Reuters confirmed today that Alibaba will ban employees from using Claude Code in workplace environments starting July 10, citing alleged security risks involving embedded backdoors. The recommended replacement: Alibaba's own Qoder. The specific allegation, surfaced by developers through reverse engineering, is detailed enough to take seriously even if unverified. According to developers who reverse-engineered version 2.1.91, Claude Code allegedly scans your proxy or API endpoints for keywords linked to Chinese AI companies — Alibaba, ByteDance, Baidu, and others. If matched, it silently modifies the system prompt using visually identical Unicode characters to encode what it found, then transmits those altered prompts back to Anthropic's servers. No notification. No pop-up. Anthropic has not responded to the allegations. The claims have not been independently verified by a third party. Two things can be true at once: the technical description is specific enough to be credible, and specific enough to be fabricated. Reverse engineering claims in geopolitically charged contexts have a history of being both — sometimes simultaneously. What's not in dispute: Alibaba made a corporate decision, Media reported it, and Claude Code now has a trust problem in China regardless of whether the underlying allegations hold up.
阿里巴巴禁员工使用Claude Code,逆向工程指控其含后门扫描中文AI公司
AI 导读
路透社确认,阿里巴巴将从7月10日起禁止员工在工作环境使用Claude Code,推荐使用自研Qoder。开发者逆向v2.1.91版本发现,Claude Code会扫描代理/API端点中与中国AI公司(阿里、字节、百度等)相关的关键词,一旦匹配则静默修改系统提示,用视觉相同Unicode字符编码后传回Anthropic服务器,无任何通知。Anthropic尚未回应,指控未获第三方独立验证。Claude Code在中国已面临信任危机。
69
AI 编辑部评分,满分 100阿里巴巴禁员工使用Claude Code,逆向工程指控其含后门扫描中文AI公司
路透社确认,阿里巴巴将从7月10日起禁止员工在工作环境使用Claude Code,推荐使用自研Qoder。开发者逆向v2.1.91版本发现,Claude Code会扫描代理/API端点中与中国AI公司(阿里、字节、百度等)相关的关键词,一旦匹配则静默修改系统提示,用视觉相同Unicode字符编码后传回Anthropic服务器,无任何通知。Anthropic尚未回应,指控未获第三方独立验证。Claude Code在中国已面临信任危机。
来源:X.PIN· x.com