Anthropic Accuses Alibaba of Using 25,000 Fake Accounts to Extract Claude Model Capabilities

Anthropic Accuses Alibaba of Using 25,000 Fake Accounts to Extract Claude Model Capabilities
Anthropic accused Alibaba's Qwen lab of using nearly 25,000 fake accounts to interact with Claude over 28.8 million times, aiming to distill its agent reasoning, software engineering, and long-horizon task capabilities.
Anthropic sent a letter to U.S. senators on June 10, 2026, accusing the Qwen lab affiliated with Alibaba of using nearly 25,000 fake accounts to complete over 28.8 million interactions with the Claude model between April 22 and June 5, a scale nearly double the combined 16 million interactions previously reported from three Chinese labs—DeepSeek, Moonshot, and MiniMax—and specifically targeting core capabilities such as agent reasoning, software engineering, and long-horizon tasks. This article reconstructs the core facts, deconstructs the business logic and technical path of the distillation attack, analyzes its impact on the China-U.S. AI competition landscape, developer ecosystem, and safety alignment, and assesses future policy coordination and signal observation points against the backdrop of music copyright lawsuits and semiconductor export controls.

On June 10, 2026, Anthropic sent a letter to U.S. senators, disclosing that the Qwen lab affiliated with Alibaba used nearly 25,000 fake accounts to complete over 28.8 million interactions with the Claude model between April 22 and June 5. The scale is nearly double the combined 16 million interactions previously reported from three labs—DeepSeek, Moonshot, and MiniMax—and specifically targeted core capabilities such as agent reasoning, software engineering, and long-horizon tasks.

This figure directly points to the real-world path of industrial-scale distillation attacks. Distillation technology itself allows weaker models to rapidly replicate behavior by learning from stronger model outputs, thereby significantly reducing self-training costs. However, when the attacker uses batch fake accounts to achieve high-frequency, systematic API calls, the cost shift moves from internal lab efforts to persistent consumption of frontier model APIs. Anthropic clearly stated in the letter that such behavior not only violates the terms of service but also converts hundreds of billions of dollars in U.S. R&D investment into a hidden subsidy for competitors.

How the Attack Escalated from Occasional Violations to Industrial Scale

From a technical execution perspective, the creation and maintenance of 25,000 accounts require stable API access channels and automated management capabilities. Previous cases disclosed by Anthropic involving three labs showed that 24,000 accounts generated 16 million interactions, while this Alibaba-affiliated operation achieved nearly double that scale in a shorter time, indicating that the attacker has established a repeatable account rotation and traffic scheduling mechanism. The Qwen model itself has music analysis capabilities, which parallels the concurrent copyright lawsuit filed by the music industry against Anthropic. However, distillation itself does not rely on lyric data but directly replicates reasoning trajectories.

In terms of business logic, the appeal of distillation lies in avoiding the massive investment of training from scratch. Anthropic emphasizes that the resulting models often have flaws in safety alignment. If deployed directly, they could amplify the protective vulnerabilities from the training phase into the production environment.

Impact on the Landscape of Various Stakeholders

For Chinese labs, such attacks can quickly improve model performance in the short term, but face service disruption and reputation risks in the long run. The developer community may face higher compliance barriers due to tightened API access. Enterprise users, when choosing a multi-model strategy, need to additionally evaluate supply chain security. Anthropic itself leverages this to strengthen its agenda dominance in congressional hearings, with the Senate Banking Committee's hearing the next day serving as a direct background.

At the same time, U.S. officials' questioning of whether restricted semiconductor equipment is flowing into China further places the technology transfer issue at the policy center. The combination of distillation attacks and hardware controls within the same time window makes it insufficient to rely solely on blocking through terms of service.

Differences Between Comparable Precedents and the Current Case

Anthropic had previously named three labs in a February blog post with a combined 16 million interactions. This Alibaba operation nearly doubles the interaction volume and covers a shorter time span, demonstrating increased attack efficiency. In the music copyright lawsuit, plaintiffs including Universal Music Publishing Group accused Anthropic of copying over 20,000 song lyrics without permission, seeking damages exceeding $3 billion, while Anthropic claims fair use. Although the two incidents are in different domains, both point to cross-border flow disputes over training data and model capabilities.

Strategic Judgment and Verifiable Signals

Analysis and judgment: In the short term, the most likely development is discussions on government-industry coordination frameworks, such as joint account risk control standards or cross-border API audit mechanisms. Observation signals include whether Anthropic subsequently releases more lab data, the results of further U.S. Department of Commerce reviews on semiconductor exports, and whether the Qwen series models adjust public benchmarks to avoid distillation accusations. Mere post-hoc disclosure is no longer sufficient to act as a deterrent; policy-level early technical and commercial intervention is needed.