American company Anthropic sent a letter to U.S. senators accusing Chinese technology and commerce company Alibaba of having “shamelessly” and “illegally” attempted to extract capabilities from its Claude model. It was allegedly the largest attack of its kind the company had ever recorded. Between April 22 and June 5 of this year, people linked to Alibaba reportedly submitted more than 28.8 million queries to Claude through nearly 25,000 fraudulent accounts. What exactly is Anthropic claiming, and why could the matter end up before the U.S. Congress?
The letter is addressed to two members of the U.S. Senate, Tim Scott and Elizabeth Warren. In it, Anthropic describes what it calls “the largest campaign aimed at illegally obtaining Claude’s capabilities that we have ever measured.” People connected to Alibaba and its Alibaba Qwen laboratory are alleged to be behind the attack.
How was it allegedly carried out? Over six weeks, the operators generated more than 28.8 million exchanges with Claude, using almost 25,000 fake accounts. In doing so, they violated the terms of use and access restrictions. Moreover, the Chinese actors should not have been able to access Claude directly. Anthropic routinely blocks access by Chinese entities, so according to the company, the attackers used commercial proxy services to circumvent the geographic restrictions.
Use of the distillation method
The term “distillation attack” may not mean anything to you yet. It works by having an attacker send carefully prepared queries to a powerful model, collect its responses, and then use them to train their own weaker and cheaper model so that it approximates the behavior of the original. In short, the student learns from the teacher, but without the teacher’s permission.
And that is precisely what is at issue here. Anthropic claims that Alibaba targeted Claude’s most valuable skills. Specifically, programming, so-called agentic reasoning, and the ability to handle long and complex tasks. In other words, exactly what makes the model commercially attractive. The alleged goal was to catch up with Claude’s advanced capabilities without the Chinese company having to spend billions on its own research and training. “Distillation attacks turn hundreds of billions of dollars in American investment and research into a massive subsidy for our geopolitical rivals,” Anthropic wrote in the letter.
Another similar incident
This is not the first accusation of its kind. Back in February, Anthropic publicly drew attention to three Chinese laboratories that had allegedly exploited Claude in a similar way. They were DeepSeek, Moonshot, and MiniMax. Together, they reportedly generated more than 16 million exchanges through roughly 24,000 fake accounts.
To illustrate how this is escalating: DeepSeek’s operation involved more than 150,000 exchanges, Moonshot exceeded 3.4 million, and MiniMax surpassed 13 million. The campaign attributed to Alibaba alone thus exceeded the combined volume of all three previous campaigns. And for the first time, the company involved is a global corporation of this size, rather than a smaller startup.
In April, the White House accused China of stealing the intellectual property of American laboratories on an industrial scale. At the time, the Office of Science and Technology Policy issued a report promising to help American companies detect attacks and coordinate a joint defense. However, the attack attributed to Alibaba allegedly took place afterward. Anthropic therefore claims that the company “ignored the Trump administration’s warnings” and continued.
Pressure on Alibaba is also mounting from other directions. The Pentagon added it to its list of Chinese military companies, which Anthropic also mentioned in the letter. Alibaba objected to the designation this week and sued the Department of Defense. It called the designation unfounded and claims it has no connection to the military. Other major companies were added to the list alongside it, including automaker BYD and technology conglomerate Baidu, both of which deny any ties to the Chinese military.
What Anthropic is demanding
Anthropic is not asking for money in the letter. Its appeal is directed at lawmakers. It wants Congress to make it easier for American laboratories to share information about threats, close loopholes that allow Chinese companies to gain access to advanced American chips, and punish those responsible for distillation attacks.
The company also emphasized that it supports the U.S. government’s efforts to combat these attacks, including cooperation with the private sector in sharing intelligence. Rival companies OpenAI and Google have also published similar findings about attackers targeting their own models. Alibaba has not yet publicly commented on the accusation. It did not respond to journalists’ requests for comment.
Sources: bbc.com and cnbc.com



