Skip to main content
Live
Main content

Anthropic accuses Alibaba of 28.8M-query distillation attack on Claude

A letter to the Senate Banking Committee calls it the largest known distillation attack on Anthropic to date.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

Anthropic has accused Alibaba of running the largest known distillation attack on its models, telling the US Senate that operators tied to the Chinese company and its AI lab pushed 28.8 million queries through Claude between April 22 and June 5 using roughly 25,000 fraudulent accounts. The accusation was delivered in a June 10 letter to the Senate Committee on Banking, Housing, and Urban Affairs, addressed to Sens. Tim Scott and Elizabeth Warren, and confirmed Wednesday by CNBC after Bloomberg first reported its existence.

Distillation is a training shortcut: a smaller model learns by ingesting the outputs of a larger, more capable one. Anthropic argues the scale and structure of the Alibaba activity make it the most aggressive instance it has documented, dwarfing earlier incidents the company has attributed to other Chinese labs. Alibaba has not publicly responded.

Anthropic's letter said Alibaba carried out the campaign even after the White House Office of Science and Technology Policy issued a memorandum, two months before the letter, pledging to help US AI companies detect and coordinate against industrial-scale distillation. The company wrote that Alibaba had ignored the Trump administration's warnings in proceeding with the attacks.

Key facts

  • 01Anthropic told the Senate Banking Committee that Alibaba-linked operators ran 28.8 million exchanges with its models between April 22 and June 5.
  • 02The campaign used roughly 25,000 fraudulent accounts and is the largest known distillation attack on Anthropic to date.
  • 03Anthropic flagged three earlier industrial-scale distillation campaigns in February tied to DeepSeek, Moonshot, and MiniMax.
  • 04The letter was sent June 10 to Sens. Tim Scott and Elizabeth Warren, two months after a White House OSTP memorandum on the issue.
  • 05Anthropic separately faces a Trump administration export control directive ordering it to suspend foreign-national access to Claude Fable 5 and Mythos 5.

This is not the first time Anthropic has gone public with the playbook. In February the company identified three industrial-scale distillation campaigns it traced to DeepSeek, Moonshot, and MiniMax, and called for coordinated defenses across model providers, cloud platforms, and policymakers. The Alibaba claim escalates that pattern from three labs to four, with an order-of-magnitude jump in scale: 28.8 million exchanges over six weeks across 25,000 accounts is substantially larger than what Anthropic described earlier in the year.

The mechanics matter for the policy debate. US export controls on AI chips and frontier models are built on the assumption that the capability gap can be defended at the silicon and weights layer. Distillation routes around both. A foreign lab does not need access to the underlying weights or the H100s used to train them if it can run tens of millions of API calls and use the responses as training data. That is the loophole Anthropic is asking Congress to close.

We believe combating the threat of illicit distillation requires coordinated action between government and industry, and we will continue working with Congress and the Administration to maintain American AI leadership
Anthropic spokesperson, Anthropic

The letter lands at an awkward moment for the company's relationship with Washington. Earlier this month Anthropic received an export control directive from the Trump administration ordering it to suspend access to its latest Claude models — Fable 5 and Mythos 5 — for any foreign national, whether inside or outside the United States, including foreign-national Anthropic employees. The government cited national security authorities without specifying the concern.

Senior Anthropic staffers flew to Washington to meet with administration officials in the days after the directive. The company told CNBC that both parties are working quickly to get this resolved, but has not said when the affected models will come back online. CEO Dario Amodei was photographed at the G7 Summit in Évian-les-Bains, France on June 17, attending a working lunch on AI with G7 leaders and tech CEOs.

The dual storyline — Anthropic asking Washington for help against Chinese distillation while also negotiating with Washington over its own export restrictions — is the practical shape of US AI policy in 2026. Frontier labs want the government to police capability leakage abroad, and the government wants assurance that the same labs are not the leakage vector themselves. The Fable 5 and Mythos 5 suspension suggests officials are not yet satisfied on the second point.

Related · from this week
Anthropic says China labs ran 200M-exchange distillation attack on Claude
Jaeden Schafer · 5 min read →

Detection is the unresolved technical question. Anthropic has not published the methodology it used to attribute the 25,000 accounts to Alibaba, and distillation campaigns are notoriously hard to prove without account-level forensics that providers are reluctant to disclose. The company's February disclosures relied on similar attribution, and at least one of the named labs — DeepSeek — has previously denied distilling from Western models. Alibaba's silence so far means the public record on this specific campaign is one-sided.

The Senate Banking Committee is an unusual venue for an AI-security complaint, but it is the committee with jurisdiction over export controls and sanctions. Anthropic is effectively asking lawmakers to treat large-scale API abuse as an export-control matter, not just a terms-of-service violation. If that framing takes hold, it would push enforcement upstream — onto the model providers, who would be expected to detect and report — and downstream, onto foreign entities that could face sanctions for orchestrating fake-account campaigns.

For the broader market, the more interesting question is what this does to API access policy at every frontier lab. If Anthropic can document a 28.8-million-query distillation campaign run through fraudulent accounts, every competitor — OpenAI, Google, xAI, Meta — is presumably seeing similar activity at similar scale. Expect tighter KYC on enterprise API access, more aggressive rate-limiting on high-volume accounts from certain jurisdictions, and a quiet conversation in Washington about whether the next round of AI export controls should target query volume rather than chips. The distillation problem is not going away, and the policy tools built for the chip era do not fit it.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Anthropic says China labs ran 200M-exchange distillation attack on Claude

Alibaba, Moonshot AI, and DeepSeek tied to five campaigns harvesting Claude's reasoning traces, with one Moonshot request routed from the Chinese military.

Jaeden Schafer5 min read
Anthropic logo
Security

Sony Music and Warner Chappell sue Anthropic over Claude training data

Publishers accuse the AI lab of pirating millions of books containing lyrics and sheet music, building on the $1.5B Bartz precedent.

Jaeden Schafer5 min read
Anthropic logo
Security

Anthropic pulls Claude Fable 5 after Trump administration 90-minute ultimatum

A jailbreak warning from Amazon researchers triggered emergency export controls, taking Anthropic's newest public model offline within hours.

Jaeden Schafer5 min read