Anthropic accuses Alibaba of creating 25,000 fake accounts to ask Claude 28.8 million questions, then using the answers to beef up its own Qwen model. No passwords stolen, no firewalls breached: the attackers simply used Claude like any other customer. That's the whole problem, and it raises a question the law hasn't yet settled.
On 24 June 2026, Bloomberg revealed the existence of a letter. Dated 10 June, signed by Anthropic (the American lab behind Claude, the AI assistant we often cover here), and addressed to two US senators, Tim Scott and Elizabeth Warren. Its contents are explosive: Anthropic accuses Alibaba, the Chinese e-commerce and cloud giant, of having carried out "the largest distillation attack ever seen" against Claude.
The word "attack" conjures up hackers, viruses, breached servers. But there's none of that here. And that's precisely what makes this story fascinating, because it touches on a question few have asked: can you steal an artificial intelligence without ever breaking in anywhere?
First, what is "distillation"?
The technical term is model distillation. At its core, it's not an attack at all: it's a perfectly legitimate learning technique used throughout the industry.
The principle: you have a very powerful but heavy and costly model, called the "teacher". You want a smaller, faster, cheaper model, called the "student". Rather than training the student from scratch on billions of texts, you have it observe the teacher's responses, and it learns to imitate them. The student will never become as good as the teacher, but it gets close for a fraction of the cost.
Imagine a great Michelin-starred chef letting an apprentice watch every dish leave the kitchen, over and over. The apprentice never invented a single recipe. But by observing thousands of plates, they eventually reproduce the menu convincingly. That's distillation: you don't steal the recipe book, you simply watch enough dishes to recreate the menu.
The technique becomes an "attack by distillation" (or adversarial distillation) when applied to a competitor's model without authorisation. You take normal access to the API (the interface that lets software talk to the model), flood it with carefully crafted questions, collect all the answers, and use them to train your own AI to imitate the competitor's.
What Anthropic specifically accuses Alibaba of
According to the letter, operators linked to Alibaba and its Qwen AI lab allegedly generated more than 28.8 million exchanges with Claude between 22 April and 5 June 2026, through nearly 25,000 fraudulent accounts, using commercial proxy services to bypass the geographic restrictions that normally bar Chinese entities from accessing the model.
The campaign reportedly targeted Claude's most valuable capabilities: agentic reasoning (the ability to chain steps autonomously), coding, and completing long, complex tasks. In other words, exactly what distinguishes a frontier model from a basic AI.
For scale: in February 2026, Anthropic had already flagged similar campaigns from three Chinese labs (DeepSeek, Moonshot AI and MiniMax), totalling around 24,000 fake accounts and 16 million exchanges. The operation attributed to Alibaba would alone exceed the sum of the previous three. It's also the first time Anthropic has named a conglomerate of this global size.
Why it's almost impossible to prevent
Here's the technical heart of the problem, and it's deeper than it looks. A distillation request is indistinguishable from a normal request. At the API level, a question asked to steal the model's know-how looks exactly like a question from a legitimate developer.
The dizzying consequence: the only truly effective way to prevent distillation would be to refuse access to the model. But selling access to the model is Anthropic's entire business. The company is trapped by its own business model. That's exactly why it didn't just file a simple complaint for breach of terms of service: it went to the Senate. The problem isn't legal in the classic sense, it's structural.
The flip side: not everyone buys it
For the sake of honesty, it must be said clearly: these figures are Anthropic's allegations, not verified facts. Alibaba denies it and says it does not train its models on the outputs of others' proprietary models. None of the data (the 25,000 accounts, the 28.8 million exchanges) has been verified by an independent third party to date.
Several analysts point to flaws. How can you attribute 25,000 anonymous accounts to a specific company with certainty, rather than to a third party that might have used Qwen as a cover? And the timeline raises questions, since some of the targeted capabilities were not yet publicly available during the supposed attack window. Caution is warranted: this is a serious and plausible accusation, not a conviction.
Two days after this letter was sent, the US government restricted Anthropic's own models, Fable 5 and Mythos 5, for national security reasons, as we covered in our article on the cut-off. Anthropic thus finds itself on two fronts at once: asking the state to protect it from Chinese theft, while fighting that same state restricting its products. An uncomfortable position.
The real stakes: creating a legal boundary around software
Beyond the duel between two companies, the case raises a question that concerns us all. Today, there is no legal definition of adversarial distillation. A dispute of this scale with no law to settle it usually ends up forcing the creation of such a law, whether through legislation or the courts.
US senators are already preparing amendments to sanction foreign companies that illegally extract the outputs of American models. If a definition emerges, we can expect much stricter terms of service, systematic identity verification to access the most sensitive models, and formalised information sharing between labs.
And that's where it gets philosophical. For centuries, stealing meant depriving someone of a good: if I take your car, you no longer have it. Here, Alibaba (if the accusation is true) took nothing away from Anthropic. Claude still works exactly the same. What would have been "stolen" is a know-how, a way of reasoning, captured by observing responses. How do you protect something that doesn't disappear when copied? Our law, designed for physical objects, has no clear answer yet.
The Alibaba case may be just one episode in the Sino-American rivalry. But the question it raises will occupy us for years: in the age of software intelligence, what does it mean, exactly, to own an idea?