skip to content
ai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILURE
BAD/GATEWAY*

ANTHROPIC ACCUSES ALIBABA OF STEALING CLAUDE SECRETS

The AI company told U.S. senators that Chinese rival ran nearly 29 million exchanges with its model in three months.

by editor5 min readcomments soon

Anthropic says Alibaba used 25,000 fake accounts to steal Claude’s secrets
· AI GENERATED

Anthropic has accused Alibaba of running a massive online deception campaign that used 25,000 fake accounts to carry out nearly 29 million illicit exchanges with its Claude AI model. The company brought the accusation directly to U.S. senators, presenting evidence that Alibaba created fraudulent accounts to bypass access restrictions and used Claude’s responses to train its own competing models.

The campaign took place between April and June 2026, a three-month window in which Anthropic says Alibaba employees and affiliates systematically queried Claude through thousands of fake profiles. Anthropic traced more than 25,000 of those accounts to operators with clear ties to Alibaba and its Qwen model line. The company described the activity as "distillation attacks", a technique where a competitor runs a model’s own API against itself to extract its behaviour, then uses that data to replicate or improve its own system.

THE DISTILLATION CAMPAIGN

Distillation attacks are not new. They are a known vulnerability for any company that offers a paid or free API tier with usage limits. The attacker creates many accounts to stay under rate limits and detection thresholds, then systematically prompts the target model across a wide range of inputs. The goal is to harvest enough output pairs to train a substitute model that approximates the original’s performance.

What makes this case stand out is the scale. Twenty-five thousand accounts is an industrial effort, far beyond the handful of test accounts a smaller research group might create. Twenty-eight point eight million exchanges means a sustained operation running around the clock for weeks. That level of compute and coordination is hard to attribute to anyone other than a well-resourced organisation. Anthropic says it attributed the accounts to Alibaba and Alibaba Qwen, suggesting the company had evidence beyond IP addresses.

A GEOPOLITICALLY CHARGED SITUATION

This accusation arrives in a moment when US-China tech tensions are widening across raw materials, chip supply chains, and AI itself. Alibaba is simultaneously suing the Pentagon to be removed from a blacklist of firms allegedly linked to the People’s Liberation Army. The company denies those allegations, but the blacklist designation has hindered its ability to do business with US partners.

On the US side, the government is working to reduce reliance on Chinese tech through an effort called “Pax Silica” that aims to secure alternative supply chains for semiconductors, rare earths, and other strategic components. Several European governments and the European Union joined the initiative this week. The Anthropic accusation adds a direct intellectual-property theft charge to a landscape already shaped by export controls, tariff disputes, and national security investigations.

WHAT COMES NEXT

Anthropic’s decision to escalate to senators rather than fight Alibaba through a private cease-and-desist suggests the company wants a regulatory or diplomatic response. It could prompt US lawmakers to ask whether existing API abuse protections are sufficient, or whether they need to be encoded into broader AI governance frameworks. It also raises questions about how many other Chinese firms are running similar distillation campaigns against US models, and how many are succeeding without detection.

For Alibaba, the charge lands hard because distillation is hard to prove convincingly in public, but harder to deny if the accuser has account-level forensics. The broader legal fight over the Pentagon blacklist will test whether the US government treats a large Chinese tech firm differently when it is accused of cyber-enabled IP theft versus geopolitical association.

THE TECHNICAL ARMS RACE

Distillation defence is becoming a field of its own. Companies like Anthropic and OpenAI already deploy rate limiting, behavioural anomaly detection, and output watermarking to make large-scale extraction harder. But attackers adapt. Fake accounts with realistic browsing patterns, residential proxy networks, and account credential stuffing are getting harder to distinguish from legitimate users.

What Anthropic alleges here is a case where those defences were evidently not enough for a three-month window. The company presumably has since closed the gap, but the fact that 25,000 accounts could operate undetected that long suggests a fundamental asymmetry: defenders need to catch every attempt, while attackers only need one success.

WHY THIS MATTERS

The 29 million exchanges figure is the headline, but the bigger issue is that model distillation is a zero-sum threat for companies that invest billions in training. If a competitor can replicate a model’s capabilities for the cost of API fees and some engineering time, the moat is gone. That logic is driving the industry toward more aggressive detection, more restrictive API tiers, and eventually toward model weights that are simply not served through public API endpoints.

For now, Anthropic’s accusation is a shot across the bow. It tells the market that no API is safe from a determined adversary and that the US-China tech rivalry now has a new front: the quiet theft of the intelligence inside models. Whether Congress responds with new laws, trade measures, or simply a louder alarm, the incident marks a point of no return for how the industry thinks about API security.


what did you make of it?

share

more from ai