Industry·3 min read
By BitsMindsSource: The Next Web

Anthropic Accuses Alibaba of Mass Claude Distillation

Anthropic told the White House and U.S. senators that Alibaba’s Qwen lab used roughly 25,000 fake accounts to run nearly 28.8 million Claude queries between April and June — harvesting its coding and agent skills in what Anthropic calls the largest distillation campaign it has ever documented. Alibaba declined to comment.

Anthropic accuses Alibaba Its largest reported distillation campaign against Claude CLAUDE the source QWEN a cheaper copy 28.8M queries ≈ 25,000 fake accounts April 22 – June 5 targeted: coding + agents reported to the White House BITSMINDS.COM Source: Anthropic letter
Share:

Anthropic has accused Chinese technology giant Alibaba of running the largest campaign it has ever documented to copy its Claude models — telling U.S. senators and White House officials that operators tied to Alibaba's Qwen AI lab used roughly 25,000 fraudulent accounts to generate nearly 28.8 million exchanges with Claude between April 22 and June 5, 2026. The queries, Anthropic alleges, were engineered to harvest Claude's most valuable skills: software engineering and agentic reasoning.

The technique at issue is distillation — feeding carefully constructed prompts to a frontier model, collecting its responses, and using that data to train a cheaper rival that approximates the original's behavior. Done at scale, it lets a competitor short-circuit the hundreds of millions of dollars and years of research that went into the source model. By focusing on coding and agent tasks, Anthropic says, the operation went straight for the capabilities that are hardest to build and most lucrative to sell.

What makes this filing notable is the scale and the target. The single Alibaba campaign, by Anthropic's count, exceeded the combined volume of the three Chinese startups it named in February — DeepSeek, MiniMax and Moonshot AI — which together ran some 16 million exchanges through about 24,000 fake accounts. It is also the first time Anthropic has publicly named a major Chinese conglomerate rather than a startup. The company stressed that the activity continued after an April White House memo had explicitly flagged distillation as a national-security concern — in its framing, in open defiance of Washington's warnings.

Anthropic is using the episode to press for policy action: clearer antitrust guidance so AI firms can share information about distillation campaigns, renewed support for export controls on advanced AI chips, and penalties for companies caught using the technique. The asks land amid an already tense stretch of U.S.–China AI policy, from chip restrictions to the recent export-control directive that pulled Anthropic's own Fable 5 offline. Alibaba, for its part, declined to comment on the allegations.

The accusation is, for now, exactly that — an allegation, with no independent adjudication and a flat non-response from the accused. But it crystallizes the question increasingly at the center of the AI race: when a model's outputs can be used to clone its hardest-won abilities, how does any lab protect what it spent billions to build — and can terms-of-service violations even be policed across borders?

More on Claude

Evergreen coverage we keep current — start here.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles

$11B SENIOR UNSECURED NOTES BITSMINDS.COM
Industry

SoftBank Sells $11B in Bonds to Fund Its OpenAI Tranche

417–3 in the House. One objection in the Senate. Editorial illustration of the stalled Ratepayer Protection Act, H.R. 9340. A large 417–3 House vote meets a single red senator and a closed stop line. Below, AI data centres drawing 100 MW or more connect through a transmission tower to a home and an electricity bill. Amber conduits link the industrial load, grid upgrades and household costs. The proposed large-load standard would assign full incremental grid-upgrade costs to data centres, but a senator blocked unanimous consent, objecting that states were only asked to consider the standard. H.R. 9340 RATEPAYER PROTECTION ACT 417–3 HOUSE VOTE ONE SENATOR. BILL BLOCKED. The objection: states only asked to “consider”. AI DATA CENTRES 100 MW+ GRID UPGRADES WHO PAYS? BILL $ HOUSEHOLD BILLS BITSMINDS.COM
Industry

House Votes 417–3 to Make Data Centers Pay for the Grid

Hacktron: from an image upload to an internal repository An oversized HEIC photo file is connected by an electric green line to two glass security gates, labelled Forum and SSO, then to a dark repository cabinet bearing the OpenAI emblem and a pull-request symbol. A separate Claude Opus 5 plaque credits the model used by the researchers. The top caption says disclosed and patched. This is a conceptual illustration of Hacktron's reported security research and vulnerability chain. The two gates represent the two reported flaws, and their open padlocks are a visual metaphor. Original vector editorial illustration for BitsMinds, hacktron-claude-opus-5-openai-exploit-chain. 18 September 2026. Conceptual architecture based on the article, not a real interface or technical system diagram. HACKTRON / SECURITY RESEARCH DISCLOSED & PATCHED .HEIC IMAGE UPLOAD 01 FORUM IMAGE PROCESSING 02 SSO SIGN-IN TRUST INTERNAL REPO PULL REQUEST OPENED CLAUDE OPUS 5 RESEARCH ASSISTANT TWO FLAWS. ONE CHAIN. BITSMINDS.COM
Industry

Claude Opus 5 Wrote the Exploit That Broke Into OpenAI