China's Ministry of Industry and Information Technology cybersecurity platform found serious security backdoor risks in Anthropic's AI coding tool Claude Code versions 2.1.91 to 2.1.196. The tool could transmit users' geographic location and identity information without their consent, posing a serious threat, according to the National Vulnerability Database in China [1, 2, 3, 4, 5, 6].

The cybersecurity platform advised users and organizations to immediately uninstall the affected versions or upgrade to the latest release, which removed the backdoor code. Claude Code version 2.1.200 was released on July 3, 2026, addressing these issues by deleting the problematic code [2, 3, 7, 4, 5, 6].

Alibaba, citing these security risks, banned employee use of Anthropic's Claude Code internally starting July 10, 2026. The Chinese tech giant labeled the software as high-risk and required staff to uninstall all Anthropic models and agent products. Alibaba recommended its own AI assistant tool Qoder as the replacement for internal use [1, 2, 8, 9, 5, 6].

Anthropic described the backdoor mechanism as an experimental anti-abuse feature designed to prevent unauthorized distillation—the illegal extraction of its model capabilities—especially targeting users in China. The company’s terms of service prohibit Chinese companies and adversarial nations from accessing Claude Code [1, 8, 9, 6].

In June 2026, Anthropic sent a letter to the US Senate accusing Alibaba of launching the largest known distillation attack on its models, alleging nearly 25,000 fraudulent accounts were used to scrape Claude data and generate over 28 million exchanges. Despite these restrictions, Chinese developers have continued to use Claude Code unofficially [8, 3, 7, 9, 6].

Alibaba’s internal ban requires employees to uninstall Anthropic’s products and switch to in-house AI tools by July 10, 2026. The Chinese cybersecurity platform issued its public warning on July 8, 2026, urging immediate removal or upgrade of vulnerable versions [1, 2, 8, 9, 5, 6].