In Short: Anthropic has formally accused Alibaba of running the largest AI model distillation attack ever detected — using ~25,000 fake accounts to generate 28.8 million exchanges with Claude over 44 days. The accusation has ignited a geopolitical firestorm involving Pentagon blacklists, export control paradoxes, new US legislation, and China’s unveiled counter-weapon, “Yitian Tulong.”
CNBC-TV18 AI Pulse report on Anthropic’s accusation against Alibaba for the largest known AI distillation attack
What Actually Happened?
Between April 22 and June 5, 2026 , operators affiliated with Alibaba and its Qwen AI lab executed an industrial-scale AI model distillation attack against Anthropic’s Claude models. According to a formal letter sent to Senators Tim Scott and Elizabeth Warren on June 10 , the attackers used approximately 25,000 fraudulent accounts to generate 28.8 million exchanges — targeting Claude’s most advanced software engineering and agentic reasoning capabilities, particularly the Mythos Preview class.
“ These distillation attacks are carried out illicitly, systematically, and at an industrial scale to harvest U.S. AI capabilities across frontier labs and repackage them as their own without incurring the training and R &D costs,” the letter states.
What Is an AI Distillation Attack?
AI model distillation trains a smaller “student” model on the outputs of a larger “teacher” model. The student learns to mimic the teacher’s capabilities at a fraction of the training cost. In legitimate contexts, it’s a valuable research tool. But at industrial scale and without authorization, it becomes AI theft — the attacker avoids billions in R&D while replicating the core capability.
Explainer video on AI model distillation and how it enables copying AI capabilities at a fraction of the cost
This Wasn’t the First — It Was the Biggest
The Alibaba campaign is the latest in a rapid escalation of distillation attacks detected since early 2026. Each successive campaign represents a massive jump in scale:
| Entity | Exchanges |
|---|---|
| DeepSeek | Over 150,000 |
| Moonshot AI | Over 3.4 million |
| MiniMax | Over 13 million |
| Alibaba / Qwen | 28.8 million |
As AI harness engineering accelerates software development, the tools for both legitimate and malicious distillation become more powerful — and harder to detect. This escalation mirrors the broader US-China AI infrastructure arms race, where both sides pour resources into frontier capabilities.
The Ironic Regulatory Backdrop
Just two days after Anthropic’s letter, on June 12 , the US Commerce Department ordered Anthropic to suspend all access to Fable 5 and Mythos 5 for any foreign national — including its own foreign national employees. An American AI company simultaneously accuses China of stealing its tech while the US government prevents it from selling that same tech. Fortune called it a “national security paradox.”
Adding another layer: in February 2026, President Trump ordered all federal agencies to stop using Anthropic models after the company refused Pentagon contract terms allowing AI use “for any lawful purpose.”
The Pentagon, the Blacklist, and Alibaba’s Lawsuit
On June 9 — one day before Anthropic’s letter — the Pentagon added Alibaba to its “Chinese military companies” list under Section 1260H. Then on June 23 , Alibaba sued the Department of Defense, calling the designation “ arbitrary and capricious. ” The company accused of orchestrating the largest AI theft in history is simultaneously in US court arguing it’s a commercial entity, not a military arm of China.
New Legislation Targets AI Distillation
Senators Bill Hagerty (R-TN) and Andy Kim (D-NJ) are drafting an amendment to defense legislation that would blacklist or sanction Chinese firms caught improperly accessing US AI model outputs. The amendment reframes distillation as a national security issue — not just IP theft. This builds on the Five Eyes’ recent warning that frontier AI could destabilise governments within months.
China’s Answer — ‘Yitian Tulong’
On June 25 , Chinese security firm 360 Security Technology unveiled “Yitian Tulong” (Heavenly Sword and Dragon Saber) at the ISC.AI 2026 conference in Beijing. Its Tulongfeng component is explicitly branded as “China’s version of Mythos” — the very model Alibaba is accused of trying to replicate. NSA Chief Joshua Rudd previously testified that Mythos Preview “ broke into almost all of our classified systems, not in weeks, but in hours. “
Market Fallout
Alibaba shares (BABA) hit a 16-month low on June 25, dropping more than 4%. The dual shock of the Anthropic accusations and the Pentagon blacklist lawsuit — layered on US-China tech decoupling fears — has erased billions in market value.
What Happens Next?
Watch the Hagerty-Kim amendment (which could create a legal framework for sanctioning distillation attacks), Alibaba’s lawsuit (could set precedent for “Chinese military company” designations), Yitian Tulong’s real capabilities, and the next attack — the escalation from 150K to 28.8M in under six months suggests the next campaign could breach 100 million exchanges.
Sources
- Reuters — Anthropic says Alibaba illicitly extracted Claude AI model capabilities
- CNBC — Anthropic accuses Alibaba of ‘brazenly’ extracting AI model capabilities
- BBC — Anthropic accuses Chinese firms of large-scale AI theft
- Forbes — Anthropic disabled Fable 5 and Mythos 5 after US export control order
Frequently Asked Questions
What is an AI distillation attack?
AI model distillation trains a weaker “student” model on outputs of a stronger “teacher” model. Without authorization, it’s AI theft — the attacker avoids billions in R&D costs.
How many queries did Alibaba make to Claude?
Approximately 28.8 million exchanges through ~25,000 fake accounts over 44 days (April 22 – June 5, 2026).
What is Yitian Tulong?
A two-part AI cybersecurity system unveiled by 360 Security Technology at ISC.AI 2026, with its Tulongfeng component branded as “China’s version of Mythos.”
What is Mythos Preview?
Anthropic’s state-of-the-art cybersecurity AI model. The NSA testified it broke into almost all classified US systems “not in weeks, but in hours” during testing.
Featured image: AI-generated concept art. Video credits: CNBC-TV18, CNBC. Article originally published on TekMag.
Originally published on TekMag
Top comments (0)