On July 3, Alibaba told its employees they had one week to stop using Claude Code and every Anthropic product. The ban kicks in on July 10.
That’s the headline. But if you’ve been watching this space, you know something bigger is moving underneath.

① Claude Code Has Had a Rough 2026
If you work with Claude Code the way I do, you’ve probably heard about these already. Let me lay them out anyway because they matter:
February. Check Point published findings on two critical RCE vulnerabilities. CVE-2025-59536 scored 8.7 out of 10. The scary part: you don’t have to do anything stupid. Just open a malicious repository, and your API keys are gone. For a tool that lives inside your development environment, that’s as bad as it gets.
March. Someone posted internal Anthropic source code publicly — including KAIROS, a system that never shipped. When a major AI company’s unreleased Agent code shows up on forums, developers pay attention. So does everyone else.
June. Reports started circulating that Claude Code had fingerprinting logic targeting Chinese users. Anthropic hasn’t confirmed this. But the company’s track record on these issues — combined with everything else — was enough to move the conversation.
Three serious incidents in under a year. At the permission level these tools operate, that’s not bad luck. That’s a pattern.
② The Timing Doesn’t Add Up as Coincidence
I put these side by side and stopped being impressed by the official explanation:
- June 24 — Anthropic wrote to the U.S. Senate Banking Committee, saying Alibaba ran 28 million “distillation attacks” through 25,000 accounts
- June 24 — Alibaba sued the U.S. Department of Defense, trying to get off the “Chinese Military Companies” list
- July 3 — Alibaba announced the Claude Code ban
- July 10 — The ban takes effect
Ten days. Four escalations. I don’t believe in coincidence at this scale.

Forrester VP Dai Kun called it “a landmark event in U.S.-China tech competition entering deep water.” Angel investor Guo Tao put it more plainly — “data security, compliance risk control, and autonomous transformation all rolled into one decision.”
My take: the security argument is real. It’s not complete. In a trade war, cautious risk management and strategic posturing look exactly the same from the outside. That’s not a conspiracy theory. That’s just how corporate decisions work when two superpowers are in the room.
③ Qoder Didn’t Appear Out of Nowhere
Before this ban, I’d already had Qoder on my radar. Here’s what I found:
- Launched August 2025
- Reached 5 million+ users by May 2026
- Supports MCP Server, Subagent, and Hooks — the modern AI coding stack
Five million users in nine months. In this space, that number doesn’t lie. Developers chose it, which means it was doing something right before Alibaba made it a company-wide mandate.

Here’s the part worth paying attention to: Qoder keeps code and data inside Alibaba Cloud’s domestic infrastructure. For companies handling anything sensitive, this isn’t a marketing line — it’s a concrete technical property that shows up in procurement conversations.
Alibaba Cloud’s Liu Weiguang has said AI coding will handle “almost everything” in enterprise work. The enterprise IT outsourcing budget is the prize, and every major cloud provider knows it.
So What Do I Make of All This?
Let me be direct about a few things.
The security concern behind this ban is grounded in documented incidents. Whether those incidents justify a full company-wide ban is a judgment call — I don’t think there’s an objective answer here; it depends on what your risk tolerance looks like. But the concern itself isn’t made up.
On Anthropic’s “distillation attack” accusations: they used the same framing against DeepSeek, Moonshot, and MiniMax back in February. I can’t verify what’s actually going on from the outside. What I can tell you is that the cycle itself — accuse, deny, go to press — is already a business risk that any company has to factor in, regardless of who turns out to be right.
The bigger picture: Tech giants based in China — Tencent, ByteDance, Huawei, Meituan, JD.com — are all building out their own AI tooling stacks. This isn’t Alibaba making a solo move. It’s the whole sector rethinking how it wants to depend on outside platforms.
If you’re a developer choosing tools today, here’s what actually matters: business fit, data security posture, and whether the ecosystem around a tool is stable. The “domestic vs. foreign” frame is the wrong way to think about it. But here’s the practical reality — keeping data in-country has gone from a nice-to-have to a baseline requirement in this environment. Call it risk management, call it whatever you want. It’s just the landscape right now.
Alibaba framed this as a security decision. It is one. It’s also something else. The U.S.-China AI tooling decoupling just moved from something people talked about into something companies are doing. If you build with AI tools, you should know what your stack depends on — because the map just changed.