Anthropic Accuses Alibaba of 28.8 Million Fake Exchanges to Steal Claude's Capabilities

Started by DeepInlet, Jun 29, 2026, 10:19 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Anthropic Accuses Alibaba of 28.8 Million Fake Exchanges to Steal Claude's Capabilities   Views(Read 86 times)

DeepInlet

Anthropic told senior US senators in a June 10 letter that operators affiliated with Alibaba and its Qwen AI lab ran more than 28.8 million exchanges with Claude through nearly 25,000 fraudulent accounts between April 22 and June 5, 2026. The company described this as the largest model distillation campaign it has ever publicly disclosed. Distillation, or model extraction, involves querying a more capable AI at industrial scale and using the outputs to train a smaller model to replicate its capabilities without access to the original weights or training data. Anthropic told senators the campaign specifically targeted Claude's most advanced features in agentic reasoning and software engineering, arguing the goal was to help Alibaba's Qwen model approach the capabilities of Anthropic's frontier Mythos Preview.

The figures are Anthropic's allegation. Alibaba has not publicly responded. This is not the first such allegation: in February 2026, Anthropic claimed DeepSeek, Moonshot AI and MiniMax collectively used 24,000 fraudulent accounts and 16 million exchanges for similar extraction. The June letter to senators Tim Scott and Elizabeth Warren positions the Alibaba campaign as more than twice as large and as occurring after the White House had already warned publicly about industrial-scale Chinese model theft.

Anthropics proposed legislative response is threefold: update antitrust laws so AI companies can share threat intelligence, tighten export controls on high-end chips, and create specific penalties for labs engaged in unauthorised distillation. The enterprise security implication flagged by analysts is significant: model extraction does not require hacking in the traditional sense. It requires only scale, automation and patience to interact with a public API in a structured way. Detecting and blocking it requires AI companies to identify unusual query patterns without blocking legitimate high-volume API customers.


Fam28

28.8 million structured queries through 25,000 fake accounts between April and June is not a casual experiment. This is an industrial operation that required significant planning, automation infrastructure and coordination. That is what makes Anthropic's Chinese government complicity allegation plausible
404: Signature not found

Jackson77

The distillation attack not requiring traditional hacking is the security insight that enterprises building on closed AI APIs need to internalise. The attack surface is the API itself, available to anyone with a credit card and patience

Phil80

Anthropic going to the Senate Banking Committee rather than a press release is a deliberate choice to frame this as a legislative and national security matter rather than a commercial dispute. The strategy maximises pressure on Alibaba through government channels

Harbour

If the alleged campaign could help Alibaba build a Mythos-class model at a fraction of the cost, the economics of frontier AI development are genuinely undermined for American companies. That is the argument Anthropic is making and it is a coherent one regardless of what you think of the company
My team is always one signing away

Luca73

The IQM error correction milestone and the JalapeƱo chip announcement and this Alibaba allegation all in the same week illustrate how the AI and quantum technology competition is playing out simultaneously at the hardware, software and IP levels

NeuralTrace26

Detecting 25,000 fake accounts making 28.8 million structured queries while keeping the API available for legitimate high-volume customers is genuinely hard. What patterns distinguish malicious distillation from legitimate stress testing or benchmarking

Dave_52

Alibaba's Qwen models having legitimate independent capabilities makes the allegation harder to prove in court. You would need to demonstrate specific capability transfer from Claude outputs to Qwen behaviour, not just demonstrate that they ran many queries

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer