Anthropic has accused Alibaba of conducting the largest illicit AI distillation campaign ever recorded, alleging the company used fraudulent accounts to extract reasoning data from its Claude models. According to an Anthropic threat report, Alibaba allegedly processed over 151 million exchanges between May and July 2026 to train its own Qwen models. The operation reportedly peaked at nearly 3 million daily requests, targeting complex tasks such as software engineering and kernel development.
The report claims Alibaba utilized two pools of thousands of fraudulent accounts, employing residential proxies and disposable credentials to bypass security measures. Anthropic noted that some of these proxy networks were also linked to other Chinese firms, including DeepSeek and Xiaomi. While Anthropic identified seven China-based labs engaged in similar activities, it stated that its advanced Mythos-class models remained secure from these extraction attempts.
In response to the campaign, Anthropic has implemented stricter identity verification and new classifiers to detect adversarial data extraction. The company also introduced technical safeguards to prevent new accounts from manipulating conversation contexts. Alibaba had not publicly responded to these allegations, which have not been independently verified, at the time of the report's release.



