Anthropic Accuses Alibaba of a 28.8 Million-Exchange Claude Distillation Campaign

Anthropic told Senate Banking Committee leaders in a June 10 letter that Alibaba- and Qwen-affiliated operators used almost 25,000 fraudulent accounts for more than 28.8 million Claude exchanges between April 22 and June 5. Anthropic called it its largest known distillation attack and asked Congress to expand threat sharing, tighten chip-access loopholes and consider penalties; Alibaba did not comment to Reuters.
Anthropic accused operators affiliated with Alibaba and its Qwen lab of running the largest distillation campaign the company has identified against Claude. In a June 10 letter to Senate Banking Committee Chair Tim Scott and ranking member Elizabeth Warren, Anthropic said the operation generated more than 28.8 million exchanges through almost 25,000 fraudulent accounts between April 22 and June 5, 2026.
Reuters reported the allegation on June 25 after reviewing the letter. Alibaba did not immediately respond to Reuters' request for comment. The attribution and scale therefore remain Anthropic's claims, not an independently published technical finding or government determination.
What Anthropic alleges
The letter says the accounts targeted Claude's agentic reasoning, software engineering and long-horizon task capabilities while violating Anthropic's terms and regional access restrictions. Anthropic describes distillation as training a less capable model on outputs from a stronger one. The method is common in legitimate model development, but Anthropic uses the term "distillation attack" for coordinated extraction that it says bypasses access controls and transfers capabilities to a competitor.
Anthropic compared the Alibaba-linked activity with three campaigns it disclosed in February involving DeepSeek, Moonshot AI and MiniMax. Those earlier campaigns totaled more than 16 million Claude exchanges through about 24,000 accounts. The June letter says the Alibaba-linked campaign alone exceeded that combined exchange volume.
What Anthropic asked Congress to do
The company asked Congress to improve threat-information sharing among U.S. AI labs, close routes that let Chinese AI companies use advanced U.S. chips, and consider penalties for companies responsible for illicit distillation. Those requests are proposals. The letter does not establish that Congress adopted them, that regulators opened an enforcement case, or that Alibaba trained a named Qwen release on the collected outputs.
Reuters also reported that Alibaba had recently been added to the Pentagon's list of Chinese military companies, a designation the company was challenging. That dispute is separate from Anthropic's model-access allegation.
Why the evidence boundary matters
For AI-platform teams, the incident highlights account verification, proxy detection, coordinated-traffic analysis and capability-focused abuse monitoring as control points around model APIs. It does not show that high query volume alone proves distillation. Reliable attribution requires linked account, infrastructure and behavioral evidence, much of which Anthropic described as confidential rather than publishing in the letter.
Key Points
- 1Anthropic alleged that Alibaba- and Qwen-affiliated operators generated more than 28.8 million Claude exchanges through almost 25,000 fraudulent accounts between April 22 and June 5, 2026.
- 2The company said the campaign targeted agentic reasoning, software engineering and long-horizon task capabilities and exceeded the combined exchange volume of three campaigns it disclosed in February.
- 3Anthropic asked Congress to expand threat-information sharing, close advanced-chip access loopholes and consider penalties for companies responsible for illicit distillation.
- 4The scale and attribution are Anthropic's allegations; the public letter does not disclose the confidential technical evidence needed for independent verification, and Alibaba did not comment to Reuters.
Scoring Rationale
The alleged campaign is material because of its reported scale, focus on valuable Claude capabilities and direct policy request to Congress. The impact remains bounded because the attribution and technical evidence come from Anthropic, Alibaba did not comment to Reuters, and no enforcement outcome or independently verified model transfer is established.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

