Claude's Capabilities Extracted at Large Scale? Anthropic Accuses Ali-Related Parties of 'Distilling' Models

marsbitPublished on 2026-06-25Last updated on 2026-06-25

Abstract

Anthropic alleges that entities associated with Alibaba and its AI lab Qwen used nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI model in what it calls the "largest known" model distillation attack. The alleged incident occurred between April 22 and June 5, involving over 28.8 million interactions with Claude. Model distillation involves using a powerful model's outputs to train another model, potentially replicating abilities like software engineering and agent reasoning without stealing the underlying code. The accusations emerge amid heightened US AI export controls and the Pentagon's listing of Alibaba as a "Chinese military company." Anthropic detailed the claims in a June 10 letter to the US Senate Banking Committee, urging better threat intelligence sharing. While not conclusively proving direct Alibaba involvement or successful capability replication, the case highlights growing concerns over AI model outputs as contested assets. The incident may push for stricter controls on model access and user verification, increasing compliance costs for AI firms and potentially limiting Chinese companies' access to advanced foreign models.

In a letter to the U.S. Senate Banking Committee, Anthropic accused Alibaba and operators related to its AI lab Qwen of using nearly 25,000 fraudulent accounts to extract the capabilities of the Claude model at a large scale. According to the letter seen by Reuters and other media, this incident, described by Anthropic as the "largest known" model distillation attack, occurred between April 22 and June 5, 2026, involving over 28.8 million interactions with Claude. Its sensitivity stems not only from its scale but also because it coincided with consecutive U.S. government escalations in AI export controls and the Pentagon's listing of Alibaba on its "Chinese military company" roster.

The so-called "model distillation" does not involve directly stealing model weights or source code. Instead, it uses the output results of a strong model to train another model, allowing the latter to rapidly replicate some of its capabilities. In AI R&D, this is originally a common technique. However, if conducted through fraudulent accounts, in violation of service terms, or by circumventing access restrictions, it is viewed as the illegal extraction of intellectual property. For U.S. policymakers, a more棘手 issue is that even without obtaining the most advanced model itself, large-scale queries could help competitors acquire similar capabilities in areas like software engineering and agent reasoning.

42 Days, 28.8 Million Interactions: Anthropic Points the Finger at Ali and Qwen

Dated June 10, the letter was addressed to U.S. Senate Banking Committee Chairman Tim Scott and senior member Elizabeth Warren. Content seen by multiple media outlets shows Anthropic described this operation as the largest known distillation attack against the company.

The core numbers are straightforward. From April 22 to June 5, attackers used approximately 25,000 fraudulent accounts to conduct over 28.8 million interactions with Claude. Anthropic believes the operators behind these accounts are related to Alibaba and Alibaba Qwen, with the aim of accelerating China's acquisition of Anthropic's advanced model capabilities.

Anthropic's concern in the letter is not merely the replication of general question-answering abilities but the potential outflow of capabilities closer to the cutting edge, such as in software engineering, automated tasks, and agent reasoning. Once these outputs are systematically collected, they could become data for training other models.

Nuance is important here. Anthropic's phrasing uses "operators related to Alibaba and Alibaba Qwen," which does not equate to confirming that Alibaba officially orchestrated the attack directly, nor does it prove that related models have successfully replicated Claude's advanced capabilities. As of the reports' publication, Alibaba had not responded to the distillation allegation. Regarding its listing on the Pentagon's "Chinese military company" list, Alibaba has filed a lawsuit, calling the designation "devoid of factual or legal basis."

Why Are Distillation Attacks More Sensitive Than Ordinary Scraping?

Ordinary data scraping typically refers to crawling web pages, text, or publicly available materials. Distillation attacks target the output capabilities of the model itself.

Attackers can repeatedly pose questions to a strong model, saving its answers, reasoning processes, code generation results, or task execution plans, and then use them to train their own model. This way, even without accessing the underlying weights, they may learn the behavioral patterns of the strong model on certain tasks.

This is precisely where AI companies and regulators are becoming increasingly vigilant. The access interface of an advanced model is originally a commercial product and a channel for external services. But when the scale of access reaches tens of millions of instances and the accounts are identified as fraudulent, the product interface can become a channel for capability extraction.

Anthropic has previously disclosed similar incidents publicly. In February 2026, the company stated it had discovered smaller-scale similar activities by DeepSeek, Moonshot AI, and MiniMax, with DeepSeek-related interactions exceeding 150,000, Moonshot AI over 3.4 million, and MiniMax over 13 million. Compared to these cases, the 28.8 million interactions linked to Alibaba and Qwen-related operators are significantly larger.

By writing to Congress, Anthropic is also pushing for the U.S. government to engage in threat intelligence sharing with private AI companies. According to its statement, the intensity and complexity of such attacks are rising, requiring faster coordinated responses.

Allegations Coincide with U.S. Policy Escalation, Anthropic Itself Also Restricted

This allegation did not emerge in isolation.

In April this year, the White House accused China of stealing intellectual property from U.S. AI labs on an "industrial scale." By early June, the Pentagon updated its 1260H list, adding Alibaba to its "Chinese military company" list. Alibaba is challenging this designation, but the move has already tightened its relationship with U.S. national security scrutiny.

Subsequently, on June 12, the U.S. Commerce Department imposed export restrictions on Anthropic's latest Mythos and Fable models, citing national security concerns. The U.S. side worries these advanced models could be used by military or intelligence agencies in countries like China.

For Anthropic, this restriction brings direct consequences. Due to difficulties in effectively screening global user identities and access sources, the company has had to impose broader access restrictions on the relevant models, rather than just region-specific blockades.

This creates a contrast. On one hand, Anthropic is asking the government for help combating external distillation attacks; on the other hand, it is also beginning to bear the product access limitations resulting from stricter export controls. AI models are no longer just software services; they are being incorporated into security control frameworks similar to those for advanced chips.

Attribution and Countermeasure Boundaries Remain the Biggest Questions

In the short term, this incident is most likely to prompt further discussion in the U.S. Congress and among regulators regarding AI model access control. Compared to traditional export controls, managing model interfaces is more challenging. Users can register across borders, resell access rights, or distribute query volumes across numerous small accounts.

However, this incident remains at the stage of Anthropic's unilateral allegation. The intent of the attack, the true operating entities behind the accounts, and the extent of capability outflow have not entered judicial determination. Whether Alibaba will respond, how it explains the identity of Qwen-related operators, and whether there were third parties operating using the Alibaba ecosystem or name remain unresolved questions.

A more practical impact is that the U.S. may further require AI companies to strengthen account review, abnormal query monitoring, and cross-company threat intelligence sharing. For frontier model companies like Anthropic, OpenAI, and Google, this will increase security and compliance costs. For Chinese AI companies, the difficulty of accessing overseas advanced model services may continue to rise.

This allegation has not yet become a judicial conclusion, but it has made one question more concrete: beyond model weights, model outputs themselves are becoming assets subject to control and contention in the U.S.-China AI competition.

Trending Cryptos

Related Questions

QWhat specific incident does Anthropic allege occurred between April 22 and June 5, 2026, according to the article?

AAnthropic alleges that operators related to Alibaba and its AI lab Qwen used approximately 25,000 fraudulent accounts to conduct over 28.8 million interactions with the Claude model in a large-scale 'model distillation' attack.

QHow does the article define 'model distillation' and what makes its use in this context a potential problem?

AThe article defines 'model distillation' as a technique to train one model using the output results of a stronger model, allowing the former to replicate some capabilities. While common in AI research, it becomes problematic and potentially illegal if conducted through fraudulent accounts, in violation of service terms, or by bypassing access restrictions to extract intellectual property.

QWhat is a key concern for US policymakers regarding this alleged distillation attack, beyond the immediate intellectual property issue?

AA key concern is that even without obtaining the most advanced model itself, large-scale interactions could help competitors acquire similar capabilities in areas like software engineering and agent reasoning, advancing their own AI development.

QWhat was a direct consequence for Anthropic itself following the U.S. government's increased export controls on AI mentioned in the article?

AFollowing U.S. export restrictions placed on Anthropic's latest Mythos and Fable models on national security grounds, the company had to impose broader access restrictions on these models due to difficulties in effectively screening global user identities and access sources.

QAccording to the article, what remains a major unresolved aspect or 'suspense' surrounding Anthropic's allegations?

AThe major unresolved aspect is the attribution and specifics of the incident. It remains at the stage of Anthropic's unilateral allegation, with the true intent, the actual operating entity behind the accounts, and the extent of capability leakage not yet legally determined. Alibaba's response and explanation regarding Qwen-related operators are also pending.

Related Reads

Fable 5 is about to make a comeback, code exposed? Anthropic CEO kicked out of the White House

Fable 5, a previously restricted AI model from Anthropic, appears poised for a comeback. Evidence from leaked code in the Claude Code v2.1.190 version suggests a shift in its business model from a separate purchase to a potentially limited weekly usage allowance within standard Claude subscriptions. Furthermore, the model has reportedly reappeared in Amazon Bedrock documentation. This potential revival coincides with significant internal changes at Anthropic. According to a report by The Wired, CEO Dario Amodei was reportedly sidelined from negotiations with the Trump administration over Fable 5's export restrictions. Government officials found him difficult to communicate with. Co-founder Tom Brown and policy head Sarah Heck took over discussions, leading to more productive technical talks aimed at addressing White House security concerns about the model being "jailbroken." External pressure is mounting as a bipartisan group of US lawmakers has demanded answers from the Commerce Department by a June 26 deadline regarding the criteria and timeline for potentially reinstating public access to Fable 5. The potential return of Fable 5 comes as competitors OpenAI and Google have reportedly delayed their own major model releases. If Anthropic successfully navigates the government's security review, Fable 5 could gain a significant "safety-certified" advantage in the enterprise market. The countdown to the June 26 deadline is now underway.

marsbit26m ago

Fable 5 is about to make a comeback, code exposed? Anthropic CEO kicked out of the White House

marsbit26m ago

Trading

Spot
Futures

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of S (S) are presented below.

活动图片