Anthropic accused Alibaba and its Qwen research division of illicitly accessing its Claude models in what it called the largest known AI distillation attack against the company. In a letter to the U.S. Senate Banking Committee, Anthropic said operators used nearly 25,000 fraudulent accounts to generate more than 28.8 million Claude exchanges between April 22 and June 5, targeting high-value capabilities from the Mythos Preview model, including software engineering and agentic reasoning. The company said the activity was designed to replicate frontier-model performance without incurring the full cost of training a competing system.
Anthropic warned that adversarial distillation can transfer advanced capabilities while omitting the original model’s safety guardrails, raising both security and national security concerns beyond intellectual property theft. The company linked the alleged operation to a broader pattern involving other Chinese AI labs, including DeepSeek, Moonshot AI, and MiniMax, and called for antitrust-safe threat intelligence sharing, continued AI chip export controls, and penalties for firms found to have improperly used U.S. model outputs. The disclosure has also spurred proposed U.S. legislative action, including potential sanctions or blacklisting of Chinese companies accused of training rival systems on unauthorized American AI outputs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
TechCrunch reported that Alibaba classified Anthropic's Claude Code as high-risk software and told employees it would ban use of the tool, directing them instead to Alibaba's own Qoder product. The report said the ban would take effect on July 10, 2026.
Following Anthropic's disclosure, Senators Bill Hagerty and Andy Kim were reported to be preparing an amendment that would blacklist or sanction Chinese firms found improperly using U.S. AI model outputs to train competing systems.
Anthropic cited a separate February 2026 case involving DeepSeek and two other Chinese AI laboratories as part of what it described as a broader pattern of unauthorized exploitation of its AI models.
Two days after Anthropic sent its June 10, 2026 warning letter to Congress, the U.S. government imposed restrictions on the export and deployment of Anthropic's Mythos and Fable models. The reference says the move led to the models' global disablement over concerns they could be accessed by Chinese military intelligence services.
On June 10, 2026, Anthropic sent a letter to Senate Banking Committee leaders Tim Scott and Elizabeth Warren accusing Alibaba and Alibaba Qwen of illicitly accessing Claude in what it called the largest known distillation attack against the company.
Anthropic said the campaign ran through June 5, 2026, using nearly 25,000 fraudulent accounts to generate more than 28.8 million Claude exchanges. The activity allegedly targeted software engineering and agentic reasoning capabilities tied to Claude Mythos Preview.
Anthropic said operators affiliated with Alibaba and its Qwen division began a large-scale distillation campaign against Claude on April 22, 2026. The company alleged the operation used fraudulent accounts to extract high-value capabilities from its models.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
techcrunch.com
Open sourcedatainnovation.org
Open sourcearstechnica.com
Open sourcezdnet.fr
Open sourcebankinfosecurity.com
Open sourceinfoworld.com
Open sourcelawfaremedia.org
Open sourceassets.bwbx.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.