Anthropic accused Alibaba of running what it called the largest campaign to illicitly extract Claude AI capabilities, saying the effort involved almost 29 million exchanges through thousands of fraudulent accounts. The allegation, laid out in a 10 June letter to US Senators Tim Scott and Elizabeth Warren, puts one of the most aggressive claims yet around the copying of American AI systems in front of Congress.
That is why the keyword is drawing attention now: Anthropic did not describe a small breach or a one-off misuse, but a campaign it said was brazen, industrial in scale and aimed at the model’s most valuable strengths. Those capabilities included Claude’s ability to handle longer and more complex tasks and its approach to decision-making, the areas that make a model useful enough to replicate, not just query.
Anthropic said the operators linked to Alibaba used distillation attacks, a method that extracts answers from a stronger AI model to train a weaker one. In its framing, the harm is not only the copying itself. It is the scale. If the company’s account is right, the exchanges were not random prompts but a systematic attempt to harvest and repackage Claude’s output so that Chinese companies could turn US AI investment into a cheaper substitute.
The company went further in the letter, saying the same style of attack can be used against other targets and that some of the alleged activity posed a threat to the US military. Anthropic also cited US Department of Defense claims that Alibaba, BYD and Baidu are tied to the Chinese military, even as Alibaba has denied those allegations and is suing the US government this week to try to get its name removed from the Pentagon blacklist. The clash matters because it turns a technical accusation into a broader national-security fight.
What Anthropic says it has not fully explained is how it linked the nearly 29 million exchanges to Alibaba operators. The company gave Congress the size of the alleged campaign and the method, but not the chain of proof in public. That leaves lawmakers with a harder question than whether the conduct was serious: whether current US rules can punish the companies behind these attacks at all, and if so, whether Congress has the appetite to make the penalties sharp enough to matter.
For Anthropic, the warning is simple. Distillation attacks, in its words, can turn hundreds of billions of dollars in American investment and research and development into a subsidy for geopolitical competitors. For Scott and Warren, the letter is now part of a larger decision about whether the US treats AI theft as a policy problem, a trade problem or a security problem — and whether any of those labels will bring consequences fast enough to change behavior.

