Anthropic Accuses Alibaba of Record 28.8 Million-Query Distillation Attack on Claude in Letter to U.S. Senate
In a letter dated June 10, 2026, and first reported publicly by CNBC on June 24, Anthropic accused operators affiliated with Alibaba and its Qwen AI lab of conducting what it called "the largest known distillation attack on Anthropic to date." The letter, addressed to Senate Banking Committee Chair Tim Scott and Ranking Member Elizabeth Warren, alleged that Alibaba-linked entities used approximately 25,000 fraudulent accounts to generate more than 28.8 million exchanges with Anthropic's Claude models over a 44-day window running from April 22 to June 5, 2026. According to reporting by Digital Applied and Let's Data Science, the campaign specifically targeted Claude's software engineering capabilities, agentic reasoning, and long-horizon task completion — the capabilities that most sharply distinguish frontier models from earlier generations of AI.
The technique at the centre of the accusation is model distillation, a process in which a smaller, less capable model is trained on the outputs of a more powerful one, allowing it to approximate the stronger model's capabilities without independently developing them or incurring the associated research and development costs. As Anthropic wrote in its letter, accessed by Bloomberg, such attacks are carried out "illicitly, systematically, and at an industrial scale to harvest US AI capabilities across frontier labs and repackage them as their own." The company had previously, in February 2026, disclosed three separate distillation campaigns attributed to DeepSeek, Moonshot, and MiniMax, which together involved approximately 16 million exchanges. The Alibaba campaign, at 28.8 million exchanges, nearly doubles that combined figure, according to reporting by Let's Data Science.
Alibaba has not issued a detailed public rebuttal. According to Sesame Disk, Alibaba's American depositary receipts fell to a 16-month low following the news becoming public, while Chinese experts cited by the Global Times dismissed the claims as rooted in what they called "tech hegemony anxiety." The accusations arrived at a particularly fraught moment for Alibaba: the Pentagon added the company to its Section 1260H list of Chinese military companies on June 8, and Alibaba filed a federal lawsuit in the Northern District of California on June 23 challenging that designation. As Tech Times reported, the distillation letter has already triggered a concrete congressional response, with Senators Bill Hagerty of Tennessee and Andy Kim of New Jersey moving to add a bipartisan amendment to must-pass defence legislation that would authorise the blacklisting or sanctioning of entities found to have conducted adversarial distillation campaigns.
The episode exposes a structural vulnerability that extends beyond Anthropic to every commercial frontier AI provider. As Legal analyst reporting in Let's Data Science noted, a distillation query looks identical to a legitimate query at the API level, meaning that geographic access restrictions — the primary tool used to bar Chinese entities from accessing Claude — are insufficient on their own. Anthropic itself acknowledged the dilemma in its Senate letter, arguing that protecting U.S. AI models from distillation and allowing those models to be deployed commercially are complementary rather than contradictory goals. That argument is complicated by a separate action: the Commerce Department issued an export control directive on June 12, 2026, ordering Anthropic to suspend access to its most advanced models, Claude Fable 5 and Mythos 5, by any foreign national anywhere in the world, according to reporting by Tech Times. The company complied while publicly describing the order as a misunderstanding, and told CNBC that both parties are working to resolve the matter.
The geopolitical and commercial stakes of the distillation debate are only accelerating. Anthropic confidentially filed for an IPO on June 16, 2026, with the New York Times reporting a potential valuation of $1 trillion. Sesame Disk analysis noted that a public accusation of large-scale intellectual property theft serves multiple simultaneous purposes: signalling to prospective investors that the company has the monitoring infrastructure to detect sophisticated attacks, pressuring regulators to act while export control policy is being actively shaped, and framing Chinese competition as a structural threat justifying continued investment in safety infrastructure. Whether or not the Hagerty-Kim defence amendment passes, the Anthropic-Alibaba confrontation has already shifted the terms of the debate: AI model outputs are now being treated as exportable intellectual property, and the question of how to police their extraction is moving from terms-of-service enforcement into the domain of trade and national security law.