Anthropic Accuses Alibaba-Linked Operators of Mining Claude for Qwen - RuntimeWire
RuntimeWire
You're browsing RuntimeWire with JavaScript disabled. Articles and<br>navigation work fully. Interactive features — search, comments,<br>and newsletter signup — require JavaScript.
Why it matters
Anthropic is turning model distillation from a terms-of-service dispute into a policy fight over who can access US frontier AI, how cloud accounts are verified, and whether cheaper Chinese models are competing on original capability or harvested outputs.
Dario Amodei's Anthropic accused operators linked to Alibaba's Qwen AI lab of using nearly 25,000 fraudulent accounts to extract Claude capabilities between April 22 and June 5, 2026, according to a June 10 letter described by Bloomberg and separately seen by Reuters.
The claim, amplified Wednesday in a thread on X, puts Alibaba inside the argument Anthropic has been building for months: that the frontier AI race is no longer just about who can buy chips or hire researchers, but who can prevent rivals from using high-end model outputs as training data. Anthropic says the Alibaba-linked campaign generated more than 28.8 million exchanges with Claude and focused on software engineering and agentic reasoning, two of the capabilities that make Claude commercially useful for developers and enterprise workflows.
Amodei and his sister, Daniela Amodei, co-founded Anthropic in 2021 after leaving OpenAI, and the company has consistently tried to frame its commercial model business as a national-security project as much as a software business. That framing matters here. Anthropic is not merely saying an account farm violated its terms. It is arguing that a major Chinese technology company used Claude outputs to accelerate the development of Qwen, Alibaba's foundation-model family, while bypassing Anthropic's decision not to offer commercial Claude access in China.
Reuters reported that Anthropic described the operation as the largest known distillation attack against the company to date. The letter was sent to Senate Banking Committee Chair Tim Scott and ranking member Elizabeth Warren, according to Reuters, before a scheduled hearing on AI. That audience was not incidental. Anthropic has been pressing the case that model distillation is an export-control problem: if a restricted entity can reach a frontier model through proxy accounts, the practical effect can resemble gaining indirect access to the underlying capability.
What Anthropic says happened
Distillation is a common technique inside AI labs: a smaller or cheaper model is trained on the outputs of a stronger model. Used within one company, it can make models faster, cheaper, or easier to deploy. Anthropic's allegation is narrower and more pointed. It says outside operators used fraudulent accounts and proxy-like access patterns to generate high volumes of Claude responses that could be used to train or improve another model.
Anthropic laid out the same playbook in a February post on detecting and preventing distillation attacks. In that earlier disclosure, Anthropic accused DeepSeek, Moonshot AI, and MiniMax of running industrial-scale campaigns that produced more than 16 million Claude exchanges through more than 24,000 fraudulent accounts. The company said those campaigns targeted agentic reasoning, tool use, coding, computer vision, and chain-of-thought-like reasoning traces.
The Alibaba allegation is larger by volume than the February cases Anthropic disclosed. Reuters' account of the June 10 letter says the campaign ran for roughly six weeks and generated 28.8 million Claude exchanges through almost 25,000 accounts. Bloomberg Law reported that Anthropic said the Alibaba-linked activity targeted Claude's prized capabilities, including software engineering and agentic reasoning.
Those are not abstract benchmark categories. Coding and agentic reasoning are where model vendors are trying to turn general chatbots into systems that can write software, call tools, execute multi-step tasks, and hold a workflow together across many actions. If a rival can cheaply harvest examples in those categories, it can reduce the amount of original training and reinforcement-learning work needed to ship a competitive model.
Why Qwen is the obvious flashpoint
Alibaba has made Qwen central to its AI push. Alibaba Cloud Model Studio markets access to Qwen, Wan, and other models for developers and enterprises, and Alibaba's commercial AI strategy depends on getting Qwen into the workflows that OpenAI, Anthropic, Google, DeepSeek, MiniMax, and Moonshot are also chasing. That makes Qwen both a product line and a distribution wedge for Alibaba Cloud.
Anthropic's accusation does not prove that Qwen's published capabilities came from Claude. It says operators affiliated with Alibaba and Alibaba Qwen ran the extraction campaign. That distinction matters: the public record described by Bloomberg and Reuters is Anthropic's allegation, not...