Vivold Consulting

A reverse-engineered tracking experiment hands Alibaba cause to ban Anthropic tools and push its own Qoder - dev stacks are now geopolitical

Key Insights

Alibaba has banned employees from using Anthropic's Claude Code from July 10, classifying it as high-risk software and directing staff to its in-house Qoder tool instead - some reports say the directive extends to uninstalling all Anthropic products. The trigger: a June 30 Reddit reverse-engineering post revealed the tool had quietly shipped code since April that checked for signs a user was in China (timezones, proxies, AI-lab infrastructure); an Anthropic engineer called it an anti-reseller, anti-distillation experiment that has since been removed. The backdrop is an open feud - Anthropic accused operators tied to Alibaba's Qwen lab of running a 28.8-million-exchange distillation attack via ~25,000 fraudulent accounts.

Stay Updated

Get the latest insights delivered to your inbox

A ban years in the making, triggered in a week

Alibaba has told employees to stop using Anthropic's Claude Code for work as of July 10, adding it to an internal list of high-risk software with security vulnerabilities after what the company called a comprehensive evaluation, according to an internal notice seen by the South China Morning Post. Staff are being directed to Alibaba's own coding assistant, Qoder, and reports citing company insiders say the guidance goes further - instructing removal of Anthropic products generally. The proximate cause: a June 30 post on Reddit in which a developer who reverse-engineered Claude Code reported obfuscated detection logic shipping silently since version 2.1.91 in early April - checks for Chinese timezones, proxy servers, and AI-lab network characteristics, with identifying markers embedded in data sent back to Anthropic. An Anthropic engineer publicly described it as a March experiment to prevent account abuse by unauthorised resellers and protect against distillation, adding that stronger mitigations had landed since and the code was slated for removal.

The feud behind the security story

Context makes this less a surprise than an escalation. Anthropic already prohibits Chinese companies (and their foreign-owned entities) from using its models, and last month it went to the US Senate accusing operators affiliated with Alibaba's Qwen lab of the largest known model-distillation attack against Claude - roughly 25,000 fraudulent accounts generating 28.8 million exchanges between late April and early June. Alibaba's counter-accusation of spyware, and its shove toward Qoder, completes a cycle in which each side's security claim doubles as industrial policy. Notably, Microsoft had already dropped internal Claude Code licences in May - for cost, not politics - a reminder that tool standardisation decisions are piling up for many reasons at once.

What this means for your dev stack

- The uncomfortable general lesson: your coding agent is a telemetry channel. Whatever the intent, Claude Code shipped undisclosed environment-fingerprinting logic - so if you operate in a regulated or IP-sensitive environment, put AI dev tools through the same egress and supply-chain review as any other software with network access, and monitor what they transmit.
- For multinationals with China operations, assume the tooling split is permanent: US frontier tools on one side, domestic mandates (Qoder, Qwen-based stacks) on the other. Standardise per-region toolchains now, with code-review and CI practices that keep output quality comparable across both.
- Vendor-trust playbook: ask your AI tooling providers directly what client-side detection or fingerprinting their software performs and where it is disclosed. Anthropic's experiment was arguably defensible anti-abuse engineering - but undisclosed is undisclosed, and this episode is your leverage to demand contractual transparency.

Related Articles

Discovery Loop aims to automate science itself - and Google is funding the startup draining its own bench, as Hassabis exits the DeepMind CEO role

Jeff Dean, Google's chief scientist and 30th employee, is leaving after 27 years to found Discovery Loop, a public benefit corporation using AI to automate scientific research - taking co-founders Sanjay Ghemawat, Quoc Le (Google Brain), and Oriol Vinyals (DeepMind) with him. Google is a founding investor and cloud partner, supplying compute for at least the first year, with Radical Ventures and Khosla Ventures co-leading the seed. In the same announcement, Demis Hassabis steps down as DeepMind CEO to become chairman and Alphabet chief scientist, with Koray Kavukcuoglu taking over Gemini model development. Alphabet stock fell about 4%.

Abbott orders audits of every new project as ERCOT's queue hits 474GW, roughly 90% of it data centres

Governor Greg Abbott announced that all new Texas data-centre projects must be audited by the Public Utility Commission and grid operator ERCOT - a sharp turn for a state whose loose regulation and cheap power made it second only to Virginia for data centres. The trigger is a staggering queue: ERCOT's interconnection requests doubled from 233GW in January to 474GW, about 90% data centres, more than five times the grid's all-time peak demand. Audits will demand power and water use, noise mitigation, light controls, tax-incentive use, and ownership details - after a voluntary survey that most operators simply ignored.

Volta and Bitdeer will build a 133MW Nvidia Vera Rubin data centre in Norway - Anthropic's latest move in a compute land grab

Anthropic has reportedly signed a $10 billion, six-year compute deal with Volta, an AI cloud startup founded only earlier this year, per Bloomberg. Volta is partnering with crypto-mining firm Bitdeer to develop the data centre - located in Norway, delivering 133 megawatts, and running Nvidia's Vera Rubin architecture - and is a member of Nvidia's Cloud Partner programme. It caps an aggressive capacity spree that also includes recent compute deals with SpaceX and Amazon, as Anthropic races rivals for the scarcest input in the industry.