虎嗅

Claude Code: "High Risk" – Who Will Fulfill the Orders First?

原文:Claude Code “高危“,谁先兑现订单?

Summary of Key Points

On July 8th, the Ministry of Industry and Information Technology (MIIT) reported that the American AI programming tool Claude Code contains a security backdoor that may leak sensitive information such as location and device identifiers. This is the first time authorities have officially identified a potential backdoor in an overseas AI tool. Alibaba immediately added Claude Code to its high-risk list and banned its internal use starting July 10th, recommending its own developed tool, Qoder, as a substitute. This marks a shift in the AI programming tool competition from focusing on “who can write code faster” to prioritizing “security.” The capital market responded positively (Zhipu’s stock price in Hong Kong rose by 13%, and Alibaba’s rose by 12%), but whether this “security premium” is based on real demand or speculation depends on whether domestic tools can pass three critical tests: internal verification, product quality, and commercial viability.

I. Regulatory Authorities and Giants Join Forces: Security Becomes a Barrier in the AI Programming Tool Market

In the past, the main criterion for choosing an AI programming tool was its efficiency in writing code; now, security has become a prerequisite.

  • The MIIT’s announcement signals that overseas AI tools with security vulnerabilities cannot be used and will be publicly identified. Claude Code was targeted because certain versions of it can secretly collect sensitive user data, posing significant risks to companies (e.g., leaking company code or device information).
  • Alibaba’s action is even more direct: Tens of thousands of its internal developers must switch from Claude Code to Qoder within a short period. This is not just an individual company’s decision but a industry trend. In the future, when companies choose AI programming tools, they will first ask about security issues; those that are insecure will be immediately dismissed.

In simple terms, security has gone from being an optional bonus to a mandatory requirement.

II. Domestic Tools: Those with Internal Testing Platforms Are More Reliable

For domestic AI programming tools to replace Claude Code, their reliability depends on whether they have an internal testing infrastructure:

1. Platform companies with internal testing (higher certainty):

  • Examples: Alibaba Qoder, Tencent CodeBuddy, Baidu Comate.
  • Why are they reliable? They have large teams of internal developers serving as a testing ground:
  • Alibaba Qoder: With tens of thousands of developers forced to switch, it has undergone a large-scale free test, quickly verifying the tool’s effectiveness and suitability for real work. If Alibaba releases data on internal adoption rates and code acceptance, this will boost its credibility among external companies.
  • Tencent CodeBuddy: Used by 90% of Tencent engineers, with AI-generated code accounting for 50% of new code, reducing coding time by 40%. It already has clients like China Merchants Bank and Midea, and is likely to secure corporate replacement orders in the third quarter.
  • Baidu Comate: A veteran player, with 45% of new internal code generated using its tool, and over 1.1 million external enterprise users. Although it has long touted its security features, the gap created by Claude Code’s issues presents a real opportunity.
  • Ranking by reliability: Alibaba Qoder > Tencent CodeBuddy > Baidu Comate.

2. Independent tools without internal testing (lower certainty):

  • Examples: Zhipu ZCode, etc.
  • The problem is that they lack their own internal developer teams and must rely on external clients. However, the purchasing process for companies is lengthy (evaluation, testing, contract signing), so it’s difficult to secure real orders in the third quarter; these tools are still in the concept validation phase.

III. Security Is Just the Entry Ticket; Product Quality Is Key to Retaining Users

Security may compel users to switch tools, but whether they will stay depends on the tool’s usability:

1. Performance gaps are narrowing, but the key is code adoption rates:

  • In terms of performance, Claude Code’s core model scored 87.6% in industry tests (SWE-bench Verified), while domestic models like Tencent Hy3 and Alibaba Qwen3-Coder scored 74.4% and 69.6%, respectively—although there is a gap, it’s narrowing.
  • The key metric is code adoption rate (the proportion of AI-generated code that developers actually use). Claude Code has an adoption rate of 85%-90%; if domestic tools can match this, users may find them sufficient and secure even if their performance is slightly lower. If the adoption rate is too low, developers may revert to the old tools despite compliance requirements.

2. Low migration costs are essential:

  • Developers are accustomed to Claude Code’s functionality (e.g., command syntax, plugin usage), so switching to a new tool could be challenging. Good news: Alibaba Qoder supports “Bring Your Own Key” (BYOK) and allows direct integration of Claude models, reducing the transition cost; Zhipu ZCode is compatible with Claude’s API protocol, making migration almost seamless.

IV. Capital Market: Speculation or Real Value? Three Tests Determine Long-Term Success

Short-term stock price gains may be driven by sentiment, but long-term value depends on three key tests:

1. Internal data disclosure (affecting short-term sentiment):

  • Will Alibaba, Tencent, and Baidu release internal usage data (e.g., adoption rates, efficiency improvements, coverage)? Positive results will boost market confidence and further drive stock prices.

2. Product quality verification (affecting sustainability):

  • After the third quarter, will domestic tools maintain a high user retention rate and high code adoption rates? If they do, it indicates a true efficiency revolution; otherwise, it’ll just be a compliance measure, and market enthusiasm will wane.

3. Commercial viability (affecting valuation):

  • Will there be external orders? For example, signed agreements with clients, growth in paid users, increased cloud resource usage? This is the final step to turning the security premium into actual revenue.

If all three tests are successful, this development marks a shift from China’s AI programming tools following overseas trends to becoming independent. If the change remains limited to internal use without follow-up data, stock prices will likely decline, as the market ultimately values real revenue.

Final note: The above content is for reference only and does not constitute investment advice. Please proceed with caution.

(End of article)