{"slug": "anthropic-says-alibaba-linked-operators-used-25000-accounts-to-mine-claude-for", "title": "Anthropic Says Alibaba-Linked Operators Used 25,000 Accounts to Mine Claude for Qwen", "summary": "Anthropic accused operators linked to Alibaba's Qwen AI lab of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI model, generating over 28.8 million exchanges between April and June 2026. The company described the operation as the largest known distillation attack, targeting software engineering and agentic reasoning, and argued that such actions represent an export-control problem in the frontier AI race.", "body_md": "[Dario Amodei](https://www.amodei.co/)'s [Anthropic](https://www.anthropic.com/) accused operators linked to Alibaba's Qwen AI lab of using nearly 25,000 fraudulent accounts to extract Claude capabilities between April 22 and June 5, 2026, according to a June 10 letter described by [Bloomberg](https://www.bloomberg.com/news/articles/2026-06-24/anthropic-accuses-alibaba-of-illicitly-accessing-its-ai-models) and separately seen by [Reuters](https://es.marketscreener.com/noticias/anthropic-dice-que-alibaba-extrajo-de-forma-il-cita-capacidades-del-modelo-de-ia-claude-ce7f5fd8d981f227).\n\nThe claim, amplified Wednesday in [a thread on X](https://x.com/kimmonismus/status/2069879640835961277), puts Alibaba inside the argument Anthropic has been building for months: that the frontier AI race is no longer just about who can buy chips or hire researchers, but who can prevent rivals from using high-end model outputs as training data. Anthropic says the Alibaba-linked campaign generated more than 28.8 million exchanges with Claude and focused on software engineering and agentic reasoning, two of the capabilities that make Claude commercially useful for developers and enterprise workflows.\n\nAmodei and his sister, [Daniela Amodei](https://www.amodei.co/), co-founded Anthropic in 2021 after leaving OpenAI, and the company has consistently tried to frame its commercial model business as a national-security project as much as a software business. That framing matters here. Anthropic is not merely saying an account farm violated its terms. It is arguing that a major Chinese technology company used Claude outputs to accelerate the development of Qwen, Alibaba's foundation-model family, while bypassing Anthropic's decision not to offer commercial Claude access in China.\n\nReuters reported that Anthropic described the operation as the largest known distillation attack against the company to date. The letter was sent to Senate Banking Committee Chair Tim Scott and ranking member Elizabeth Warren, according to Reuters, before a scheduled hearing on AI. That audience was not incidental. Anthropic has been pressing the case that model distillation is an export-control problem: if a restricted entity can reach a frontier model through proxy accounts, the practical effect can resemble gaining indirect access to the underlying capability.\n\n### What Anthropic says happened\n\nDistillation is a common technique inside AI labs: a smaller or cheaper model is trained on the outputs of a stronger model. Used within one company, it can make models faster, cheaper, or easier to deploy. Anthropic's allegation is narrower and more pointed. It says outside operators used fraudulent accounts and proxy-like access patterns to generate high volumes of Claude responses that could be used to train or improve another model.\n\nAnthropic laid out the same playbook in a [February post on detecting and preventing distillation attacks](https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks). In that earlier disclosure, Anthropic accused DeepSeek, Moonshot AI, and MiniMax of running industrial-scale campaigns that produced more than 16 million Claude exchanges through more than 24,000 fraudulent accounts. The company said those campaigns targeted agentic reasoning, tool use, coding, computer vision, and chain-of-thought-like reasoning traces.\n\nThe Alibaba allegation is larger by volume than the February cases Anthropic disclosed. Reuters' account of the June 10 letter says the campaign ran for roughly six weeks and generated 28.8 million Claude exchanges through almost 25,000 accounts. Bloomberg Law reported that Anthropic said the Alibaba-linked activity targeted Claude's prized capabilities, including software engineering and agentic reasoning.\n\nThose are not abstract benchmark categories. Coding and agentic reasoning are where model vendors are trying to turn general chatbots into systems that can write software, call tools, execute multi-step tasks, and hold a workflow together across many actions. If a rival can cheaply harvest examples in those categories, it can reduce the amount of original training and reinforcement-learning work needed to ship a competitive model.\n\n### Why Qwen is the obvious flashpoint\n\nAlibaba has made Qwen central to its AI push. [Alibaba Cloud Model Studio](https://modelstudio.alibabacloud.com/) markets access to Qwen, Wan, and other models for developers and enterprises, and Alibaba's commercial AI strategy depends on getting Qwen into the workflows that OpenAI, Anthropic, Google, DeepSeek, MiniMax, and Moonshot are also chasing. That makes Qwen both a product line and a distribution wedge for Alibaba Cloud.\n\nAnthropic's accusation does not prove that Qwen's published capabilities came from Claude. It says operators affiliated with Alibaba and Alibaba Qwen ran the extraction campaign. That distinction matters: the public record described by Bloomberg and Reuters is Anthropic's allegation, not an adjudicated finding, and the letter itself is not a technical report with reproducible evidence.\n\nStill, the timing is useful. The alleged campaign ran from April 22 to June 5, 2026, after Anthropic had already publicly warned that Chinese AI labs were using account networks to mine Claude. If Anthropic's account is accurate, the prior disclosure did not deter the behavior. It may have simply moved the fight from named specialist labs to a larger platform company with a cloud business, a model family, and a direct incentive to lower the cost of competing with US frontier labs.\n\n### The policy play is as important as the technical claim\n\nAnthropic's February post argued that distillation attacks reinforce the case for export controls because extraction at large scale still requires compute, orchestration, and infrastructure. The June 10 letter extends that argument into Congress with a more politically legible target: Alibaba, a Chinese technology giant rather than a smaller AI lab.\n\nThat is the strategic layer under the accusation. Anthropic benefits if policymakers treat model access, cloud-account verification, and frontier-model outputs as part of the same control surface as chips. Alibaba benefits if Qwen can close performance gaps quickly and cheaply while remaining broadly available through Alibaba's own cloud channels. Developers benefit from cheaper, capable models, but the economics that make those models cheap are exactly what frontier labs are now asking regulators to scrutinize.\n\nThe unanswered question is attribution. Anthropic says it can identify distillation campaigns through IP correlation, request metadata, infrastructure indicators, account behavior, and corroboration from partners. Those methods may be strong enough for account bans and government briefings. They are not the same as a public forensic record tying a model's weights or benchmark gains to Claude-derived data.\n\nThat gap does not make the claim irrelevant. It defines the next phase of the AI platform fight. Frontier labs are selling access to models that are themselves training-data generators. Every API call can be a customer interaction, an enterprise workflow, or an attempt to turn one company's expensive capability into another company's cheaper model. Anthropic's Alibaba accusation is the clearest sign yet that model vendors now see access control as product strategy, policy strategy, and IP defense at the same time.", "url": "https://wpnews.pro/news/anthropic-says-alibaba-linked-operators-used-25000-accounts-to-mine-claude-for", "canonical_source": "https://runtimewire.com/article/anthropic-alibaba-qwen-claude-distillation-claims", "published_at": "2026-06-24 23:22:33+00:00", "updated_at": "2026-06-24 23:47:27.673597+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "large-language-models", "ai-ethics", "ai-research"], "entities": ["Anthropic", "Alibaba", "Qwen", "Claude", "Dario Amodei", "Daniela Amodei", "Tim Scott", "Elizabeth Warren"], "alternates": {"html": "https://wpnews.pro/news/anthropic-says-alibaba-linked-operators-used-25000-accounts-to-mine-claude-for", "markdown": "https://wpnews.pro/news/anthropic-says-alibaba-linked-operators-used-25000-accounts-to-mine-claude-for.md", "text": "https://wpnews.pro/news/anthropic-says-alibaba-linked-operators-used-25000-accounts-to-mine-claude-for.txt", "jsonld": "https://wpnews.pro/news/anthropic-says-alibaba-linked-operators-used-25000-accounts-to-mine-claude-for.jsonld"}}