Anthropic Accuses Alibaba of Largest-Ever Claude Distillation Attack with 28.8M Interactions

Anthropic Accuses Alibaba of Largest-Ever Claude Distillation Attack with 28.8M Interactions

N
News Editor 01
2026-07-23 08:35:15
Anthropic submitted a confidential letter to the U.S. Senate alleging that Alibaba orchestrated the largest model distillation attack ever, using 25,000 fraudulent accounts to extract capabilities from Claude through 28.8 million interactions.
AnthropicAlibabamodel distillationAI securityClaude

AI giant Anthropic has sent a confidential letter to the U.S. Senate, accusing Chinese tech conglomerate Alibaba of launching the largest-ever "model distillation attack." According to the letter, Alibaba-associated teams used nearly 25,000 fraudulent accounts to conduct over 28.8 million malicious interactions with the Claude model in an attempt to steal cutting-edge U.S. AI technology without bearing the massive development costs.

25,000 Fake Accounts, 28.8M Queries Targeting Claude's Core Abilities

Submitted ahead of the Senate hearing "AI and the American Dream," the letter details the operation that occurred between April 22 and June 5, 2026. Anthropic claims the attackers were linked to Alibaba and its Qwen AI lab. They extensively violated Claude's terms of service, employing obfuscation techniques and proxy networks to evade security detection, registering nearly 25,000 fraudulent accounts to interact with Claude over 28.8 million times. Anthropic states this is the "largest illicit extraction operation" it has ever detected.

The goal was unmistakably clear: avoid the hundreds of billions of dollars in training and R&D costs required to build frontier models while directly cloning Claude's most valuable advanced capabilities, including agentic reasoning, software engineering, and long-horizon task solving.

Brazen Act Despite Trump's Warning

The political sensitivity is extreme. President Donald Trump had publicly accused China of "industrial-scale" AI technology theft just two months earlier, in April 2026. Anthropic had previously accused Chinese startups DeepSeek and Moonshot of similar tactics totaling about 16 million interactions. Yet the Alibaba-led attack came after the U.S. government's stern warning. Anthropic's letter sharply criticizes Alibaba — a NYSE-listed multinational with significant U.S. operations — for "brazenly" disregarding Washington's warning and continuing the theft. Following the news, Alibaba's stock price dropped approximately 3%.

Call for Antitrust Reform and Stricter Export Controls

In response to the persistent Chinese distillation threat, Anthropic urges Congress to act immediately with three demands:

  1. Amend antitrust laws to allow U.S. AI companies to legally share threat intelligence on Chinese attack tactics (currently constrained by monopoly regulations).
  2. Tighten chip export controls to further restrict China's access to advanced computing power, rendering distilled data useless without sufficient hardware support.
  3. Penalize Chinese labs by limiting their access to U.S. models and advanced chips, even banning them from using data centers located outside China.

Anthropic warns that without intervention, these attacks will help China drastically narrow the technology gap and potentially achieve capabilities comparable to Anthropic's own cybersecurity model "Mythos Preview" — which Chinese 360 Security founder Zhou Hongyi has publicly described as a "cyber nuclear weapon." If such a model, equipped with advanced software engineering yet lacking American safety guardrails, falls into adversarial hands, it could pose a devastating threat to U.S. national security.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.