Skip to content

Has Claude's ability been massively scaled? Anthropic accuses Alibaba affiliate of 'distilling' model

Jun 25, 14:19
Has Claude's ability been massively scaled? Anthropic accuses Alibaba affiliate of 'distilling' model
TL;DR· Anthropic Sends Letter to the U.S. Senate, Accusing Alibaba and Qwen-Related Operators of Large-Scale Extraction of Claude's Capability.
· This type of distillation attack involves using a strong model's output to train other models, potentially bypassing model weight export restrictions.
· Alibaba has not responded to the distillation accusation, and U.S. model controls are now starting to restrict Anthropic's own openness.


Anthropic has accused Alibaba and its AI lab's Qwen-related operators of using nearly 25,000 fraudulent accounts to extract Claude's model capability on a large scale in a letter to the U.S. Senate Banking Committee. According to a letter seen by Reuters and other media outlets, this incident, described by Anthropic as the "largest known" model distillation attack, occurred between April 22, 2026, and June 5, involving over 28.8 million interactions with Claude. The sensitivity of this issue lies not only in its scale but also because it took place during a time when the U.S. government was ramping up AI export controls, and the Pentagon was placing Alibaba on the "Chinese Military Company" list.


The so-called "model distillation" does not involve directly stealing model weights or source code but rather training another model with the output of a strong model to quickly replicate some of its capabilities. In AI research and development, this was originally a common technique, but if done through fraudulent accounts, violations of terms of service, or bypassing access restrictions, it is considered illegal extraction of intellectual property. For U.S. policymakers, the more challenging aspect is that even without obtaining the most advanced model itself, large-scale calls may help competitors gain similar capabilities in software engineering, intelligent agent reasoning, and other aspects.


42 Days, 28.8 Million Interactions - Anthropic Points Finger at Alibaba and Qwen


The letter, dated June 10, was addressed to U.S. Senate Banking Committee Chairman Tim Scott and senior member Elizabeth Warren. The contents of the letter, seen by multiple media outlets, portray this action as the largest known distillation attack against the company.


The key figures are straightforward. Between April 22 and June 5, attackers engaged in over 28.8 million interactions with Claude through approximately 25,000 fraudulent accounts. Anthropic believes that the operators behind these accounts are associated with Alibaba and Alibaba Qwen, with the aim of accelerating China's access to Anthropic's advanced model capabilities.


The concern in the letter is not just the ability to replicate common knowledge but rather the closer-to-the-edge models' capabilities in software engineering, automated tasks, and agent reasoning leaking out. Once these outputs are systematically collected, they could potentially become training data for other models.


The context here is equally important. The use of the term "operational parties related to Alibaba and Alibaba Qwen" by Anthropic should not be equated to a confirmed direct organization-backed attack by Alibaba, nor does it prove that related models have successfully replicated Claude's advanced capabilities. As of the publication of the related reports, Alibaba has not responded to these distillation allegations. Regarding the Pentagon listing it as a "Chinese military company," Alibaba has filed a lawsuit stating that the related designation has "no factual or legal basis."


Why is Distillation Attack More Sensitive Than Ordinary Scraping?


Ordinary data scraping usually refers to fetching web pages, text, or public information. A distillation attack targets the output capability of the model itself.


Attackers can repeatedly query a strong model, save the answers, reasoning processes, code generation results, or task execution plans, and then use them to train their own models. This way, even without accessing the underlying weights, they may learn the strong model's behavioral patterns in certain tasks.


This is precisely what AI companies and regulatory bodies are increasingly wary of. The access interfaces of advanced models were originally commercial products and external service channels. However, when the access reaches millions of queries and the accounts are identified as fraudulent accounts, the product interface can become a channel for capability extraction.


Anthropic has previously disclosed similar incidents. In February 2026, the company stated that it had discovered small-scale similar actions in DeepSeek, Moonshot AI, and MiniMax, with DeepSeek having over 150,000 interactions, Moonshot AI over 3.4 million interactions, and MiniMax over 13 million interactions. Compared to these cases, the 28.8 million interactions pointing to Alibaba and Qwen-related operational parties are significantly larger.


Anthropic's letter to Congress is also aimed at promoting threat intelligence sharing between the U.S. government and private AI companies. According to them, the intensity and complexity of similar attacks are on the rise, requiring faster coordinated responses.


The Accusation Clashes with U.S. Policy Escalation, Restricting Anthropic Itself


This accusation is not an isolated incident.


In April of this year, the White House accused China of engaging in "industrial-scale" theft of U.S. AI lab intellectual property. By early June, the Pentagon updated the 1260H list, designating Alibaba as a "Chinese military company." Alibaba is challenging this designation, but the move has further strained its relationship with U.S. national security reviews.


Subsequently, on June 12, the U.S. Department of Commerce, citing national security concerns, imposed export restrictions on Anthropic's latest Mythos and Fable models. The U.S. side is worried that these advanced models could be used by the military or intelligence agencies of countries like China.


For Anthropic, this restriction had direct consequences. Due to the difficulty of effectively screening global user identities and access sources, the company had to impose broader restrictions on model access, rather than precise regional blockades.


This has created a paradox. While Anthropic is requesting government assistance to combat external distillation attacks, it is also facing product accessibility restrictions due to stricter export controls. AI models are no longer just software services but are being brought into a security control framework similar to advanced chips.


Attribution and Countermeasure Boundaries Remain the Greatest Suspense


This incident is most likely to prompt continued discussions in the U.S. Congress and regulatory agencies regarding AI model access control in the short term. Compared to traditional export controls, controlling model interfaces is more challenging. Users can register across borders, resell access rights, and split call volumes through numerous small accounts.


However, this incident is still in the unilateral accusation stage by Anthropic. The attack intent, the real operational entities behind the accounts, and the extent of capability leakage have not yet been legally determined. Whether Alibaba will respond, how to explain the identity of the operators behind Qwen operations, and whether there are third parties utilizing the Alibaba ecosystem or name for operations are still unresolved issues.


The more immediate impact is that the U.S. may further demand AI companies to enhance account reviews, monitor abnormal calls, and share cross-company threat intelligence. For companies like Anthropic, OpenAI, Google, and other cutting-edge model companies, this will increase security and compliance costs. For Chinese AI companies, the difficulty of accessing advanced overseas model services may continue to rise.


While this accusation has not yet turned into a judicial conclusion, it has made one issue more specific: beyond model weights, the model output itself is increasingly becoming an asset subject to regulation and competition in the U.S.-China AI competition.



Recommended

Eight-Year Investment U-Turn: Why Did Ethereum Suddenly Abandon Poseidon?

Aug 16, 10:00
Eight-Year Investment U-Turn: Why Did Ethereum Suddenly Abandon Poseidon?

The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Aug 15, 14:00
The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?

Tencent Still Has a Dream

Aug 15, 11:27
Tencent Still Has a Dream

To Catch North Korean Hackers, They Set Up a Fake Project

Aug 15, 10:00
To Catch North Korean Hackers, They Set Up a Fake Project

From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

Aug 14, 19:32
From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA

11,742 Shipping Addresses Exposed Alongside Trezor Orders

Aug 14, 19:01
11,742 Shipping Addresses Exposed Alongside Trezor Orders