company running Claude Code in a corporate environment. Anthropic's own spokesperson acknowledged the team had intended to remove the code before the Reddit post forced the issue.
For everyday Claude users who access the assistant through claude.ai, none of this changes anything. The detection code was specific to Claude Code — the developer tool — not the standard web or mobile interface, and Anthropic confirmed it was fully removed as of July 1.
What the episode makes clear is how fast the US-China AI competition has escalated beyond benchmarks and hiring battles. Formal Senate accusations. Covert detection code. Corporate bans. In the span of a few weeks, a competitive rivalry has started to look like something more serious.
If you're looking to get more from your Claude subscription while keeping things simple — no developer tools, no geopolitical drama — ClaudeCraft's done-for-you guides at https://claudecraft.ca are built for exactly that.
- CNBC — China's Alibaba bans Anthropic AI for employees after 'distillation attack' accusation
- TechCrunch — Alibaba reportedly bans employees from using Claude Code
- Tom's Hardware — Alibaba bans Anthropic's Claude Code after an alleged hidden China-detection backdoor is uncovered
- The Next Web — Alibaba bans Claude Code over hidden Chinese user tracking