- Anthropic claims Alibaba used roughly 25,000 fraudulent accounts to perform a massive 'model distillation' attack on Claude.
- The operation reportedly involved over 28.8 million interactions aimed at copying advanced reasoning and coding capabilities.
- U.S. lawmakers have been notified of the breach, which Anthropic frames as a significant threat to national security and intellectual property.
- The incident highlights a growing geopolitical struggle over AI supremacy, with calls for stricter export controls and antitrust updates.
The tech world is currently buzzing with a high-stakes controversy as Anthropic, the firm behind the Claude AI, has officially flagged a massive data extraction effort. According to reports, the company sent a detailed letter to U.S. senators and White House officials alleging that operators connected to Alibaba orchestrated an unprecedented campaign to siphon off its proprietary technology. This isn’t just a minor glitch in the system; we’re talking about a sophisticated operation that allegedly took place between April and June 2026.
It turns out that this wasn’t a traditional hack where someone breaks into a server. Instead, the strategy involved creating approximately 25,000 fake accounts to interact with Claude millions of times. By doing this, the Chinese tech giant supposedly aimed to use a technique known as “model distillation.” This process allows a smaller or less advanced AI to learn from a more powerful “teacher” model, effectively replicating high-level capabilities without the massive research and development costs usually required to build such systems from scratch.
The scale of the industrial extraction

The numbers involved in this dispute are quite staggering. Anthropic’s data suggests that these fraudulent accounts generated more than 28.8 million interactions with Claude. This volume is nearly double what was seen in previous incidents involving other Chinese labs like DeepSeek or Moonshot. To keep under the radar, those responsible allegedly used obfuscation techniques and proxy networks, making it look like legitimate traffic from around the globe rather than a coordinated attack from a single source.
The primary goal of this digital harvest seems to have been Claude’s most advanced features. Specifically, the queries were focused on agentic reasoning and software engineering. Since Claude is officially unavailable in China due to geographic restrictions, using thousands of fake identities was a way to bypass those barriers. Anthropic argues that this essentially turns billions of dollars in American investment into a subsidy for international competitors who are looking for a shortcut to the top of the AI food chain.
Geopolitics and security implications

This situation has quickly moved past a simple corporate disagreement and into the realm of national security. In their communication with the Senate, Anthropic leadership pointed out that if foreign entities can narrow the gap in AI capabilities through these methods, it could lead to advanced cyber-tools being deployed against government infrastructure. This is particularly sensitive given that Alibaba has faced increased scrutiny from the Pentagon recently regarding its ties to various technological initiatives.
To tackle this, Anthropic is pushing for some serious changes in how things are handled. They are suggesting three major legislative measures: updating antitrust laws so AI firms can share threat intelligence, tightening export controls on high-end chips, and creating specific penalties for labs that engage in unauthorized distillation. They believe that limiting computing power is one of the few ways to effectively slow down this type of industrial-scale imitation while protecting domestic innovation.
While the market has reacted with some volatility—Alibaba’s shares saw a dip following the news—the broader impact on the industry remains to be seen. Alibaba has generally remained quiet or denied claims of unauthorized technology use in the past, often pointing toward common industry practices regarding synthetic data. Regardless of the legal outcome, it is clear that the battle for AI supremacy is no longer just about who has the best code, but who can best protect their model’s unique way of thinking from being cloned through millions of automated conversations.