Anthropic says Alibaba ran the largest known AI distillation attack on record, extracting 57.6 billion tokens from Claude through 25,000 fake accounts.
Anthropic says Alibaba ran the largest known AI distillation attack on record, extracting 57.6 billion tokens from Claude through 25,000 fake accounts.

Anthropic told Congress that Alibaba siphoned 57.6 billion tokens from Claude through 25,000 fraudulent accounts, the largest known AI distillation attack, targeting agentic reasoning and software engineering.
"These distillation attacks are carried out illicitly, systematically, and at industrial scale to harvest US AI capabilities across frontier labs and repackage them as their own without incurring the training and R&D costs required to train US frontier models," Anthropic wrote in a June 10 letter to Congress.
The campaign ran from April to June 2026, with 28.8 million prompt-response exchanges across roughly 90 days. Each fake account averaged 12.8 exchanges per day — a volume indistinguishable from ordinary users, which is why the operation escaped detection. The haul, roughly 576,000 books' worth of digital knowledge, targeted Claude's most valuable capabilities: agentic reasoning, software engineering, and long-horizon tasks.
The theft exposes a widening gap in US AI export controls. Anthropic called on Congress to mandate threat-information sharing between US labs, close loopholes letting Chinese labs access advanced chips, and penalize labs behind distillation attacks — a push that follows a White House memorandum on "Adversarial Distillation of American AI Models" and comes as Alibaba, listed on the New York Stock Exchange, faces mounting scrutiny over its AI practices.
Distillation is a standard technique in which a large model acts as a teacher, transferring knowledge to a smaller "student" model. Anthropic and other labs use it legitimately to build small language models. The illegal variant flips the arrangement: an attacker submits millions of ordinary-looking prompts to a rival's model, records the responses, and feeds those prompt-response pairs into its own model to train it on proprietary capabilities without paying for the underlying research.
The stealth is the point. A distillation attack requires no exploit — just prompts and responses. Alibaba's operation spread 28.8 million exchanges across 25,000 accounts, keeping each account at roughly 12 to 13 exchanges per day, a cadence that mimics a normal user. With major models like OpenAI's ChatGPT serving about 1 billion weekly active users, a few thousand new accounts draw no attention.
Anthropic's letter puts the scale in context. At roughly 2,000 tokens per exchange, the 28.8 million exchanges yielded about 57.6 billion tokens — the equivalent of 576,000 average-length books. That is a fraction of the 10 trillion to 15 trillion tokens a frontier model typically trains on, but the comparison misses the point: distillation harvests refined, hard-to-replicate knowledge rather than raw web data. Stealing even a small slice of Claude's agentic-reasoning and software-engineering capabilities could save Alibaba's Qwen lab years of research and billions in training cost.
The incident is part of a broader pattern. The White House Office of Science and Technology Policy, led by Michael Kratsios, published a memorandum on "Adversarial Distillation of American AI Models" earlier this year, and Treasury Secretary Scott Bessent has warned that "sanctions and Entity List designations will be on the table" for Chinese firms conducting industrial-scale distillation. The same enforcement gap has surfaced around Moonshot AI's Kimi K3, a 2.8-trillion-parameter model trained on roughly 20,000 Nvidia chips supplied through Alibaba's cloud, and around Singapore-based cloud provider Megaspeed, which is under US investigation for allegedly diverting Nvidia hardware to China.
Anthropic's letter proposes three fixes: threat-information sharing between US AI labs, closing loopholes that let Chinese labs access advanced US chips, and penalties for labs behind distillation attacks. The Chip Security Act (H.R. 3447), which passed the House Foreign Affairs Committee in March, would require embedded location-verification in exported chips — a hardware-level answer to a paper-based compliance system that cannot track where chips actually operate.
For investors, the stakes are concrete. Alibaba's Qwen lab, which competes with Anthropic's Claude and OpenAI's GPT-5, stands accused of harvesting a rival's intellectual property at a fraction of the cost of building it. Anthropic, which has not disclosed the financial impact, faces a persistent threat to its most valuable asset: the proprietary reasoning embedded in Claude. The cat-and-mouse game is unlikely to end — as Sun Tzu put it, "There is no place where espionage is not possible."
This article is for informational purposes only and does not constitute investment advice.