Crypto news

26.06.2026
10:43

Alibaba in the Crosshairs: Anthropic Reveals the Largest Claude Distillation Attack

ии-стартап Anthropic AI

Anthropic has uncovered a large-scale campaign to illegally distill its flagship model, Claude. According to the company, operators linked to China's Alibaba and its AI lab Qwen orchestrated an attack that has become the largest known in the industry.

From April 22 to June 5, attackers used nearly 25,000 fake accounts to generate over 28.8 million queries to Claude. The goal was to extract the model's key capabilities in agentic tasks, software development, and long-term planning.

In a letter addressed to U.S. Senate Banking Committee Chairman Tim Scott and Senator Elizabeth Warren, Anthropic emphasized the "brazen nature" of the attack. Alibaba, as a public company listed on the New York Stock Exchange, conducts business in the U.S. and is accountable to American investors and regulators. This makes the situation particularly sensitive.

Distillation itself is a common practice, allowing the creation of more compact and cheaper versions of models. However, the problem arises when competitors use fake accounts to bypass restrictions and train their own systems at the expense of others' intellectual labor and investments.

Anthropic stresses that such actions undermine the economic model underpinning U.S. leadership in AI. Chinese labs gain access to cutting-edge capabilities without bearing the training costs, which run into billions of dollars. Moreover, the company warns that distilled models could be used for cyber operations, military tasks, and intelligence gathering.

What Anthropic is Demanding from Congress

The company calls for expanded sharing of technical indicators between AI developers and the U.S. government. It also proposes clarifying antitrust laws so that firms can share information about attacks without risking violations of competition laws.

A separate set of proposals concerns export controls. Anthropic insists on tightening restrictions on the supply of advanced AI chips and computing resources, as well as closing loopholes that allow Chinese organizations to access foreign data centers. The company suggests imposing sanctions on those responsible for large-scale extraction of model capabilities.

Context and Precedents

This is not the first time Anthropic has faced such attacks. Previously, the company accused DeepSeek, Moonshot AI, and MiniMax of generating over 16 million interactions with Claude. Those campaigns were linked to specific labs via IP addresses and metadata.

Notably, distillation remains a controversial topic. Elon Musk himself admitted that xAI "partially" used OpenAI's models when training Grok. However, in the case of Chinese labs, it involves systematic and large-scale data extraction through fake accounts, going beyond standard industry practice.

Expert opinion: This incident is an alarming signal for the entire industry. It demonstrates that geopolitical competition in AI is entering a new phase, where intellectual property and access to computing resources become targets of deliberate attacks. Tightening export controls and legislation is only part of the solution. Without a global dialogue on distillation standards and model protection, we risk facing an escalation of the "cold war" in artificial intelligence.