{"slug": "anthropic-says-alibaba-ran-a-44-day-operation-to-steal-claudes-brain", "title": "Anthropic Says Alibaba Ran a 44-Day Operation to Steal Claude’s Brain", "summary": "Anthropic accused Alibaba's Qwen AI team of orchestrating a 44-day distillation attack using 25,000 fake accounts and 28.8 million interactions to steal capabilities from its Claude model, marking the largest known such operation. The U.S. Commerce Department moved to impose export-control-style restrictions on Anthropic's Mythos and Fable models, and Anthropic urged lawmakers to criminalize unauthorized distillation.", "body_md": "Consider a botnet attack — except the target isn’t a bank vault. It’s the reasoning capability of a frontier AI model. [Anthropic has accused](https://www.techspot.com/news/112897-anthropic-accuses-china-alibaba-stealing-claude-ai-capabilities.html) Alibaba’s Qwen AI team of orchestrating what the company calls the largest known distillation attack it has ever detected. The numbers, according to a confidential letter Anthropic sent to U.S. lawmakers and later [reported by Reuters](https://www.reuters.com/video/watch/idRW227325062026RP1/): roughly **25,000 fake accounts**, **28.8 million interactions**, crammed into a **44-day window** between April 22 and June 5, 2026. Years of R&D, allegedly copied in six weeks.\n\n## What “Distillation” Actually Means (And Why It’s Not Just API Scraping)\n\n*Think of it as filming every move in a competitor’s kitchen, then opening a restaurant next door.*\n\n[Knowledge distillation](https://www.skyengine.ai/blog/what-is-knowledge-distillation) is a standard machine learning technique — labs compress their own large models into smaller, cheaper ones routinely. The allegation here is something different: running that same technique against a competitor’s API at industrial scale. Anthropic’s technical disclosures describe the result as copying “reasoning patterns, safety behaviors, and specialized capabilities” at a fraction of the original cost.\n\nHere’s what Anthropic says happened, based on its letter and technical disclosures:\n\n- Approximately 25,000 fraudulent accounts distributed API requests across proxy networks Anthropic calls\n**“hydra clusters”** - 28.8 million interactions generated over those 44 days\n- Targeted capabilities included software engineering, agentic reasoning, complex planning, and tool use\n- Requests were structured to mimic normal user traffic while quietly harvesting outputs\n- Anthropic attributed the campaign using IP correlation, request metadata, and infrastructure fingerprints\n\nThis wasn’t the first such campaign. In **February 2026**, [Anthropic](https://www.gadgetreview.com/anthropics-mythos-ai-cracked-nearly-all-classified-u-s-systems-in-hours) disclosed similar operations by DeepSeek, Moonshot AI, and MiniMax — collectively around 24,000 fraudulent accounts and 16 million exchanges. The Alibaba operation allegedly dwarfs all of them combined. That escalation pushed Anthropic to write directly to Senators Tim Scott and Elizabeth Warren on June 10, 2026. These episodes rank among the most brazen [tech scandals](https://www.gadgetreview.com/evil-tech-scandals-failures-that-took-advantage-millions-people) in recent memory.\n\n## Washington Is Paying Attention – And Closing the Door\n\n*For developers who built workflows on Anthropic’s Mythos or Fable models, access just got complicated.*\n\nThe U.S. Commerce Department moved to impose export-control-style restrictions on both models shortly after the letter landed. Anthropic hasstress-test suspended global public access to Mythos and Fable pending federal clarification, and is urging lawmakers to:\n\n- Criminalize unauthorized distillation\n- Enable inter-lab attack data sharing\n- Tighten AI export controls broadly\n\nOne critical caveat: Alibaba has not publicly responded to these allegations. Everything here flows from Anthropic’s letter and Western reporting. Some developer-forum voices argue that querying public APIs is inherently competitive territory, and the line between benchmarking and extraction is genuinely contested. That debate has real weight — but 28.8 million interactions across 25,000 fake accounts stress-tests that argument like a Category 5 hurricane hitting a garden fence.\n\nFrontier [AI models](https://www.gadgetreview.com/ai-models-ran-a-simulated-society-grok-went-extinct-in-4-days-after-committing-over-180-crimes) may soon be treated like advanced semiconductors — geo-fenced, licensed, and restricted. For developers, the open-API era for the most powerful models could be closing. Whether Washington can build enforceable rules fast enough to matter is the question that actually keeps AI labs up at night.", "url": "https://wpnews.pro/news/anthropic-says-alibaba-ran-a-44-day-operation-to-steal-claudes-brain", "canonical_source": "https://www.gadgetreview.com/anthropic-says-alibaba-ran-a-44-day-operation-to-steal-claudes-brain", "published_at": "2026-06-25 19:04:46+00:00", "updated_at": "2026-06-25 19:20:54.418225+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "large-language-models", "ai-ethics", "ai-research"], "entities": ["Anthropic", "Alibaba", "Qwen", "Claude", "Mythos", "Fable", "DeepSeek", "Moonshot AI"], "alternates": {"html": "https://wpnews.pro/news/anthropic-says-alibaba-ran-a-44-day-operation-to-steal-claudes-brain", "markdown": "https://wpnews.pro/news/anthropic-says-alibaba-ran-a-44-day-operation-to-steal-claudes-brain.md", "text": "https://wpnews.pro/news/anthropic-says-alibaba-ran-a-44-day-operation-to-steal-claudes-brain.txt", "jsonld": "https://wpnews.pro/news/anthropic-says-alibaba-ran-a-44-day-operation-to-steal-claudes-brain.jsonld"}}