“This is not Anthropic complaining that a rival built a better chatbot. It is accusing one of China’s biggest tech companies of using fake accounts and millions of interactions to pull apart Claude’s strengths and feed them into its own models.”
Anthropic has accused Alibaba of carrying out what it describes as the biggest known “distillation” attack on its Claude AI platform, claiming operators linked to the Chinese tech giant extracted Claude’s capabilities through a huge network of fraudulent accounts over several weeks.
The allegation is laid out in a letter Anthropic sent to senior US lawmakers earlier this month, and it gives a striking sense of the scale the company says it was dealing with. According to Anthropic, the campaign ran from April 22 to June 5 and generated more than 28.8 million exchanges with Claude through almost 25,000 fake accounts. The company says the activity was tied to individuals affiliated with Alibaba and Qwen, Alibaba’s AI arm. Alibaba did not immediately respond to Reuters’ request for comment.
The word Anthropic is using here is distillation, and in AI circles that has become one of the most sensitive fights in the business.
In simple terms, distillation is a way of training a smaller or less capable model by feeding it the outputs of a stronger one. There are legitimate versions of that inside a company’s own development work. What Anthropic is alleging is something very different: that Claude was effectively mined at industrial scale by a competitor trying to absorb its reasoning and product capabilities without paying the research cost of building them from scratch. Anthropic says the goal was to help accelerate China’s ability to reach the level of its advanced Mythos Preview system.
That is why this matters beyond a corporate spat.
Anthropic did not send the letter into a vacuum. It was addressed to Senator Tim Scott and Senator Elizabeth Warren ahead of a Senate Banking Committee hearing on AI, which means the company was clearly trying to push this into the center of Washington’s national security conversation. In the letter, Anthropic backed stronger government action against these kinds of attacks, including closer intelligence sharing between the US government and private AI companies.
And this was not even the first time Anthropic had pointed the finger at Chinese AI firms.
Back in February, the company said DeepSeek, Moonshot AI and MiniMax had also used Claude to improperly obtain capabilities for their own models. Anthropic said those campaigns involved millions of exchanges as well, though the Alibaba operation is described as far larger. The company has been warning for months that these attempts are becoming more sophisticated and more aggressive.
SEE ALSO: Anthropic Files for IPO as AI Race With OpenAI Enters New Stage
That wider context matters because the accusation lands in the middle of a much bigger US-China technology standoff.
Washington has spent the last two years tightening export controls on advanced chips and increasingly treating frontier AI as a strategic asset rather than just a commercial product. Anthropic has leaned into that argument more openly than some of its rivals, often saying that advanced model capabilities should be protected not just as intellectual property, but as national-security infrastructure. In this case, the company argues that large-scale distillation attacks can help rivals leapfrog expensive research and get closer to powerful frontier systems without having to build the whole stack themselves.
There is also a timing wrinkle that makes the whole thing more awkward.
Just two days after Anthropic sent the letter, the US Commerce Department imposed restrictions on Anthropic’s latest Mythos and Fable models over fears they could be used by military intelligence actors in China and other countries of concern. Anthropic responded by disabling access to those models globally. So at the same moment it is warning lawmakers that Chinese-linked actors are trying to siphon off Claude’s capabilities, the US government is also constraining how Anthropic can distribute some of its own most advanced systems.
For Alibaba, the allegation adds to an already sensitive period.
The company was recently added to the Pentagon’s list of Chinese military-linked companies, a designation it is challenging. Now it is facing a public accusation from one of the most important AI labs in the US that people linked to its AI unit used a massive fake-account operation to extract frontier model behaviour from Claude. Anthropic has not publicly released the full technical evidence behind the claim, and Alibaba has not yet answered it in detail. So for now, the accusation is serious, but still one-sided in public.
Even so, it says a lot about where the AI race is heading.
The competition is no longer just about who can build the best model or raise the most money. It is also about who can protect model outputs, who can stop capability leakage, and how governments decide to treat AI systems that are increasingly being described in the language of strategic technology rather than ordinary software.
Anthropic is essentially saying that the fight over frontier AI has already moved into a more covert phase, where what matters is not just training your own model, but preventing somebody else from quietly learning from it at scale.





