This isn’t a product launch — it’s an accusation, and it landed in a letter to US senators and the White House. Anthropic says Alibaba’s Qwen lab spun up nearly 25,000 fake accounts and fired off 28.8 million Claude interactions between April 22 and June 5, 2026, then used the outputs to train Qwen.
What “distillation attack” actually means
Distillation is simple: query a stronger model at industrial scale, harvest its answers, and train your cheaper model to imitate them. You skip the hard part — the original research — and copy the homework. Anthropic says Alibaba zeroed in on Claude’s most valuable outputs: software-engineering and agentic-reasoning traces, exactly the stuff that makes a coding model good.
Why this one is bigger
February’s disclosure named DeepSeek, Moonshot and MiniMax — about 24,000 accounts and 16 million exchanges combined. Alibaba allegedly beat that total in six weeks alone, which is why Anthropic calls it the largest known distillation attack in AI history.
Alibaba hasn’t responded. The bigger story is the arms race it kicks off: frontier labs are now treating identity verification as IP defense, and the US-China model-weight fight just moved from chips to outputs.
You Might Also Like
- Alibaba Qwen 3 5 Just Dropped and it Brought 10 Million Milk Teas With it
- Deepclaude Lets Claude Code run on Deepseek v4 pro 0 87 vs 15 per Million Tokens
- Mistral Cybersecurity Model for European Banks Anthropic Mythos Rival Lands as ecb Sounds the Alarm on Mythos Attacks
- Anthropic Agent sdk Metered Credits Openclaw Reinstated June 15 Splits Your Claude Subscription in two
- Nessie Labs Turns Your Messy ai Chat History Into an Actual Second Brain

Leave a comment