Anthropic says Alibaba-linked accounts hit Claude 151 million times
Anthropic says the three-month operation used fraudulent accounts to collect Claude's reasoning traces and improve Qwen.
Verified 7:12 AM PDT · 3 original sources
Anthropic published a 154-page threat report on September 10. It covers misuse the company says it disrupted between December 2025 and August 2026. Anthropic says seven China-based AI labs tried to extract and copy Claude's capabilities. It linked the largest operation to Alibaba's Qwen and Tongyi teams.
Anthropic says the operation produced more than 151 million exchanges from May through July. Traffic peaked near three million exchanges a day. It came through more than 3,500 accounts that Anthropic described as fraudulent. The company says operators collected Claude's reasoning traces and used them to improve Qwen models.
The report links more than 23 million exchanges to Moonshot and 12.1 million to DeepSeek. It also links 3.4 million to Zhipu and more than 400,000 to Xiaomi. Reuters reports that Anthropic accused Moonshot and DeepSeek of routing some live customer conversations through Claude without telling users. Alibaba had not responded when Reuters published its report.
This is a company claim based on Anthropic's own service logs and attributions. The report provides campaign identifiers, dates and counts, but no outside auditor has verified the complete evidence. Distillation is also a standard method used throughout the AI industry. The disputed conduct is the alleged use of fraudulent accounts and covert customer routing, not the technique by itself. Anthropic says the cases in its report were notable rather than typical.
Chip controls limit who can train the largest models, but distillation offers another route. A lab can query a finished model, collect its answers and train a smaller model to copy selected capabilities. The smaller model still needs data, engineering and computing power, but it does not need access to the larger model's weights.
At the scale Anthropic reports, access to a model becomes part of the supply chain. Account checks, reseller controls and traffic analysis can matter as much as a hardware export license. Private model companies must then investigate foreign labs and decide which uses cross the line.
The named companies should publish technical responses that address the account counts, traffic patterns and routing claims. Independent researchers need enough logs to test Anthropic's attribution. A denial without supporting data will not settle a claim based on private service records.
Governments will have to decide whether export-control rules should cover model outputs. The details matter. A broad rule could block ordinary research or interoperability. A narrow rule could miss proxy networks and resellers. Watch for rules aimed at account fraud, covert routing and industrial-scale extraction rather than distillation itself.
Audit the story
Original sources
Company claims remain company claims. Follow the reporting and judge the evidence directly.
Continue the edition