Explainer: How the 28.8 Million-Exchange 'Distillation Attack' on Claude is Reshaping AI Security
Anthropic has accused Alibaba of using 25,000 fake accounts to harvest millions of AI outputs, highlighting the growing battle over 'model distillation' and intellectual property.
- Frontier AI Labs
- View distillation as intellectual property theft that threatens national security and commercial leadership.
- Enterprise Security Analysts
- Focus on the shifting attack surface where AI outputs are the primary target.
- Open-Source Advocates
- Argue that distillation is a standard industry practice that democratizes AI access.
The most valuable asset in the artificial intelligence industry is no longer just the underlying code or the massive data centers powering it. It is the answers the models generate. As frontier AI labs pour billions of dollars into developing systems capable of complex reasoning, a new battleground has emerged over who gets to keep the fruits of that labor.
On June 10, Anthropic, the San Francisco-based maker of the Claude AI model, sent a stark warning to the United States Senate. The company alleged that Alibaba, the Chinese e-commerce and technology behemoth, had executed the "largest known distillation attack" to date against its systems.[4][5]
Between April 22 and June 5, operators affiliated with Alibaba's Qwen AI lab allegedly deployed roughly 25,000 fraudulent accounts to bypass Anthropic's security measures. Over those six weeks, the accounts conducted 28.8 million exchanges with Claude, systematically harvesting its outputs.[2]
The goal of this massive operation was not to hack Anthropic's servers or steal its source code. Instead, it was an industrial-scale effort to perform "model distillation"—a technique where a cheaper, less capable "student" model is trained on the high-quality answers generated by a state-of-the-art "teacher" model.[1]
By feeding Claude's outputs into its own systems, Alibaba could theoretically replicate Anthropic's advanced capabilities without incurring the massive research, development, and compute costs required to build a frontier model from scratch. Anthropic noted that the campaign specifically targeted Claude's most valuable skills, including agentic reasoning, software engineering, and long-horizon tasks.[2]
"These distillation attacks are carried out illicitly, systematically, and at industrial scale to harvest US AI capabilities across frontier labs and repackage them as their own without incurring the training and R&D costs," wrote Sarah Heck, Anthropic's head of policy, in the letter addressed to Senators Tim Scott and Elizabeth Warren.
The Alibaba accusation represents a massive escalation in a trend that has been quietly reshaping the AI landscape. In February 2026, Anthropic accused three other Chinese AI startups—DeepSeek, Moonshot AI, and MiniMax—of similar extraction campaigns.[1][3][4]
The Alibaba accusation represents a massive escalation in a trend that has been quietly reshaping the AI landscape.
However, the scale of the Alibaba operation dwarfs those previous incidents. DeepSeek's alleged operation involved roughly 150,000 exchanges, while Moonshot AI and MiniMax were accused of harvesting 3.4 million and 13 million interactions, respectively. The 28.8 million queries attributed to Alibaba represent more than double the previous largest attack.[3][4]
For enterprise security analysts, the incident highlights a fundamental shift in how digital assets must be protected. When a frontier model is exposed through an Application Programming Interface (API), the attack surface changes entirely. The model's outputs themselves become a strategic asset that competitors will inevitably try to capture.
"Beyond the Anthropic-Alibaba distillation allegation, enterprises should be more concerned about their own AI leakage risks," noted Kashyap Kompella, CEO of RPA2AI Research. He emphasized that public-facing AI applications can inadvertently leak sensitive business logic and proprietary workflows if they are systematically probed.
The challenge for AI companies is that distillation is incredibly difficult to stop. It requires distinguishing between a legitimate enterprise customer running millions of queries for a complex business application and an automated script designed to harvest training data.
Complicating matters further is the fact that distillation itself is not inherently malicious. It is a standard, widely used technique within the AI research community to create smaller, more efficient models that can run locally on smartphones and laptops. The controversy arises when the technique is used to cross corporate and geopolitical boundaries without permission.
Some open-source advocates argue that the panic over distillation is overblown, suggesting that a copy is a lagging indicator of leadership. Because a distilled model is always chasing the capabilities of the original teacher, it can never surpass it. In this view, the massive effort to copy Claude simply confirms Anthropic's significant technological lead.[3]
Nevertheless, the geopolitical stakes have transformed what might otherwise be a corporate terms-of-service dispute into a matter of national security. The US government recently placed export controls on Anthropic's most advanced models, Mythos 5 and Fable 5, to prevent foreign entities from accessing capabilities that could be used to compromise critical infrastructure.[1]
Anthropic is now urging lawmakers to go further. The company is calling for coordinated action between the government and the private sector, including threat-intelligence sharing, stronger export controls, and the creation of formal legal penalties for industrial-scale distillation.[1][4]
As the AI industry moves forward, the era of frictionless, open API access may be coming to an end. Frontier labs are increasingly likely to implement draconian vetting processes for high-volume users, fundamentally altering how developers and enterprises interact with the world's most powerful AI systems.
The stakes
As AI becomes central to the global economy, the outputs of frontier models are now strategic assets. Understanding model distillation is crucial for enterprises, as it reveals how competitors can bypass billions in R&D to replicate advanced capabilities.
The essentials
- Anthropic accused Alibaba's Qwen AI lab of conducting the largest known 'distillation attack' against its Claude model.
- Operators allegedly used 25,000 fake accounts to harvest 28.8 million exchanges over a six-week period.
- Distillation involves using a highly advanced AI to generate answers that train a cheaper, less capable model.
- The campaign specifically targeted Claude's advanced capabilities in agentic reasoning and software engineering.
- Anthropic has urged the US Senate to establish legal safeguards and penalties to protect American AI leadership.
- Security analysts warn that AI model outputs have become strategic assets vulnerable to automated extraction.
Open questions
- Whether the US Congress will introduce specific legislation criminalizing model distillation.
- How Alibaba's Qwen AI lab will formally respond to Anthropic's allegations.
- The exact technical methods Anthropic used to attribute the 25,000 fraudulent accounts to Alibaba-affiliated operators.
Glossary
- Model Distillation
- A training technique where a smaller AI model learns to mimic the behavior and outputs of a larger, more advanced model.
- Frontier Model
- The most advanced, state-of-the-art artificial intelligence systems, typically developed by well-funded labs like Anthropic, OpenAI, and Google.
- Agentic Reasoning
- The ability of an AI system to autonomously plan, break down complex problems, and execute multi-step tasks over time.
- API (Application Programming Interface)
- A software intermediary that allows different applications to communicate, which is how external users access cloud-based AI models.
Sources
[1]ForbesFrontier AI LabsAffordable Electricity And National Security
Read on Forbes →
[2]Inc.Open-Source AdvocatesAnthropic Accused Alibaba of a Distillation Attack. Here's What That Means
Read on Inc. →
[3]Forbes TechOpen-Source AdvocatesFormer FBI Profiler: This Is What The Ransom Note Tells Us About Who Abducted Nancy Guthrie
Read on Forbes Tech →
[4]ReutersFrontier AI LabsAnthropic says Alibaba illicitly extracted Claude AI model capabilities
Read on Reuters →
[5]CNBCFrontier AI LabsAnthropic accuses Alibaba of campaign to 'brazenly' and 'illicitly' extract AI capabilities
Read on CNBC →
Comments
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.