Anthropic has accused operators affiliated with Alibaba's Qwen AI lab of running its largest known data-siphoning campaign, telling U.S. lawmakers that roughly 25,000 fraudulent accounts were used to generate 28.8 million interactions with Claude over a six-week stretch this spring in an alleged bid to copy the chatbot's most commercially prized skills.

In a letter dated June 10 and addressed to Senators Tim Scott and Elizabeth Warren of the Senate Banking Committee, along with White House officials, Anthropic described the operation as "the largest known distillation attack on Anthropic to date" and accused the Chinese tech giant of "brazenly" and "illicitly" attempting to extract its artificial-intelligence capabilities. The activity ran from April 22 to June 5, 2026, according to the company, and the volume exceeds the combined total of three earlier Chinese-lab campaigns Anthropic disclosed in February, which it linked to DeepSeek, Moonshot and MiniMax.

Anthropic says the fake accounts were not random probing but a coordinated effort targeting Claude's strengths in software engineering and agentic reasoning, the multi-step, autonomous problem-solving that frontier labs consider among the most valuable frontiers in AI. The campaign, Anthropic alleges, was designed to help Alibaba's Qwen models approach the capabilities of its own frontier Mythos Preview system, which specializes in advanced coding, complex reasoning and cybersecurity tasks. Alibaba had not publicly responded to the allegations as of the letter's disclosure on June 24, and the claims remain unproven assertions in a letter, not findings of any court or regulator.

What 'distillation' means and why it matters

Model distillation is a legitimate and widespread training technique: a smaller "student" model learns to mimic a larger "teacher" model by ingesting the teacher's outputs, capturing much of its performance at a fraction of the cost. The technique becomes contentious when the outputs are harvested in violation of a provider's terms of service. The attacker does not need to steal source code or model weights; enough high-quality answers can teach a rival system to imitate the original. Because only a finished model is ever made public, not its training data, proving distillation is notoriously hard, a difficulty that surfaced when OpenAI leveled similar accusations against DeepSeek. That evidentiary gap is precisely why Anthropic appears to be routing its complaint through Washington rather than the courts: the alleged use of 25,000 disguised accounts to evade detection is the kind of "Sybil" behavior easier to frame as a national-security and fraud problem than as a contract dispute.

The US-China AI rivalry, and an awkward irony

The accusation lands in the middle of an escalating technology cold war. American lawmakers have grown increasingly anxious that Chinese labs are closing the gap with U.S. frontier systems by free-riding on capabilities developed at great expense in California, and a Chinese model matching Mythos-class performance is exactly the outcome the export-control regime is meant to prevent. By framing the episode as theft of strategically sensitive coding and cyber capabilities, Anthropic positions itself squarely as a guardian of American AI leadership.

The timing, however, cuts in two directions. Just two days after the letter's date, on June 12, the Commerce Department's Bureau of Industry and Security ordered Anthropic to suspend access to its Fable 5 and Mythos 5 models for any foreign national, at home or abroad, over fears the models' cyber capabilities could reach militaries in China or Russia. Unable to reliably screen users by nationality, Anthropic disabled both models worldwide. The company has pushed back hard, arguing the government acted on a narrow, single-instance jailbreak. "We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people," Anthropic wrote, noting the same exploit could likely elicit comparable behavior from rival models such as OpenAI's GPT-5.5, which face no equivalent restrictions.

The result is a striking posture: Anthropic is simultaneously asking Washington to shield it from Chinese extraction while protesting Washington's own limits on its products. Both stances flow from the same logic, that frontier AI is now a national-security asset, but they leave the company arguing for government intervention and against it in the same news cycle.

What to watch

The immediate question is whether Alibaba responds, and whether it disputes the technical attribution linking the 25,000 accounts to its Qwen lab. Anthropic has not publicly detailed precisely what enforcement it wants, but routing the complaint to the Senate Banking Committee and the White House points toward sanctions, tighter account-verification mandates or formal scrutiny of Chinese labs rather than litigation. Watch, too, for whether other frontier labs corroborate similar campaigns against their own systems, which would strengthen the case that industrial-scale distillation has become a systematic strategy rather than isolated incidents. And the unresolved Mythos and Fable standoff will test how far Anthropic can have it both ways, casting itself as a national-security ally while contesting the very controls that argument invites.

"We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people."
- Anthropic, Statement on US export restrictions
25,000
Fraudulent accounts allegedly used
28.8M
Claude interactions generated
Apr 22 - Jun 5
Window of the alleged 2026 campaign
3
Prior Chinese-lab campaigns Anthropic disclosed