---
title: "What the Alibaba–Claude Distillation Fight Looks Like From Inside China"
date: 2026-08-26
originalDate: 2026-07-03
originalTitle: "阿里偷了Claude，后果由你来承担"
issue: "Issue 1"
description: "The Alibaba–Anthropic distillation fight as Chinese netizens saw it: timeline, account bans, and the one-line summary — translated, sources cross-checked."
tags:
  - "Alibaba"
  - "Anthropic"
  - "Qwen"
  - "Claude"
  - "Distillation"
  - "China AI"
sources:
  - label: "Reuters: Anthropic says Alibaba illicitly extracted Claude capabilities (2026-06-24)"
    url: "https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/"
  - label: "Washington Post: why Anthropic alleges Chinese firms are distilling Claude (2026-07-06)"
    url: "https://www.washingtonpost.com/national-security/2026/07/06/why-anthropic-alleges-chinese-firms-are-distilling-knowledge-claude/"
  - label: "Tom's Hardware: Alibaba bans Claude Code; employees switch to Qoder"
    url: "https://www.tomshardware.com/tech-industry/artificial-intelligence/alibaba-bans-anthropics-claude-code-after-an-alleged-hidden-china-detection-backdoor-is-uncovered-employees-told-to-switch-to-qoder-as-the-rift-between-the-firms-widens"
faq:
  - q: "What did Anthropic accuse Alibaba of in June 2026?"
    a: "In a June 10, 2026 letter to US senators, Anthropic alleged Alibaba's Qwen team ran the largest known distillation operation against Claude: roughly 25,000 fake accounts making 28.8 million requests between April 22 and June 5, 2026 (Reuters). Anthropic later said it had banned nearly 700,000 accounts using Claude in China (Washington Post)."
  - q: "Did Alibaba ban Claude Code?"
    a: "Yes. An internal notice dated July 3, 2026 [unverified, from the Chinese original] told staff to uninstall Claude Code by July 10, citing security risks including an alleged hidden China-detection mechanism; employees were directed to Alibaba's own Qoder tool (Tom's Hardware corroborates the July 10 deadline and Qoder switch)."
  - q: "How did Chinese netizens react to the Alibaba–Claude dispute?"
    a: "The take our essay captured: the saga distilled into one savage line — steal something, get caught, then declare the stolen goods poisoned and swear off stealing. The essay's harder point: Alibaba has its own stack (Qwen3.7-Max, Qoder with a claimed 5M+ users), so 25,000 fake accounts over 44 days read as insiders knowing the gap with Claude is real."
---
On June 10, 2026, Anthropic alleged in a letter to US senators that Alibaba's Qwen team ran what it called the largest-ever distillation operation against Claude — roughly 25,000 fake accounts making 28.8 million requests between April 22 and June 5 (Reuters). Weeks later, an internal Alibaba notice dated July 3 [unverified, from the Chinese original] banned staff use of Claude Code by July 10, citing security risks — a move Chinese commentators read as cover. English coverage adds the scale of collateral damage: Anthropic says it has banned nearly 700,000 accounts using Claude in China (Washington Post).

## The numbers

- 2026-06-10 — Anthropic letter to US senators (Reuters)
- 2026-04-22 to 06-05 — 44-day window of the alleged request campaign (Reuters)
- ~25,000 fake accounts; 28.8 million requests (Reuters)
- ~650,000 requests per day average (derived from the above)
- ~700,000 China-region accounts banned by Anthropic (Washington Post)
- 2026-07-03 — internal Alibaba notice banning Claude Code [unverified, from the Chinese original]
- 2026-07-10 — uninstall deadline; staff directed to Qoder (Tom's Hardware)
- Qoder: launched August 2025, official claim of 5M+ global users [unverified]
- Prior Claude Code security incidents cited in the essay: early-2025 bricking bug, February 2026 RCE flaws (CVE-2025-59536, CVE-2026-21852), March 2026 source-code leak [unverified as a set]

## The take inside China

The Chinese internet distilled this saga into one savage line: you steal something, get caught, then announce the stolen goods are poisoned and swear off stealing. That is how many Chinese netizens read Alibaba's July move — banning Claude Code company-wide for "backdoor risks" weeks after Anthropic accused the Qwen team of history's biggest distillation attack.

The essay leans on the timeline. For over a year, Claude Code had known security incidents — a bricking bug in early 2025, RCE flaws in February 2026, a March source-code leak [unverified as a set] — and Alibaba didn't ban it; the essay claims the company even reimbursed employees for using it as a high-frequency coding tool. Then the accusation lands, and suddenly Claude is "high-risk software" requiring uninstall. As the essay puts it: while distilling, Claude was worth paying for; once caught, it became toxic. PR-smart, technically a confession.

The bitterest irony, the essay argues: Alibaba has its own stack — Qwen3.7-Max, and Qoder, its agentic coding platform with a claimed 5 million users. So why run 25,000 fake accounts for 44 days? Only one explanation: insiders know the gap with Claude is real. Mouths say "we're strong"; behavior doesn't lie.

The real casualties, per the essay: ordinary users reportedly couldn't log into Claude at all in Hangzhou — one login on Hangzhou Wi-Fi might get an account permanently banned [unverified]. And China's hard-won reputational gains from Huawei, DJI, and BYD took a hit overnight. The essay's prescription: open source is not a license to loot; admit the gap; contract-spirit is the price of global entry.

## Why it matters outside

This is the highest-profile distillation dispute yet, and it shows frontier-lab defenses now have real collateral damage — regional account bans that can lock out innocent users by the hundreds of thousands. It also signals that competitive gaps between Chinese and Western labs may be papered over by ToS-violating data harvesting, which will subject every Chinese model export to extra scrutiny. Expect tighter API access controls and heavier fingerprinting of bulk query patterns.

## Sources

- [Reuters: Anthropic says Alibaba illicitly extracted Claude AI model capabilities](https://www.reuters.com/world/china/anthropic-says-alibaba-illicitly-extracted-claude-ai-model-capabilities-2026-06-24/)
- [Washington Post: why Anthropic alleges Chinese firms are distilling Claude](https://www.washingtonpost.com/national-security/2026/07/06/why-anthropic-alleges-chinese-firms-are-distilling-knowledge-claude/)
- [Tom's Hardware: Alibaba bans Claude Code; employees told to switch to Qoder](https://www.tomshardware.com/tech-industry/artificial-intelligence/alibaba-bans-anthropics-claude-code-after-an-alleged-hidden-china-detection-backdoor-is-uncovered-employees-told-to-switch-to-qoder-as-the-rift-between-the-firms-widens)

> **Provenance & disclosure.** Originally published in Chinese on our WeChat channel on 2026-07-03 ("阿里偷了Claude，后果由你来承担"); drafted with AI assistance under human editorial direction. Translated to English on 2026-08-26 (AI-assisted, human-reviewed). Dated facts are anchored to the English sources above where they exist; claims we could not verify carry [unverified] tags; the "cover story" framing is translated opinion, clearly not ours to assert as fact. This is translated commentary — not a SigPulse measurement. Our first-party measurements live in the [dispatches](/posts/) and the [/data/ ledger](/data/).
