Skip to content
The ColumnProfile· No. 3260

Claude Code, the tool Alibaba is banning over backdoor fears

Just a few months ago, Claude Code was, for most of the general public, just one coding tool among many, developed by

Premium reading
MadMax
Key takeaways
  1. Just a few months ago, Claude Code was, for most of the general public, just one coding tool among many, developed by
  2. Introduction: the profile of a tool that turned suspect in China
  3. A simple coding assistant at the heart of a tech diplomatic crisis
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: the profile of a tool that turned suspect in China

A simple coding assistant at the heart of a tech diplomatic crisis

Just a few months ago, Claude Code was, for most of the general public, just one coding tool among many, developed by the American company Anthropic to help developers write code faster using artificial intelligence. Since July 4, 2026, this tool has become the symbol of a major technological trust crisis between the United States and China, after Alibaba announced it was banning its use across its entire workforce starting July 10, 2026.

This profile sets out to tell the story of this tool, from its creation to its sudden fall from grace at one of China's largest tech conglomerates, while trying to untangle verified fact from still-unconfirmed accusation in an affair with obvious geopolitical ramifications.

Why this profile goes beyond simple tech news

Telling the story of Claude Code today is not just talking about a piece of software: it is telling the story of the growing distrust between the world's major tech powers, a distrust that now reaches even the most technical and, seemingly, most neutral tools in the daily lives of developers around the world.

I find it fascinating, and a little unsettling, to watch a simple coding tool become, within days, the symbol of a major technological rift between the West and China. It says a great deal about the current state of mutual trust between these two blocs.

The birth of Claude Code at Anthropic

A tool designed to revolutionize assisted programming

Claude Code was developed by Anthropic, the American artificial intelligence company founded by former OpenAI researchers, with the goal of giving developers an assistant capable of writing, fixing, and optimizing computer code autonomously or semi-autonomously. The tool sits within an increasingly intense global competition among tech companies to dominate the fast-growing market for AI-powered programming assistants.

The version of Claude Code at the center of this controversy, v2.1.91, was released on April 2, 2026, just months before computer security researchers discovered the mechanism that would trigger its fall in China.

Rapid adoption, including among Chinese developers

Before this controversy, Claude Code had seen rapid adoption among developers worldwide, including in China, despite the usual restrictions on access to American artificial intelligence tools. This popularity is precisely what explains why Alibaba's decision to ban the tool sent such shockwaves through China's tech industry, where many developers had woven this assistant into their daily workflow.

This rapid cross-border adoption also illustrates a reality that geopolitical tensions sometimes struggle to fully erase: the flow of the best-performing tech tools often ignores, in practice, the political borders that governments try to impose.

I note with some interest that even amid intense technological rivalry between China and the United States, the best tools almost always end up spreading anyway — proof that technical merit sometimes outruns even the most rigid geopolitical fault lines.

The discovery that triggered it all

The Reddit post that lit the fuse

It all started on June 30, 2026, when a Reddit user going by "LegitMichel777" published a detailed analysis claiming that Claude Code secretly checked users' time zones and proxy settings, comparing that information against a list of 147 Chinese domains tied to AI labs, before encoding the results steganographically into the prompts sent to Anthropic's servers.

This discovery, if confirmed under its most alarming interpretation, suggested that Claude Code could have served as a covert surveillance tool, capable of identifying Chinese users without their explicit consent — an accusation serious enough to trigger an immediate shockwave through China's tech industry the moment it was published.

Why this discovery seemed so credible at first

The initial credibility of this discovery rested largely on the technical precision of the published analysis, which detailed a verification mechanism sophisticated enough not to look like an unfounded theory. This apparent technical sophistication contributed heavily to the accusation's rapid spread across social media and the specialized international tech press.

In a climate already marked by growing technological distrust between China and the United States, such a discovery, even without official confirmation from an independent security audit, found especially fertile ground to spread quickly among China's most cautious tech decision-makers.

I remain cautious about this initial discovery: an analysis posted on Reddit, however detailed, is not on its own definitive proof of organized espionage. The rapid virality of an accusation never replaces the need for rigorous independent verification.

Anthropic's response to the accusations

What Thariq Shihipar publicly explained

Thariq Shihipar, an Anthropic engineer, responded publicly on the social network X, stating that this controversial mechanism came from "an experiment launched in March" 2026, meant to prevent "account abuse by unauthorized resellers" and to limit distillation — a technique that lets competitors train their own artificial intelligence models by exploiting responses generated by a rival model like Claude.

According to this explanation, the mechanism was not a geopolitical spying tool specifically targeting Chinese users, but a broader commercial protection measure aimed at limiting unauthorized exploitation of Anthropic's technology by parties seeking to profit from it without permission or proper compensation.

The quick removal of the controversial mechanism

Faced with the scale of the controversy, Anthropic removed this mechanism in its July 1, 2026 update, even before Alibaba's official ban announcement. This quick removal, while it does not erase the controversy already triggered, suggests a desire to defuse the crisis rather than keep a feature that had, in effect, become a major commercial liability for the company in the Asian market.

This speed of response contrasts with the continued absence, to date, of a genuinely independent security audit capable of definitively confirming or ruling out the most alarming interpretation originally put forward by the community of developers who uncovered this technical finding.

I note that Anthropic's explanation, while commercially plausible, does not fully dispel the unease: why target specifically Chinese domains rather than a broader list of suspected resellers worldwide, with no particular geographic distinction?

The backdrop of the Anthropic-Alibaba feud over distillation

An earlier accusation by Anthropic against Qwen

To fully understand this affair, one has to go back to an earlier accusation made by Anthropic against Alibaba'sQwen lab, accused of orchestrating a massive distillation campaign between April 22 and June 5, 2026, involving roughly 25,000 fraudulent accounts and nearly 28.8 million conversations exploited to train rival Chinese models without authorization.

This earlier accusation directly sheds light on the controversial mechanism discovered in Claude Code: following Anthropic's explanation, this verification system was supposedly aimed precisely at countering this kind of large-scale distillation campaign, rather than indiscriminately spying on Chinese users for geopolitical reasons.

A commercial rivalry that goes beyond the Claude Code case alone

This rivalry between Anthropic and Alibaba'sQwen lab illustrates a broader tension now running through the entire global artificial intelligence industry: the widely shared fear among American companies that their most advanced models will be exploited by Chinese competitors to accelerate their own technological development without comparable investment in fundamental research.

This dynamic of mutual distrust, in which each side accuses the other of unfair practices, considerably complicates any attempt to objectively defuse the current controversy around Claude Code, with each party having an interest in framing the facts in whatever light is most favorable to its own position.

I believe this commercial rivalry, however legitimate from Anthropic's point of view, does not necessarily justify deploying such an opaque mechanism without clearly informing the users affected beforehand.

Alibaba's reaction to the perceived risk

A ban classified as a high security risk

Alibaba classified Claude Code as internal "high-risk software," citing potential backdoor risk, and ordered its entire workforce to stop using the tool as of July 10, 2026. This decision, made in the middle of the controversy and before an independent security audit had even concluded, illustrates how quickly a major tech company can react to a perceived threat, even one that is not fully confirmed.

Affected employees were told to switch instead to Qoder, the AI-assisted programming tool developed in-house by Alibaba — a substitution that also serves, more or less explicitly, the Chinese group's own commercial interests in its competition with equivalent Western tools.

A decision that also serves clear commercial interests

It would be naive to ignore that this ban, however justified by legitimate security concerns, also serves Alibaba's direct commercial interests by redirecting thousands of its developer employees toward its own Qoder tool rather than toward an American competitor that has suddenly become suspect in the eyes of the group's leadership.

This overlap between a legitimate security concern and a direct commercial interest does not necessarily discredit Alibaba's decision, but it calls for a more nuanced reading than a simple opposition between security and commercial recklessness in an affair with multiple motives.

I notice that the solution proposed by Alibaba, namely switching to its own Qoder tool, arrives conveniently for its commercial interests. That does not make the security concern illegitimate, but it deserves to be examined with this dual motive in mind.

What cybersecurity experts really think

The absence of a definitive independent audit

To date, no genuinely independent security audit has confirmed with certainty the most alarming interpretation of the original discovery — namely, a deliberate espionage mechanism specifically targeting Chinese users for geopolitical rather than commercial reasons. This lack of independent confirmation is an important limitation worth stating plainly in this profile.

Several cybersecurity experts, cited by the specialized tech press, are urging caution, noting that the line between a legitimate measure against commercial abuse and a geopolitical surveillance mechanism can sometimes look technically similar, without the real intent behind its deployment always being easy to establish with absolute certainty.

Why technological transparency remains a major issue

This affair illustrates a broader issue that goes well beyond the Claude Code case alone: the need for companies building widely used artificial intelligence tools to communicate far more transparently about the data collection and verification mechanisms built into their products, before those mechanisms get discovered by accident by outside users.

Without this stronger transparency, this kind of controversy risks repeating itself regularly, fueling growing technological distrust that ultimately harms the entire industry, including Western companies that never intended any harm to their international users.

I believe this initial lack of transparency, far more than the mechanism itself, is Anthropic's real failing in this affair. Technological trust is built through clarity, not through the accidental discovery of hidden mechanisms.

What this affair reveals about the global tech fracture

A distrust spreading to every technological tool

This controversy around Claude Code fits into a broader trend of growing technological distrust between major world powers, where every tool, every app, and every digital service built by a rival country becomes potentially suspect in the eyes of the other side, regardless of the precise technical reality of each individual case.

This dynamic of generalized suspicion, if it continues and intensifies, risks further fragmenting the global tech ecosystem, with potentially negative consequences for the collaborative innovation that has long defined the development of artificial intelligence on an international scale.

Why the West must stay vigilant without slipping into paranoia

Facing this growing tech fracture, the West must maintain serious vigilance against real risks of technological surveillance or espionage from rivals like China, while avoiding a slide into blanket paranoia that would hurt its own capacity for innovation and legitimate international collaboration in artificial intelligence.

This delicate balance between necessary vigilance and reasonable technological openness is, in my view, one of the most important challenges Western democracies will have to face in the coming years amid China's rising tech power.

I believe the West absolutely must keep a technological lead over China, but that vigilance must never turn into blanket distrust that would paralyze our own capacity for international collaborative innovation.

The real-world impact on Chinese developers

A forced transition to less mature tools

For the thousands of developers employed by Alibaba, this ban means a sometimes abrupt transition to Qoder, an in-house tool still less proven on the international market than Claude Code, which could temporarily hurt the productivity of technical teams that had spent months relying on the now-banned American tool within the group's work environment.

This forced transition concretely illustrates the human and operational cost of tech-driven geopolitical tensions — a cost that ultimately falls on ordinary employees, forced to quickly adapt to new tools for reasons that go well beyond their individual control or personal professional preferences.

A precedent that could spread to other Chinese companies

This decision by Alibaba could well set a precedent followed by other major Chinese tech companies, now prompted to reassess their own use of American artificial intelligence tools in light of this controversy, even without definitive proof of a similar espionage mechanism in other comparable products on the market.

This potential chain reaction shows how a single technical controversy, even one later partially explained, can have lasting repercussions on the trust extended to an entire category of tech tools coming from a rival country on the global geopolitical chessboard.

I worry about seeing this affair potentially turn into a broad precedent, where every Chinese company preemptively bans American tools on the sole basis of unconfirmed suspicion, at the expense of their own employees' productivity.

What this story says about Anthropic as a company

A company caught between commercial ambition and ethical responsibility

Anthropic, founded on the promise of more responsible and safer artificial intelligence development compared to some of its competitors, now finds itself facing a controversy that directly questions its own internal ethical consistency, caught between its public rhetoric on safety and transparency and an opaque mechanism deployed without clear communication to its international users.

This apparent contradiction, if not resolved quickly and clearly through more transparent communication from Anthropic, could durably weaken the company's reputation in the international market, particularly among users already wary of major American tech companies and their data collection practices.

A missed opportunity for proactive transparency

In hindsight, it appears Anthropic could have avoided much of this controversy by proactively communicating, as early as this experimental mechanism's launch in March 2026, about its existence and precise goals, rather than letting a community of outside developers discover it by accident months later, under circumstances far more damaging to the company's image.

This missed opportunity for proactive transparency is, in my view, the real lesson of this affair for the entire artificial intelligence industry, far beyond the specific case of Claude Code and its particular controversy with Alibaba.

I believe this affair will stand as a textbook case on the dangers of silence around sensitive technology. Proactive transparency sometimes costs a lot in the short term, but it always costs far more when it is missing at the moment of a trust crisis.

The questions that remain without a definitive answer

What we still do not know for certain

Despite the explanation provided by Thariq Shihipar on Anthropic's behalf, several questions remain unanswered and independently unverifiable: why did this mechanism specifically target a list of 147 Chinese domains rather than a broader, geographically neutral approach, and why was the collected information encoded steganographically rather than transmitted in a more transparent way, directly verifiable by outside parties.

These precise technical questions deserve a more detailed answer from Anthropic than the general explanation offered so far, if the company genuinely wants to fully restore trust with its international user base, including those based outside China.

Why this affair is probably not over yet

Given the scale of the controversy and the persistent absence of a genuinely independent security audit, this affair will likely remain under close scrutiny in the weeks and months ahead, potentially from independent cybersecurity researchers or tech regulators in several countries affected by this international controversy.

This profile, at this stage, can therefore only note the facts known and documented so far, without prejudging future conclusions that could still significantly change the current understanding of this complex and evolving technological affair.

I would rather close this profile on a note of methodological honesty: some questions remain open, and I refuse to pretend to hold certainties that even the most qualified cybersecurity experts have not yet established with absolute certainty.

Why this affair matters for the future of Western AI

A credibility test for the American AI industry

This controversy around Claude Code represents an important credibility test for the entire American artificial intelligence industry, at a moment when global tech competition with China is intensifying on practically every front, from fundamental research to the most concrete commercial applications used daily by millions of users worldwide.

If American artificial intelligence companies want to keep positioning themselves as trustworthy tech partners on a global scale, they will need to demonstrate, through concrete action and stronger transparency, that they deserve the trust this kind of controversy is precisely eroding among the most cautious international users.

The bigger stakes of the West-China tech race

Beyond the Claude Code case alone, this affair illustrates the bigger stakes of the technological race between the West and China in artificial intelligence, a field I personally consider absolutely decisive for the global geopolitical balance of the coming decades, far beyond the immediate commercial considerations of any single company involved.

It is now up to Western companies, and to Anthropic in particular in this specific case, to prove that their technological lead comes paired with enough ethical responsibility and transparency to justify the trust the whole world, despite everything, continues to place in them.

I close this profile with a strong personal conviction: the West must win this technological race against China, but it can only win it lastingly by proving an ethical edge as solid as its current technical edge.

The role of social media in accelerating the crisis

How a technical discovery goes viral within hours

This affair also illustrates the blistering speed at which a technical discovery posted on a platform like Reddit can turn into a major international crisis within just a few days. The original post by "LegitMichel777" was massively shared on X and across the specialized tech press before Anthropic even had time to draft a detailed official response.

This viral acceleration dynamic, characteristic of today's media ecosystem, often leaves companies very little time to respond thoughtfully, sometimes pushing them to react under pressure rather than with the methodical transparency that an accusation as serious as the one leveled against Claude Code would normally require.

The limits of tech journalism in this kind of affair

This affair also raises a broader question about the ability of tech journalism to independently verify accusations as technical as the one made against Claude Code, within a timeframe short enough to properly inform the public before the controversy grows disproportionate to the facts actually established at this stage of the investigation.

This structural limitation of contemporary tech journalism, faced with subjects requiring deep cybersecurity expertise, partly explains why so many outlets simply relayed the initial accusation without always giving it the methodological caution it deserved from the outset.

I include myself in this critical reflection: as a columnist, I must resist the temptation to relay a viral accusation without giving it enough context, even when the urgency of the news cycle pushes toward speed rather than caution.

What this affair changes for Western users of Claude Code

Trust shaken even outside China

While this controversy mainly concerns Claude Code's Chinese users, it has also shaken the confidence of some Western users, who now wonder whether other, still-undiscovered mechanisms might also be collecting data without their knowledge as part of their own daily use of the tool.

This concern, even though it is backed by no specific evidence regarding Western users, shows just how fragile technological trust remains and how it can spread beyond the group directly targeted by an initial controversy, ultimately affecting the overall reputation of a product used widely around the world.

What Anthropic should do to fully restore trust

To fully restore the trust of its entire international user base, Anthropic would be well served by voluntarily commissioning a complete independent security audit of Claude Code, with the results published in full, rather than settling for a public explanation unverified by qualified independent cybersecurity parties.

This proactive step, if taken quickly, could turn this trust crisis into an opportunity to demonstrate genuine commitment to transparency, rather than letting this controversy sink into a lingering ambiguity that keeps feeding the distrust of the world's most cautious users.

I believe Anthropic still has a window of opportunity to turn this crisis into proof of good faith, provided it acts quickly with a full independent audit rather than letting doubt take lasting root among its users.

Conclusion: a profile that reveals today's tech tensions

What this affair teaches us collectively

The profile of Claude Code, from its promising creation at Anthropic to its sudden ban at Alibaba, perfectly illustrates the fragility of international technological trust in an era of intense geopolitical rivalry between the United States and China. A technical mechanism, initially designed for legitimate commercial reasons according to Anthropic, turned within days into a symbol of a much broader and much deeper distrust.

What to keep watching in the coming months

The coming months will determine whether this controversy remains an isolated incident, quickly forgotten once a corrected version of Claude Code is widely adopted, or whether it instead marks the start of a more lasting technological fragmentation between the American and Chinese artificial intelligence ecosystems — a fragmentation whose consequences would extend well beyond the case of this one programming tool that has, despite itself, become a geopolitical symbol.

I close this profile with one certainty: the next episode of this technological rivalry between the West and China will not be long in coming. Claude Code was probably just the first visible symbol of a far deeper and more lasting distrust.

By Maxime Marquette, columnist

Columnist's transparency note

Who I am and my working method

I sign this profile as Maxime Marquette, columnist for MadMax, with an openly stated position in favor of Western technological leadership over China. This profile draws on specialized technology and cybersecurity journalism, as well as public statements from Anthropic and press reporting on Alibaba's decision.

My acknowledged limits

I am not a cybersecurity expert and cannot myself fully assess the technical validity of the original discovery posted on Reddit. In the absence of a definitive independent security audit, I limit myself to reporting the established facts and the explanations offered by the parties involved, without personally ruling on the real intent behind this controversial mechanism.

Sources

Primary sources

Gigazine — Alibaba bans Claude Code, July 4, 2026

South China Morning Post — Alibaba bans staff using Claude Code over Anthropic spyware concerns

Secondary sources

Reuters — Alibaba to ban Claude Code in workplace over alleged backdoor risks, July 3, 2026

TechCrunch — Alibaba reportedly bans employees from using Claude Code, July 4, 2026

Tom's Hardware — Alibaba bans Anthropic's Claude Code after alleged hidden China detection backdoor uncovered

The Register — Anthropic is removing its covert code for catching Chinese competitors, July 1, 2026

Get the tech columns

AI, platforms, digital power: the next analyses straight to your inbox.

Cite this article

Maxime Marquette (2026). Claude Code, the tool Alibaba is banning over backdoor fears. MadMax. https://mad-max.co/en/article/claude-code-l-outil-qu-alibaba-bannit-par-peur-d-une-porte-derobee

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Profile3876 words20 min read