SKIP TO CONTENT
All news
INDUSTRY NEWS·June 30, 2026·3 MIN READ

Anthropic says Alibaba's Qwen lab ran 25,000 fake accounts to steal Claude's capabilities

By VCA Newsroom

Anthropic has accused Alibaba's Qwen AI lab of orchestrating what it calls the largest known distillation attack against its Claude models, using nearly 25,000 fraudulent accounts to harvest 28.8 million conversations over a 45-day window stretching from April 22 to June 5, 2026.

The company disclosed the alleged operation in a letter to US Senate Banking Committee members, framing it as an attempt "to turn hundreds of billions of dollars of American AI investment into a subsidy for a geopolitical competitor." Alibaba has not publicly addressed the specific allegations.

What is distillation, and why does it matter?

Distillation is a legitimate training technique: you run a larger, more capable model on thousands of problems, then train a smaller model on those responses. The result is a compact model that punches above its weight because it learned from a smarter teacher.

When applied without permission to a competitor's production model, however, it becomes something closer to industrial espionage. A lab that successfully distills a frontier model sidesteps years of research and billions of dollars in compute — and, critically, the painstaking safety work that accompanied that development. As Anthropic put it in its February disclosure of earlier attacks, "the dangerous capabilities transfer through the outputs. The months spent making the model refuse harmful requests do not."

A pattern, not a one-off

The Alibaba allegation is the most prominent in an escalating series. In February 2026, Anthropic revealed that three Chinese AI startups — DeepSeek, Moonshot AI, and MiniMax — had collectively run roughly 24,000 fraudulent accounts responsible for more than 16 million exchanges with Claude, targeting the model's coding, reasoning, and agentic capabilities.

The Qwen operation dwarfs those earlier incidents in scale: 28.8 million conversations in under seven weeks, with the accounts specifically targeting Claude's advanced software engineering and multi-step agentic reasoning — precisely the capabilities most valuable in the current wave of AI-powered development tools.

What Anthropic is asking for

Beyond disclosing the incident, Anthropic is calling on US policymakers to treat large-scale distillation attacks as a national-security issue. The company argues that no individual lab can reliably detect and block these campaigns on its own, and that "rapid, coordinated action among industry players, policymakers, and the global AI community" is needed.

On the technical side, Anthropic says it has deployed improved detection systems capable of identifying the behavioral patterns that distinguish distillation-harvesting accounts from legitimate users — bulk, systematic, repetitive querying across diverse capability domains rather than the organic variety of real developer sessions.

What it means for developers

For the practical majority of developers building with Claude Code or the Anthropic API, nothing changes day-to-day. Anthropic has said legitimate use is unaffected, and terms-of-service enforcement targets the fake accounts rather than normal API customers.

But the episode is a useful reminder of the economics at stake. The capabilities that make Claude valuable for agentic coding tasks — deep reasoning, multi-step tool use, robust refusals — represent an enormous cumulative investment. When those capabilities get extracted and replicated without safety constraints, the downstream models that emerge are both cheaper and potentially less safe, reshaping the market in ways that affect every developer choosing a stack.

It also signals that model selection in 2026 is no longer purely a question of benchmark scores and price. Provenance — who built it, how, and under what safety regime — is becoming a factor worth understanding as well.

Auto-generated by Vibe Coding Academy on June 30, 2026, grounded in the real sources linked above. We review for accuracy, but please verify time-sensitive details against the primary sources.

Build Blueprint · Creator

Have an idea? Get the spec your AI agent can build from.

Describe any product and get a complete build blueprint — stack, data model, screens, APIs, and a ready-to-paste prompt for Claude Code or Cursor. Export to PDF.

Open the Blueprint