Anthropic accuses Alibaba of running largest AI distillation attack: 29 million Claude exchanges via 25,000 fraudulent accounts
Anthropic has sent a letter to the US Senate Committee on Banking, Housing, and Urban Affairs and White House officials accusing Alibaba of orchestrating the largest known AI model distillation attack against a US company. The letter, disclosed on June 24, 2026, alleges that operators linked to Alibaba's Qwen AI lab used approximately 25,000 fraudulent accounts to extract Claude's capabilities in a coordinated campaign running from April 22 to June 5, 2026.
What's new
According to Anthropic's congressional letter, the attack generated nearly 29 million exchanges with Claude targeting software engineering and agentic reasoning — the model's most commercially valuable skills. The volume exceeded the combined total of all three earlier distillation campaigns Anthropic disclosed in February 2026, when the company accused DeepSeek, Moonshot AI, and MiniMax of siphoning Claude capabilities through approximately 24,000 fake accounts and 16 million exchanges.
In the letter, Anthropic made three specific requests to US officials:
-
Antitrust clarification: Clarify antitrust guidelines so US AI labs can share information about distillation attempts across the industry without legal exposure.
-
Export controls: Anthropic reiterated its support for export controls on advanced AI chips to limit Chinese labs' access to frontier-level compute.
-
Enforcement: The company called for penalties against firms that use distillation to extract competitors' model capabilities illicitly.
Context
Model distillation is a well-established technique in which a smaller or less capable model is trained on the outputs of a more powerful one. When done with proprietary models and without authorization, it allows a competitor to effectively extract expensive-to-train capabilities at minimal cost. Claude's agentic reasoning and software engineering capabilities represent years of investment — and Alibaba's Qwen lab has been working to match these.
Anthropic first publicly disclosed distillation attacks in February 2026, naming three Chinese AI labs. The Alibaba accusation escalates the situation significantly: Alibaba is a far larger and better-resourced company than those three combined, and 29 million exchanges across 25,000 accounts represents a far more industrialized operation.
Why it matters
This is the largest publicly disclosed case of AI model capability theft by a single actor to date. The letter to Congress is also a call for the kind of industry coordination on threat intelligence that antitrust law currently makes difficult — a gap Anthropic is asking lawmakers to close. The timing is notable: Anthropic is simultaneously fighting the US government's own export control directive restricting access to its most advanced models, while now asking that same government to penalize Chinese labs for exploiting Claude at scale.
Corroborating sources
- Bloomberg
https://www.bloomberg.com/news/articles/2026-06-24/anthropic-accuses-alibaba-of-illicitly-accessing-its-ai-models
“Anthropic accuses Alibaba of illicitly accessing its AI models”
- Cnbc
https://www.cnbc.com/2026/06/24/anthropic-alibaba-distillation-campaign.html
“the largest known distillation attack on Anthropic to date”