← Reddit

Anthropic just told the US Senate that Alibaba ran 25,000 fake accounts and had 28.8 million conversations with Claude — not to use it, but to copy it

Reddit · RajmaChawala · July 14, 2026
Anthropic reported to the US Senate that Alibaba used 25,000 fake accounts and conducted 28.8 million conversations with Claude over six weeks to extract and replicate its agentic reasoning and coding capabilities for training Qwen. The distillation attack, conducted through standard API access at industrial scale without hacking, represented the largest such attack in Anthropic's history, surpassing those by DeepSeek, Moonshot, and MiniMax combined. Anthropic reported the incident to Congress rather than filing suit because the activity does not clearly violate current law.

Detailed Analysis

Anthropic's letter to the US Senate details what the company describes as the largest AI "distillation attack" in its history: a coordinated operation involving roughly 25,000 accounts, allegedly linked to Alibaba, that generated 28.8 million conversations with Claude over a six-week window between April and June. Unlike a conventional security breach, this was not the result of hacking or exploiting a vulnerability—the accounts simply used Anthropic's public API as paying customers would, but at an industrial scale designed to systematically extract Claude's reasoning patterns, coding methodology, and agentic decision-making processes. The captured outputs were reportedly used to train Alibaba's Qwen models, allowing a competitor to shortcut years of foundational research and compute investment by learning directly from a rival's finished product.

The scale of this incident is significant on its own, with Anthropic characterizing it as larger than similar distillation efforts previously attributed to DeepSeek, Moonshot, and MiniMax combined. But the more consequential detail is procedural: Anthropic chose to escalate this to Congress via letter rather than pursue litigation, because mass-scale distillation through ordinary API access does not clearly violate existing law. Terms of service violations exist, but they are civil matters typically resolved through account suspension, not criminal or strong civil liability frameworks. This ambiguity is precisely why Anthropic is seeking legislative attention—the company is effectively arguing that current law has no adequate mechanism to address this kind of extraction, even though the economic and strategic harm is substantial.

This matters because distillation attacks strike at the core economics of frontier AI development. Companies like Anthropic, OpenAI, and Google spend enormous sums on compute, data curation, RLHF, and safety testing to produce models with strong reasoning and coding abilities. If a competitor can replicate much of that capability by simply querying the finished API at scale and training a new model on the outputs, the incentive to make that upfront investment erodes. This is especially acute in the US-China AI competition, where firms like Alibaba, DeepSeek, and Moonshot have repeatedly been able to produce highly capable open-weight models at a fraction of the reported training cost—raising persistent questions about how much of that efficiency comes from genuine innovation versus distillation from Western frontier models.

The episode also connects to broader export-control and policy debates, including restrictions like the reported Fable 5 export ban, which reflect growing US government concern that even non-hardware pathways—API access, cloud inference, model outputs—can transfer strategically valuable AI capability to competitors, including those with ties to geopolitically sensitive jurisdictions. Anthropic's decision to go public and lobby Congress rather than quietly patch its terms of service signals that the company views this as an industry-wide structural problem requiring new legal categories, potentially covering rate-limiting circumvention, output-scraping at scale, and cross-border model training pipelines. Whether lawmakers treat mass distillation as actionable IP theft, a national security issue, or simply aggressive but permissible competitive behavior will likely shape how frontier labs architect API access, pricing, and monitoring going forward, and could set precedent for how AI-generated outputs are legally treated as protectable assets.

Read original article →