GLM-52 897 —
GPT-56SC 873 —
CL-OP5X 865 -0.9%
GROK-46H 865 -0.9%
GEM-37FH 865 -0.9%
GPT-56T 861 —
GLM-5 856 —
MUSE-SPK 841 —
QWEN-38X 824 -2.3%
GPT-6A 820 —
KIMI-K3X 810 -1%
CL-FAB5H 787 -0.9%
CL-OP5H 764 -0.9%
CL-OP46H 742 -0.9%
CL-OP47H 733 -1.1%
GEM-38FH 676 -1%
CL-OP47 585 -0.7%
INKL 531 —
CL-OP46 496 -0.2%
CL-OP48 490 -0.2%
GLM-52 897 —
GPT-56SC 873 —
CL-OP5X 865 -0.9%
GROK-46H 865 -0.9%
GEM-37FH 865 -0.9%
GPT-56T 861 —
GLM-5 856 —
MUSE-SPK 841 —
QWEN-38X 824 -2.3%
GPT-6A 820 —
KIMI-K3X 810 -1%
CL-FAB5H 787 -0.9%
CL-OP5H 764 -0.9%
CL-OP46H 742 -0.9%
CL-OP47H 733 -1.1%
GEM-38FH 676 -1%
CL-OP47 585 -0.7%
INKL 531 —
CL-OP46 496 -0.2%
CL-OP48 490 -0.2%
← Back to feed

Anthropic Names Alibaba in Largest-Ever Distillation Attack: 28.8M Claude Exchanges, 25,000 Fake Accounts

Anthropic sent a letter to the US Senate Banking Committee on June 10 accusing operators affiliated with Alibaba and its Qwen AI lab of running the largest known distillation campaign against a US AI company. The operation generated 28.8 million Claude exchanges through nearly 25,000 fraudulent accounts between April 22 and June 5, 2026, a six-week window that produced nearly double the combined volume of every prior Chinese lab attack Anthropic had disclosed.

The Numbers

The scale comparison is the headline. Anthropic’s February disclosure named three Chinese AI labs:

  • DeepSeek: approximately 150,000 exchanges
  • Moonshot AI: approximately 3.4 million exchanges
  • MiniMax: approximately 13 million exchanges

Combined, those three operations generated roughly 16.5 million exchanges through around 24,000 accounts over months. The Alibaba campaign surpassed all of them in six weeks at 28.8 million exchanges through 25,000 accounts. Anthropic called it “the largest known distillation attack on Anthropic to date.”

What Was Targeted

The campaign focused on Claude’s most commercially valuable capabilities: software engineering, agentic reasoning, and long-horizon task planning. Those are the exact skills that power Claude Code and managed agent pipelines, which account for a growing share of Anthropic’s revenue. The company told senators that successful distillation of these capabilities could help Chinese developers approach the performance level of Mythos Preview, Anthropic’s restricted frontier model focused on advanced cybersecurity work.

Distillation does not involve theft of model weights or training data. The technique involves asking a stronger model carefully designed questions and collecting the answers at scale to train a weaker model to mimic the stronger one’s behavior. The outputs are the attack surface.

Policy Asks

Anthropic used the letter to push three legislative requests: the ability to share threat intelligence with other US AI labs and with the federal government more freely; tighter controls on China’s access to advanced US AI compute infrastructure; and penalties on Chinese AI labs found to be running large-scale distillation campaigns. “More action is needed to ensure continued American AI leadership,” the company wrote.

The Alibaba campaign reportedly continued after an April memo from OSTP Director Michael Kratsios told the industry that the White House had flagged distillation as a national security concern. Anthropic’s framing was explicit: the operation was conducted in defiance of the administration’s guidance.

Timing

Two days after Anthropic sent the letter, on June 12, the Commerce Department imposed export restrictions on Mythos and Fable, citing concerns about deployment by military intelligence users in China. The restrictions triggered a global access shutdown that hit 200+ research institutions. Whether the letter influenced the Commerce decision, or whether both events were driven by the same underlying intelligence assessment, has not been confirmed publicly.

Alibaba did not respond to requests for comment at the time of publication. The Qwen lab has continued shipping open-weight models.

Implications

Anthropic has now named four Chinese organizations as sources of distillation attacks, all in the span of about four months. The escalation from ~150,000 exchanges (DeepSeek) to 28.8 million (Alibaba) in one step reflects both the commercial stakes of Claude’s coding capabilities and the ease with which large-scale API access can be obtained through fraudulent account creation. The company’s legislative push signals it no longer expects the problem to be solved through terms-of-service enforcement alone.