25 Juin

Anthropic names Alibaba in the largest Claude distillation attack yet

Anthropic sent a letter to the US Senate Banking Committee on June 10 accusing Alibaba of running the biggest model theft operation it has ever seen. Bloomberg broke the story on June 24. CNBC, Reuters, and the BBC all confirmed the details from the letter.

The numbers are specific. Operators tied to Alibaba and its Qwen AI lab created roughly 25,000 fraudulent accounts and pumped 28.8 million exchanges through Claude between April 22 and June 5. That is a six-week window. Anthropic does not sell Claude in China, so every single account existed in violation of its terms of service.

Anthropic called it “the largest known distillation attack on Anthropic to date.” The company used the words “brazenly” and “illicitly” in the letter addressed to Senators Tim Scott and Elizabeth Warren.

What they were after

The Alibaba-linked operators did not scatter their requests randomly. They targeted Claude’s most valuable capabilities: software engineering and agentic reasoning. Those are the skills that separate a frontier model from a chatbot. Distillation works by feeding crafted prompts to a strong model, collecting its responses, and training a weaker model on that output. You get the benefit of someone else’s billion-dollar training run without paying for the compute.

Anthropic framed the stakes bluntly. The letter said these attacks “turn hundreds of billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors.”

Bigger than everything before combined

This is not Anthropic’s first accusation. In February, the company named three Chinese labs for industrial-scale distillation: DeepSeek ran about 150,000 exchanges, Moonshot more than 3.4 million, and MiniMax over 13 million. Together those three campaigns produced roughly 16.5 million exchanges through about 24,000 accounts.

The Alibaba operation nearly doubles that combined total by itself. A single company, acting in a six-week window, outpaced what three labs did over months.

The White House Office of Science and Technology Policy issued a memorandum in April promising to help AI labs detect and coordinate against distillation theft. Anthropic wrote that Alibaba “ignored the Trump Administration’s warnings” and kept going.

The geopolitical layer

The Pentagon added Alibaba to its Chinese military companies list on June 8. The Department of Defense has previously claimed Alibaba, BYD, and Baidu have ties to the Chinese military. Alibaba denies the allegations and sued the US government this week to get its name removed from the blacklist.

Alibaba did not respond to requests for comment from CNBC, BBC, or Bloomberg. Alibaba’s US-listed shares dropped more than 3 percent after the accusation surfaced and fell below $100 in afternoon trading.

Congress is moving

Senators Bill Hagerty and Andy Kim plan to attach an amendment to must-pass defense legislation that would blacklist or sanction any Chinese firm caught improperly using American AI output to train rival systems. A related bill is under discussion in the House.

The three biggest American AI labs are now coordinating on this. Anthropic, OpenAI, and Google have started sharing information about extraction attempts that violate their terms. OpenAI previously accused Chinese groups of the same practice.

The awkward part for Anthropic

Anthropic is asking Washington for help while fighting Washington over its own models. Earlier this month the company received an export control directive ordering it to suspend access to Fable 5 and Mythos 5 “by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.” Senior staffers flew to DC to negotiate. The models are still restricted.

The company also filed confidentially for an IPO this month at a $965 billion valuation. Cheap competitors that lifted its capabilities through distillation are a direct threat to that thesis.

Mots-cles

anthropic alibaba distillation claude ai security export controls