24 Jul 2026
Signal Headquarters
Vol. I
No. 144
Signal
· · 3 min read

Anthropic's allegation against Alibaba is the largest AI distillation attack ever claimed

Anthropic told U.S. senators that Alibaba-affiliated operators ran nearly 29 million exchanges through Claude using a network of fraudulent accounts. If the numbers hold up, this is not a routine terms-of-service dispute. It is an industrial-scale capability extraction operation.

Anthropic has taken a significant allegation directly to Capitol Hill. In a June 10, 2026 letter to U.S. senators, the company accused Alibaba-affiliated operators of running approximately 28.8 to 29 million exchanges with Claude through a network of roughly 25,000 fraudulent accounts. Anthropic characterizes the operation as the largest distillation attack ever detected against its systems. Nathaniel Whittemore put the charge plainly: “Anthropic says that Alibaba accessed their models almost 29 million times through a network of 25,000 fraudulent accounts.”

The reporting is not thin. CNBC, Ars Technica, The Next Web, and Bloomberg-sourced outlets have all confirmed the core details of the letter, including the account count and the exchange volume. That breadth of corroboration means the allegation is now a matter of public record, not a leaked grievance circulating without verification.

The mechanics of a distillation attack matter here. The goal is not to breach a system in the conventional sense. It is to query a model at sufficient volume and variety that the outputs can be used to train a competing model, effectively transferring capability without transferring compute costs or research investment. At 29 million exchanges routed through 25,000 accounts built specifically to evade detection, the scale Anthropic describes would place this operation in a different category from opportunistic scraping. It describes a sustained, structured extraction campaign.

Anthropic says that Alibaba accessed their models almost 29 million times through a network of 25,000 fraudulent accounts. Nathaniel Whittemore

Anthropic’s decision to frame this in a letter to senators rather than in a civil complaint is a deliberate choice. It routes the allegation through a political and regulatory channel rather than a judicial one, at least for now. That framing invites lawmakers to treat the incident as a national-security or trade concern, not merely a contractual dispute between two private companies. Ars Technica noted the additional dimension that Anthropic’s letter invokes: the suggestion that Alibaba defied U.S. policy constraints in pursuing the operation, adding a geopolitical charge to what is already a commercially explosive accusation.

What makes the allegation non-obvious is that distillation attacks of this alleged size require organizational coordination. Twenty-five thousand fraudulent accounts do not appear spontaneously. They require infrastructure, account provisioning at scale, and a strategy for distributing queries in ways that avoid triggering automated detection. If Anthropic’s characterization is accurate, someone built and operated a system designed specifically to look like ordinary consumer traffic while systematically draining Claude’s outputs for training data.

The regulatory stakes are real regardless of how a court or a committee ultimately rules on the underlying facts. The allegation, now confirmed as public by multiple independent outlets, gives lawmakers a concrete and numerically specific case to cite when debating controls on AI model access, export restrictions, and the treatment of foundation model outputs as protectable intellectual property. Each of those policy debates has been running on theoretical framings; this provides a fact pattern to argue around.

Whether Alibaba disputes the characterization, and on what grounds, will shape how far this goes. But the initial public record is now set: Anthropic filed the allegation formally, the numbers are specific, and the reporting has held up across multiple outlets. The next move belongs to the companies, the senators, and ultimately the regulators or courts asked to determine what, exactly, 29 million model exchanges through fraudulent accounts constitutes under U.S. law.

The Editor, for the readers of Signal Headquarters

From the Archive