DEV Community

Breach Protocol
Breach Protocol

Posted on • Originally published at groundtruth.day

Anthropic says Alibaba ran the biggest 'copy Claude' campaign yet

Anthropic accused operators tied to Alibaba's Qwen AI lab of running the largest model-distillation campaign it has ever seen, using nearly 25,000 fake accounts to hold close to 29 million conversations with Claude over roughly six weeks this spring. The allegation, delivered in a letter to U.S. senators and White House officials, moves the U.S.-China AI rivalry from chips and export controls into the models themselves — the actual learned behavior that is the product.

Key facts

  • What: Anthropic told U.S. senators that Alibaba's Qwen team quietly milked Claude for its best skills. Alibaba says nothing back, and the whole fight may be as much about price as theft.
  • When: 2026-06-25
  • Primary source: read the source

The technique is called distillation: you ask an AI model thousands of carefully chosen questions, record every answer, and use that pile of question-and-answer pairs to train a cheaper model of your own. The new model never sees the original's inner workings, but it learns to imitate its behavior. According to reporting on the letter, the conversations were not random — they zeroed in on the exact things Claude is best at and makes the most money from: writing software and acting as an autonomous agent that can plan and carry out multi-step tasks.

The economics are lopsided. Training a frontier AI model from scratch costs an enormous amount in computing time, electricity, and the salaries of rare specialists. Distilling one is cheap by comparison. If a rival can spend a tiny fraction of the original budget and walk away with a model that behaves almost as well, the years of expensive work that built the original become easier to leapfrog. Anthropic argues that this lets competitors sell cheaper imitations that undercut its prices, and warns that the copies often arrive without the safety guardrails the original was carefully trained to include.

The timing sharpens everything. The accusation lands while Alibaba was recently added to a U.S. Defense Department list of companies it considers linked to the Chinese military, a designation Alibaba is fighting in court. It also lands while Anthropic is reportedly preparing to go public, which means cheaper foreign clones are not just a strategic worry but a financial risk it has to disclose to investors. Anthropic asked the government to spell out clearer rules so companies can share information about these campaigns without running afoul of antitrust law, to keep tight controls on advanced AI chips, and to penalize firms that copy models this way. Lawmakers are reportedly drafting legislation to blacklist or sanction offenders.

Here is where the picture becomes genuinely contested. Alibaba declined to comment, and its U.S.-listed shares slipped about three percent on the news. Chinese commentators pushed back hard. In one Chinese state-media response, experts framed the accusation as a "kick away the ladder" move — an attempt by a leader to pull up the rope behind it once it has climbed. Their argument has two parts. First, distillation is an ordinary, widely taught technique for making models smaller and cheaper, used all over the field, not some exotic act of sabotage. Second, they point out that Anthropic itself has faced questions about where its own training data came from, so accusations about copying cut in more than one direction.

A third reading refuses to take either side's word for it. The same week, an essay argued that closed American models are being priced like luxury goods, and that "China fears" can be used to justify keeping prices high rather than competing on cost. Through that lens, "illicit distillation" is partly a real harm and partly a convenient story — a way to explain away why open models from Chinese labs are so much cheaper. The numbers in Anthropic's letter come from Anthropic's own internal detection, not from a neutral third party, and Alibaba has confirmed none of them.

The episode exposes an awkward truth about modern AI. A model that talks to the public for a living cannot fully hide what it knows, because every answer it gives is a small leak of the expertise inside it. Protecting that expertise may turn out to be one of the hardest problems the leading labs face, and it is now tangled up with national security, antitrust law, and a coming wave of export rules redrawing the AI map.

The honest caveat: treat the specific figures as Anthropic's allegation, not established fact. The most important missing piece is independent verification — both of the scale Anthropic describes and of who exactly was behind the accounts. Until a neutral party or a court weighs in, the cleanest way to hold this story is to take the broad pattern seriously while keeping the precise numbers, and the word "theft," in quotation marks.


Originally published on Ground Truth, where every claim is checked against the primary source.

Top comments (0)