Skip to main content
Model DistillationExplainerJun 28, 2026, 4:19 PM· 4 min read

Explainer: How the 28.8 Million-Exchange 'Distillation Attack' on Claude is Reshaping AI Security

Anthropic has accused Alibaba of using 25,000 fake accounts to harvest millions of AI outputs, highlighting the growing battle over 'model distillation' and intellectual property.

By Karim Mansour

Frontier AI Labs 40%Enterprise Security Analysts 30%Open-Source Advocates 30%
Frontier AI Labs
View distillation as intellectual property theft that threatens national security and commercial leadership.
Enterprise Security Analysts
Focus on the shifting attack surface where AI outputs are the primary target.
Open-Source Advocates
Argue that distillation is a standard industry practice that democratizes AI access.

The most valuable asset in the artificial intelligence industry is no longer just the underlying code or the massive data centers powering it. It is the answers the models generate. As frontier AI labs pour billions of dollars into developing systems capable of complex reasoning, a new battleground has emerged over who gets to keep the fruits of that labor.

On June 10, Anthropic, the San Francisco-based maker of the Claude AI model, sent a stark warning to the United States Senate. The company alleged that Alibaba, the Chinese e-commerce and technology behemoth, had executed the "largest known distillation attack" to date against its systems.[4][5]

Between April 22 and June 5, operators affiliated with Alibaba's Qwen AI lab allegedly deployed roughly 25,000 fraudulent accounts to bypass Anthropic's security measures. Over those six weeks, the accounts conducted 28.8 million exchanges with Claude, systematically harvesting its outputs.[2]

The goal of this massive operation was not to hack Anthropic's servers or steal its source code. Instead, it was an industrial-scale effort to perform "model distillation"—a technique where a cheaper, less capable "student" model is trained on the high-quality answers generated by a state-of-the-art "teacher" model.[1]

Distillation allows a less capable model to learn from a state-of-the-art system, bypassing massive R&D costs.

By feeding Claude's outputs into its own systems, Alibaba could theoretically replicate Anthropic's advanced capabilities without incurring the massive research, development, and compute costs required to build a frontier model from scratch. Anthropic noted that the campaign specifically targeted Claude's most valuable skills, including agentic reasoning, software engineering, and long-horizon tasks.[2]

"These distillation attacks are carried out illicitly, systematically, and at industrial scale to harvest US AI capabilities across frontier labs and repackage them as their own without incurring the training and R&D costs," wrote Sarah Heck, Anthropic's head of policy, in the letter addressed to Senators Tim Scott and Elizabeth Warren.

The Alibaba accusation represents a massive escalation in a trend that has been quietly reshaping the AI landscape. In February 2026, Anthropic accused three other Chinese AI startups—DeepSeek, Moonshot AI, and MiniMax—of similar extraction campaigns.[1][3][4]

The Alibaba accusation represents a massive escalation in a trend that has been quietly reshaping the AI landscape.

However, the scale of the Alibaba operation dwarfs those previous incidents. DeepSeek's alleged operation involved roughly 150,000 exchanges, while Moonshot AI and MiniMax were accused of harvesting 3.4 million and 13 million interactions, respectively. The 28.8 million queries attributed to Alibaba represent more than double the previous largest attack.[3][4]

The alleged Alibaba campaign represents a massive escalation in the scale of model extraction efforts.

For enterprise security analysts, the incident highlights a fundamental shift in how digital assets must be protected. When a frontier model is exposed through an Application Programming Interface (API), the attack surface changes entirely. The model's outputs themselves become a strategic asset that competitors will inevitably try to capture.

"Beyond the Anthropic-Alibaba distillation allegation, enterprises should be more concerned about their own AI leakage risks," noted Kashyap Kompella, CEO of RPA2AI Research. He emphasized that public-facing AI applications can inadvertently leak sensitive business logic and proprietary workflows if they are systematically probed.

The challenge for AI companies is that distillation is incredibly difficult to stop. It requires distinguishing between a legitimate enterprise customer running millions of queries for a complex business application and an automated script designed to harvest training data.

Complicating matters further is the fact that distillation itself is not inherently malicious. It is a standard, widely used technique within the AI research community to create smaller, more efficient models that can run locally on smartphones and laptops. The controversy arises when the technique is used to cross corporate and geopolitical boundaries without permission.

Some open-source advocates argue that the panic over distillation is overblown, suggesting that a copy is a lagging indicator of leadership. Because a distilled model is always chasing the capabilities of the original teacher, it can never surpass it. In this view, the massive effort to copy Claude simply confirms Anthropic's significant technological lead.[3]

Nevertheless, the geopolitical stakes have transformed what might otherwise be a corporate terms-of-service dispute into a matter of national security. The US government recently placed export controls on Anthropic's most advanced models, Mythos 5 and Fable 5, to prevent foreign entities from accessing capabilities that could be used to compromise critical infrastructure.[1]

Anthropic has taken its concerns directly to the US Senate, pushing for legal safeguards against industrial-scale distillation.

Anthropic is now urging lawmakers to go further. The company is calling for coordinated action between the government and the private sector, including threat-intelligence sharing, stronger export controls, and the creation of formal legal penalties for industrial-scale distillation.[1][4]

As the AI industry moves forward, the era of frictionless, open API access may be coming to an end. Frontier labs are increasingly likely to implement draconian vetting processes for high-volume users, fundamentally altering how developers and enterprises interact with the world's most powerful AI systems.

The stakes

As AI becomes central to the global economy, the outputs of frontier models are now strategic assets. Understanding model distillation is crucial for enterprises, as it reveals how competitors can bypass billions in R&D to replicate advanced capabilities.

The essentials

  • Anthropic accused Alibaba's Qwen AI lab of conducting the largest known 'distillation attack' against its Claude model.
  • Operators allegedly used 25,000 fake accounts to harvest 28.8 million exchanges over a six-week period.
  • Distillation involves using a highly advanced AI to generate answers that train a cheaper, less capable model.
  • The campaign specifically targeted Claude's advanced capabilities in agentic reasoning and software engineering.
  • Anthropic has urged the US Senate to establish legal safeguards and penalties to protect American AI leadership.
  • Security analysts warn that AI model outputs have become strategic assets vulnerable to automated extraction.

Open questions

  • Whether the US Congress will introduce specific legislation criminalizing model distillation.
  • How Alibaba's Qwen AI lab will formally respond to Anthropic's allegations.
  • The exact technical methods Anthropic used to attribute the 25,000 fraudulent accounts to Alibaba-affiliated operators.

Glossary

Model Distillation
A training technique where a smaller AI model learns to mimic the behavior and outputs of a larger, more advanced model.
Frontier Model
The most advanced, state-of-the-art artificial intelligence systems, typically developed by well-funded labs like Anthropic, OpenAI, and Google.
Agentic Reasoning
The ability of an AI system to autonomously plan, break down complex problems, and execute multi-step tasks over time.
API (Application Programming Interface)
A software intermediary that allows different applications to communicate, which is how external users access cloud-based AI models.

Sources

Source coverage

5 outlets

3 viewpoints surfaced

Frontier AI Labs 40%Enterprise Security Analysts 30%Open-Source Advocates 30%
  1. [1]ForbesFrontier AI Labs

    Affordable Electricity And National Security

    Read on Forbes
  2. [2]Inc.Open-Source Advocates

    Anthropic Accused Alibaba of a Distillation Attack. Here's What That Means

    Read on Inc.
  3. [3]Forbes TechOpen-Source Advocates

    Former FBI Profiler: This Is What The Ransom Note Tells Us About Who Abducted Nancy Guthrie

    Read on Forbes Tech
  4. [4]ReutersFrontier AI Labs

    Anthropic says Alibaba illicitly extracted Claude AI model capabilities

    Read on Reuters
  5. [5]CNBCFrontier AI Labs

    Anthropic accuses Alibaba of campaign to 'brazenly' and 'illicitly' extract AI capabilities

    Read on CNBC

Comments

Stay informed

Every angle. Every day.

Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.