Anthropic accused Alibaba and its affiliated operator of Qwen of leveraging nearly 25,000 fraudulent accounts to conduct a large-scale extraction of Claude model capabilities in a letter addressed to the U.S. Senate Banking Committee. According to documents seen by Reuters and other media, this attack—dubbed by Anthropic as the "largest known" model distillation incident—occurred between April 22 and June 5, 2026, involving over 28.8 million interactions with Claude. The sensitivity stems not only from its scale but also from its timing: coinciding with intensified U.S. government efforts to tighten AI export controls and the Pentagon’s inclusion of Alibaba on its list of “Chinese military companies.”
“Model distillation” refers to training a secondary model using the output of a more advanced model—not directly stealing weights or source code—but enabling the latter to rapidly replicate certain capabilities. While this technique is common in AI research, when conducted via fraudulent accounts, violation of terms of service, or circumvention of access restrictions, it constitutes illegal extraction of intellectual property. For U.S. policymakers, the concern is heightened by the fact that even without obtaining the most advanced models themselves, massive querying could still enable competitors to acquire comparable software engineering, agent reasoning, and automation capabilities.
Dated June 10, the letter was sent to Senator Tim Scott, Chair of the Senate Banking Committee, and Senator Elizabeth Warren, a senior member. Media outlets reviewing the document confirm that Anthropic described this operation as the largest known distillation attack against the company.
The core figures are straightforward: between April 22 and June 5, attackers used approximately 25,000 fraudulent accounts to interact with Claude over 28.8 million times. Anthropic believes these accounts are operated by entities linked to Alibaba and Alibaba Qwen, aiming to accelerate China’s acquisition of Anthropic’s cutting-edge model capabilities.
The concern extends beyond mere replication of basic question-answering abilities; it involves the potential leakage of frontier model capabilities in software engineering, automated task execution, and agent-level reasoning. Once such outputs are systematically collected, they may be repurposed as training data for other models.
The distinction remains critical. Anthropic uses the phrase “entities associated with Alibaba and Alibaba Qwen,” which does not equate to confirmed official involvement by Alibaba in orchestrating the attack, nor does it prove that the targeted models have successfully replicated Claude’s advanced capabilities. As of the reporting date, Alibaba has not responded to the allegations. Regarding its inclusion on the Pentagon’s “Chinese Military Companies” list, Alibaba has filed a lawsuit, asserting that the designation lacks factual or legal basis.
Ordinary data scraping typically involves harvesting publicly available web content, text, or open-source materials. In contrast, distillation attacks target the model’s output capabilities directly.
Attackers can repeatedly query a powerful model, saving responses, reasoning traces, generated code, or task execution plans, then use them to train their own models. This allows them to learn behavioral patterns of the strong model on specific tasks—even without accessing underlying weights.
This is precisely why AI firms and regulators are growing increasingly vigilant. The access interface of advanced models was originally designed as a commercial product and external service channel. But when access scales into tens of millions of queries and accounts are flagged as fraudulent, the interface risks transforming into an illicit capability extraction conduit.
Anthropic had previously disclosed similar incidents. In February 2026, the company reported smaller-scale distillation activities by DeepSeek, Moonshot AI, and MiniMax, with DeepSeek-related interactions exceeding 150,000, Moonshot AI surpassing 3.4 million, and MiniMax exceeding 13 million. Compared to these cases, the current incident—targeting Alibaba and Qwen-affiliated operators with 28.8 million interactions—is markedly larger.
By sending the letter to Congress, Anthropic is pushing for greater threat intelligence sharing between the U.S. government and private AI firms. According to the company, the intensity and complexity of such attacks are rising, necessitating faster coordination and response mechanisms.
This allegation is not isolated.
In April this year, the White House accused China of pilfering U.S. AI lab IP at an “industrial scale.” By early June, the Pentagon updated its 1260H list, adding Alibaba to the “Chinese Military Companies” designation. While Alibaba has challenged this classification legally, the move has tightened its entanglement with U.S. national security scrutiny.
Subsequently, on June 12, the U.S. Department of Commerce imposed export controls on Anthropic’s latest Mythos and Fable models, citing national security concerns. U.S. officials fear these advanced models could be exploited by military or intelligence agencies in China and other nations.
For Anthropic, this restriction has direct consequences. Due to challenges in effectively verifying global user identities and access origins, the company has been forced to implement broader access limitations—not just geographically targeted blockades.
This creates a paradox: while Anthropic calls on the government to help combat external distillation attacks, it simultaneously faces stricter export controls that constrain product accessibility. AI models are no longer merely software services—they are being incorporated into security frameworks akin to those governing advanced semiconductors.
Short-term, this incident is likely to drive further congressional and regulatory discussion on AI model access control. Unlike traditional export controls, managing model interfaces poses unique challenges: users can register across borders, resell access rights, or fragment usage across thousands of small accounts to evade detection.
However, this case remains at the stage of unilateral accusation by Anthropic. The intent behind the attack, the true operational entities behind the accounts, and the extent of capability leakage have not yet entered judicial assessment. Whether Alibaba will respond, how it will explain the identity of Qwen-affiliated operators, and whether third parties exploited Alibaba’s ecosystem or brand remain unresolved questions.
The more immediate impact is that the U.S. may further require AI companies to strengthen account vetting, monitor anomalous API usage, and enhance cross-company threat intelligence sharing. For frontier AI firms like Anthropic, OpenAI, and Google, this will increase compliance and security costs. For Chinese AI companies, accessing overseas advanced model services may become increasingly difficult.
The accusation has not yet reached a judicial conclusion, but it has already made one issue more concrete: beyond model weights, model outputs themselves are becoming regulated and contested assets in the U.S.-China AI competition.
Original: BlockBeats
Disclaimer: Contains third-party opinions, does not constitute financial advice
Pearl: Can AI Inference and Mining Coexist? | Project Introduction
1 day ago
STRK surges 26% in a single day, as Starknet aims to spin off from Ethereum to become an AI-resistant L1
1 day ago
After Jev, the Chinese team began delving deep into AI's "intuition layer"
2 days ago
OpenAI and Anthropic jointly signed a letter warning that large-scale AI-powered cyberattacks are imminent
08-28
Bernstein Research Report Breakdown: Around 70 AI-Drug Projects Enter Clinical Trials—The Real Answers Will Take Another 3 to 5 Years
08-28
Goldman Sachs Research Insight: NVIDIA's Earnings Beat Expectations, Target Price of $285 Still Has 34% Upside
08-27
US Stock Market Trends (August 27): PCE Surpasses Expectations, Pressuring Broad Market, Nvidia Rises 4% After Hours, Nasdaq Futures Up 1%
08-27






