Anthropic has accused Chinese tech giant Alibaba of orchestrating the largest known model distillation attack against its Claude AI platform. In a letter sent to the U.S. Senate Banking Committee on June 10 and made public last week, Anthropic detailed how operators affiliated with Alibaba and its Qwen AI research lab used nearly 25,000 fraudulent accounts to generate over 28.8 million exchanges with Claude between April 22 and June 5, 2026.
The technique, known as adversarial distillation, involves systematically querying a frontier AI model and using the outputs to train a less capable system to replicate the original’s capabilities at lower cost. Anthropic says the campaign specifically targeted Claude’s advanced software engineering and agentic reasoning capabilities — exactly the differentiators that separate frontier models from their competitors.
This is not an isolated incident. Earlier in 2026, Anthropic identified similar extraction campaigns by other Chinese AI startups including DeepSeek, Moonshot AI, and MiniMax. Alibaba has not yet responded publicly to the allegations. The disclosure comes amid escalating U.S.-China tensions over AI intellectual property and export controls.
Sources
- InfoWorld — Anthropic accuses Alibaba of using 25,000 fake accounts to scrape Claude AI
- Tom’s Hardware — Anthropic claims Alibaba illicitly distilled its models
- Security Boulevard — Anthropic accuses Alibaba of distillation attack
Commentary
This is the AI equivalent of industrial espionage, and Anthropic going public through Congress rather than courts signals they see this as a national security issue, not just a terms-of-service violation. The scale — 25,000 accounts and 28.8 million exchanges — suggests an organized, well-resourced operation that treated Claude’s API as a training data pipeline.
The broader implication is sobering: if frontier model outputs can be systematically harvested to close the capability gap, then the billions invested in training frontier models become a shared resource for anyone willing to play dirty. Expect this to accelerate the push for output watermarking, rate limiting, and behavioral fingerprinting at the API layer. For the AI industry, distillation attacks may become as much of a strategic concern as model theft or weight exfiltration.
