Alibaba Stole 29 Million Claude Conversations – The Biggest AI Theft in History Explained
Imagine spending years and billions of dollars building something extraordinary. You hired the best researchers in the world. You ran millions of experiments. You made thousands of decisions about how your system should think, reason, and behave. And then someone created 25,000 fake identities, quietly knocked on your door nearly 29 million times, and walked away with the most valuable parts of everything you built.
That is essentially what Anthropic is accusing Alibaba of doing to Claude.
In a letter sent to US Senators Tim Scott and Elizabeth Warren on June 10, 2026, Anthropic's Head of Policy described what the company calls the largest recorded corporate espionage campaign against an AI system in history. The alleged operation ran for 45 days, generated more than 28.8 million interactions with Claude through approximately 25,000 fraudulent accounts, and was specifically designed to harvest the most sophisticated capabilities of Anthropic's frontier AI model — then use those capabilities to train a competing Chinese model.
This story matters far beyond the corporate conflict between two AI companies. It touches on questions that affect everyone who uses AI tools: the security of the technology you rely on, the geopolitics of AI development, what data theft means in an age of intelligent systems, and what happens when the most capable AI models become the target of industrial-scale theft.
In this article, I want to break down exactly what happened, how the alleged theft worked, what the consequences have been, and what it means for you.
What Actually Happened?
Between April 22 and June 5, 2026, Anthropic detected an unusual pattern of activity on its Claude platform. Approximately 25,000 accounts — later alleged to be connected to Alibaba's AI research lab, Qwen — were systematically querying Claude with highly specific, complex questions focused on two areas: software engineering and agentic reasoning.
These were not random queries. They were carefully designed prompts intended to draw out Claude's most sophisticated responses — the kind of answers that take years of training and billions of dollars in research to produce. The accounts collected these responses at scale, saving them as training data.
The technical term for what Anthropic alleges is "adversarial distillation" or a "distillation attack." It is a form of intellectual property theft specific to AI — and understanding how it works is important for understanding why this case matters so much.
What is AI Distillation — and Why is it Such a Big Deal?
To understand the significance of what Anthropic is alleging, you need to understand what model distillation is and why it is so valuable.
Training a frontier AI model from scratch is extraordinarily expensive. OpenAI spent hundreds of millions of dollars training GPT-4. Anthropic has spent similar amounts on Claude. Google has spent even more on Gemini. The cost comes not just from computing power but from years of research, millions of experiments, enormous amounts of carefully curated training data, and the accumulated expertise of thousands of engineers and scientists.
Model distillation is a legitimate technique that allows companies to compress their own large, expensive models into smaller, faster, cheaper versions that can run more efficiently. You take a big model — the teacher — ask it lots of questions, collect its responses, and use those responses to train a smaller model — the student — to behave similarly. It is legal, widely used, and an important part of how AI development works in practice.
The line Anthropic is drawing is between using this technique on your own models — which is standard practice — and using it on a competitor's model without permission, at industrial scale, through fraudulent accounts. That is what Anthropic is calling theft.
When you distill a competitor's model at scale, you are essentially acquiring decades of research and billions of dollars of investment for the cost of running API queries. Instead of building from scratch — doing the experiments, making the discoveries, spending the money — you harvest the outputs of someone else's work and use them to train your own system.
There is a financial dimension and a safety dimension to this.
The financial dimension is obvious. If you can effectively copy the capabilities of a frontier AI model for a fraction of what it cost to build, you gain a massive competitive advantage without bearing the equivalent cost or risk.
The safety dimension is more subtle but arguably more concerning. As Anthropic's policy team noted in their letter, a distilled model may produce similar outputs to the original — but it does not inherit the safety alignment built into the original. Claude has been trained with extensive safeguards — rules about what it will and will not do, how it handles sensitive topics, how it refuses dangerous requests. These safety guardrails are built through a separate and extensive training process that happens after the initial capability training.
When you distill Claude's capabilities without its safety training, you get a model that can do what Claude does — without the safeguards that prevent it from doing harmful things. The dangerous capabilities transfer through the outputs. The months spent making the model safe do not.
The Scale of What Anthropic Alleges
To appreciate the alleged scale of this operation, some context helps.
Earlier in 2026, Anthropic accused three Chinese AI startups — DeepSeek, Moonshot AI, and MiniMax — of collectively conducting 16 million interactions with Claude through 24,000 fraudulent accounts. That was significant enough to trigger a response at the time.
The alleged Alibaba operation is nearly double that in interactions, and it involved a single organization. The accounts operated by Alibaba's Qwen AI team engaged in more than 28.8 million conversations with Claude between April 22 and June 5, 2026. That is an average of more than 640,000 conversations per day, every day, for 45 consecutive days.
Anthropic's Head of Policy Sarah Heck said the attacks were carried out "illicitly, systematically, and at industrial scale to harvest US AI capabilities across frontier labs and repackage them as their own without incurring the training and R&D costs."
This is not a rogue actor or a small team of hackers. Anthropic is accusing one of the world's largest technology companies — Alibaba, with a market capitalization in the hundreds of billions of dollars — of organizing and executing a systematic campaign to steal the capabilities of a competitor's AI system.
Anthropic also alleged in its letter that the Chinese government was complicit in the attacks as part of China's broader push to assert global dominance in AI development. This is a significant accusation — moving the story from corporate intellectual property dispute to matters of national security.
What Happened After Anthropic's Letter?
The consequences of Anthropic's letter have been swift and significant.
Two days after the letter was sent to senators — on June 12 — the US Commerce Department imposed strict restrictions on Anthropic's most advanced models, "Mythos" and "Fable." Anthropic has since disabled public access to both models globally, pending clarification from the federal government.
The reasoning behind the government restrictions was essentially: if these models are powerful enough that a foreign government is conducting industrial-scale operations to steal their capabilities, they are powerful enough to be considered potential national security assets requiring government oversight of their distribution.
This is an extraordinary development. An American AI company's most advanced products have been temporarily pulled from global availability — not because of anything the company did wrong, but because the US government determined that their capabilities require controlled distribution.
Meanwhile, Alibaba has not publicly confirmed or denied the specific allegations. The broader context of US-China technology competition — including export restrictions on advanced AI chips — adds significant geopolitical weight to what might otherwise be treated as a corporate legal dispute.
Who is Alibaba's Qwen AI Lab?
For readers unfamiliar with Qwen, a brief introduction is useful.
Qwen is Alibaba's AI research division, responsible for developing the Qwen series of large language models. The Qwen models have been competitive with leading Western AI systems on several benchmarks and are widely used across Alibaba's vast ecosystem of businesses and services.
Alibaba is not a small company trying to shortcut its way to capability it could not otherwise achieve. It is one of the world's largest technology companies, with enormous resources and a talented AI research team. The allegation that it engaged in systematic distillation attacks raises questions about the economics of AI development even for well-resourced organizations — and about the competitive pressures that drive such decisions.
What Does This Mean for Regular AI Users?
You might be wondering: I use ChatGPT or Claude for everyday tasks — why does this corporate dispute matter to me?
There are several reasons why this story has direct relevance for anyone who uses AI tools.
First, it illustrates that the AI tools you use are not just software products — they are the result of enormous investments in research, safety, and alignment. When the safety-trained outputs of a carefully developed AI system are used to train a different model without those safety properties, the result is a tool that can do similar things but with fewer guardrails. This matters for anyone who cares about AI being developed and deployed responsibly.
Second, it highlights the data security dimension of using AI platforms. When you interact with any AI system through a public API or interface, those interactions are — to varying degrees — data. The Alibaba case shows that sophisticated actors can use these interactions systematically to extract valuable information. Most individual users do not need to worry about this directly, but it is worth understanding that AI systems are not passive — the interactions with them have value, and that value can be exploited.
Third, it demonstrates how seriously AI capabilities are being taken at the level of national security. The fact that the US government moved within two days of Anthropic's letter to restrict access to its most advanced models — globally — shows that AI has moved firmly into the category of strategic national assets, not just commercial products. This has implications for how AI will be regulated, distributed, and developed in the years ahead.
The Bigger Picture — AI as the New Battlefield
The Alibaba-Anthropic story is not an isolated incident. It is one piece of a much larger pattern.
DeepSeek was accused of using OpenAI's outputs to train its models. Multiple Chinese AI labs have been accused of distillation attacks against American frontier models. The US has imposed export controls on advanced AI chips specifically to slow China's AI development. China has responded with investment, state support, and what critics characterize as more aggressive approaches to capability acquisition.
What we are witnessing is the AI equivalent of the technology competition that characterized earlier eras of geopolitical rivalry — but moving faster, at a larger scale, and with stakes that include not just economic advantage but the potential to determine which nations and organizations control the most powerful AI systems in the world.
For companies like Anthropic, the challenge is significant. Building a frontier AI model is extraordinarily expensive and difficult. Protecting it from systematic extraction attacks while keeping it commercially available is a genuinely hard problem. The alternative — restricting access so severely that the model cannot be attacked — also means restricting the commercial and research value of the model. There is no easy answer.
What Anthropic Is Asking For
In its letter to senators, Anthropic made a clear request: that the US government continue to help combat distillation attacks, which the company argues have national security implications beyond corporate intellectual property concerns.
The specific policy ask involves treating systematic distillation attacks against frontier AI models as a form of technology theft that warrants government action — similar to how trade secret theft is treated in other industries. Anthropic is essentially arguing that the most capable AI models are strategic assets and that protecting them requires the kind of government involvement that protects other strategic technologies.
Whether Congress responds to this request — and how — will shape the regulatory environment for AI development in the United States for years to come.
What to Watch Going Forward
This story is not over. Several developments are worth following in the coming weeks and months.
Alibaba's response will be important. The company has not yet made a detailed public statement addressing Anthropic's specific allegations. How it chooses to respond — whether through denial, legal action, diplomatic channels, or silence — will tell us a great deal about how this situation develops.
The government's treatment of Anthropic's restricted models is worth monitoring. The temporary global restriction on Mythos and Fable is an extraordinary measure. How the Commerce Department ultimately resolves the situation — and what framework it uses to make such decisions in the future — will set important precedents.
The broader pattern of distillation attacks will likely continue regardless of how this specific case resolves. The economic incentive is too strong and the technical barrier too low. Expect this to become an ongoing challenge for AI companies rather than a problem that gets solved once and stays solved.

Comments
Post a Comment