Anthropic accuses Alibaba of using 25,000 fake accounts to steal Claude AI capabilities

2 Sources

Share

Anthropic has accused Alibaba of orchestrating the largest known attack against its systems, allegedly using nearly 25,000 fraudulent accounts to extract capabilities from Claude AI models. The campaign generated 28.8 million queries between April and June, employing a technique called distillation to potentially replicate advanced AI capabilities at lower cost.

Anthropic Reports Massive AI Model Distillation Attack

Anthropic has accused Alibaba of conducting what it describes as the largest known distillation attack against its Claude AI models, involving nearly 25,000 fake accounts and generating over 28.8 million queries

1

. The alleged large-scale model-extraction effort took place between April 22 and June 5, according to a letter Anthropic sent to senior members of the US Senate Banking Committee on June 10

2

.

Source: New York Post

Source: New York Post

The Dario Amodei-led company detailed the alleged violation of its terms of service in correspondence with Senators Tim Scott and Elizabeth Warren, claiming operators affiliated with Alibaba and its Qwen AI lab conducted 28.8 million exchanges with Claude models using fraudulent accounts

2

. Anthropic characterized Alibaba's actions as "brazenly" and "illicitly" attempting to extract capabilities from Claude AI, representing a significant escalation in AI security threats facing American companies.

Understanding the Distillation Technique Used to Replicate AI Capabilities

The attack employed distillation, a technique in which a less capable AI model is trained on the outputs of a more advanced system

1

. This AI model distillation attack method potentially allows rivals to replicate AI capabilities at significantly lower cost, bypassing the substantial investment required to develop sophisticated models from scratch. By feeding Claude's responses into their own systems, the alleged attackers could train smaller models to mimic the performance of Anthropic's more advanced technology.

Source: InfoWorld

Source: InfoWorld

This approach poses a fundamental threat to AI companies that invest billions in research and development. The ability to illicitly rip off AI capabilities through mass querying undermines competitive advantages and raises questions about how AI firms can protect their intellectual property in an increasingly hostile landscape. For Anthropic, which competes directly with OpenAI and Google in the frontier AI space, such attacks threaten both its market position and its ability to maintain technological leadership.

Growing Pattern of Chinese AI Models Targeting US Systems

This incident marks the fourth major distillation campaign Anthropic has identified from Chinese AI labs. In February, the company reported three other "industrial-scale" distillation campaigns from DeepSeek, Moonshot, and MiniMax

2

. Anthropic warned that these campaigns are becoming more sophisticated and intense, signaling an escalating pattern of attempts to extract capabilities from leading US AI models.

The timing of Alibaba's alleged campaign is particularly notable, coming after the White House Office of Science and Technology Policy issued a memorandum pledging to assist AI companies in detecting and coordinating against mass distillation. Anthropic claimed that Alibaba "ignored the Trump Administration's warnings"

2

, suggesting the attack proceeded despite heightened government scrutiny and public warnings about such practices.

Implications for American AI Leadership

The flood of powerful, cheap-to-use Chinese AI models has experts warning that America's lead in artificial intelligence could be at risk. China's z.AI released an open-source model called GLM-5.2 on June 16 that specializes in coding projects, with the company claiming it matches the capabilities of some of the best models offered by Anthropic, OpenAI, and Google

2

.

An Anthropic spokesperson emphasized the need for coordinated action: "We believe combating the threat of illicit distillation requires coordinated action between government and industry, and we will continue working with Congress and the Administration to maintain American AI leadership"

2

. The company has encouraged policymakers and other tech firms, including cloud providers, to collaborate in thwarting future attacks.

The incident highlights the tension between open competition in AI development and protecting proprietary technology. As Chinese AI models continue to advance rapidly, questions arise about whether current safeguards are sufficient to prevent the systematic extraction of capabilities that took years and substantial resources to develop. Recent weeks have also seen Anthropic clash with the White House over security concerns related to its powerful "Fable" and "Mythos" models, adding another layer of complexity to the company's operational environment

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved