🤚 The Open-Palm Recap
In a move that redefines the concept of audacity, Alibaba has classified Anthropic’s Claude Code as high-risk software and will prohibit all employees from using it effective July 10, 2026. The reason? Reports surfaced that Claude Code contained functionality designed to identify Chinese users.
If this sounds familiar, it is because five days ago, Slap of Wisdom covered Anthropic’s revelation that Alibaba had run 25,000 fake accounts through Claude, generating 28.8 million unauthorized exchanges in what Anthropic called the largest AI distillation attack in history. Alibaba was using Claude’s outputs to train its own competing models — a practice roughly equivalent to photocopying someone else’s exam and then complaining about the surveillance camera in the testing center.
Anthropic’s Thariq Shihipar confirmed that the user-identification feature was “an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation.” He added that the team had “landed stronger mitigations since then” and they had “actually been meaning to take this down for a while” — the corporate equivalent of saying the security camera was going to be removed anyway, you just happened to notice it first.
Alibaba is directing its workforce to use Qoder, the company’s proprietary coding tool, as a replacement.
👐 The Two-Handed Irony
The timeline of the Alibaba-Anthropic relationship deserves to be preserved in a museum of corporate pettiness:
- March 2026: Anthropic launches a user-identification experiment to detect unauthorized access and distillation
- Late June 2026: Anthropic publicly reveals that Alibaba ran 28.8 million unauthorized queries through 25,000 fake accounts, calling it the largest AI distillation attack in history
- Early July 2026: Alibaba discovers that Claude Code could identify Chinese users
- July 5, 2026: Alibaba bans Claude Code, citing it as “high-risk software”
To summarize: Alibaba used 25,000 fake accounts to systematically extract Anthropic’s intellectual property. Anthropic built detection tools to stop exactly this kind of abuse. Alibaba found the detection tools. Alibaba is now offended.
This is the technological equivalent of a shoplifter demanding to speak with the manager about the store’s anti-theft tags. The customer was stealing the merchandise, the store installed cameras, and now the customer has banned the store.
Anthropic, for its part, has handled this with the diplomatic restraint of a company that simultaneously needs to condemn intellectual property theft while also maintaining access to the world’s second-largest economy. Shihipar’s statement that they were “meaning to take this down for a while” is masterful — it neither apologizes nor doubles down, a rhetorical Switzerland that acknowledges the detection feature existed without conceding that detection was inappropriate.
🌿 The Gentle Awakening
The deeper story here is not about Alibaba or Anthropic. It is about the fundamental absurdity of the current AI geopolitical landscape, where every major model provider simultaneously wants to:
- Sell access to every developer on earth
- Prevent certain developers from using that access to clone the product
- Avoid identifying which developers are which, because identification is “surveillance”
- Identify which developers are which, because distillation is “theft”
These four objectives are mutually exclusive, and yet every AI company is pursuing all four simultaneously with the confidence of someone who has never heard the word “contradiction.”
Alibaba’s pivot to Qoder is the predictable outcome. When you can no longer copy the exam, you write your own — which, given that Qoder was likely trained in part on outputs distilled from Claude and its competitors, means the original copying is now baked permanently into the replacement product. The distillation attack didn’t fail. It succeeded so thoroughly that the stolen intelligence is now the foundation of the tool that replaces the victim.
👑 The Gold-Leaf Reckoning
The U.S.-China AI cold war has officially entered its pettiest phase. Anthropic builds detection tools. Alibaba bans the product. The Senate takes notes. The models get trained on each other’s outputs in an endless loop of recursive intellectual property disputes that no court in any jurisdiction has the technical literacy to adjudicate.
Meanwhile, the 25,000 fake accounts generated 28.8 million training exchanges before anyone noticed. The distillation is done. The horse has not only left the barn — it has been reverse-engineered, fine-tuned, and is now offering rides in Hangzhou under a different name.
Alibaba banning Claude Code is not a security decision. It is a press release disguised as a policy — a public declaration that the relationship is over, delivered with the theatrical indignation of someone who started the fight. Anthropic will continue blocking Chinese entities. Alibaba will continue building Qoder. And both companies will continue pretending that the 28.8 million exchanges never happened, except in court filings and earnings calls where they become either “unauthorized distillation” or “competitive research,” depending on which legal team is speaking.
The only party that benefits from this escalation is the concept of irony itself, which has never had a better year.
“We used 25,000 fake accounts to extract 28.8 million training examples, and frankly we are appalled to discover that the other side was keeping track.” — The Slap of Wisdom International Relations Bureau, drafting a formal complaint about the security camera it walked past twelve million times