Operators affiliated with Alibaba allegedly carried out the largest illicit AI distillation campaign Anthropic has ever detected, extracting the reasoning capabilities of its Claude models at a peak rate of nearly 3 million exchanges a day.
According to Anthropic’s September 2026 threat report, the operation generated more than 151 million exchanges between May and July 2026. The campaign allegedly targeted Claude Opus 4.6 and 4.7, with the stolen outputs subsequently converted into training data for Alibaba’s Qwen family of AI models.
Anthropic described the activity as the largest AI distillation attack it has “ever measured,” highlighting the growing battle among AI developers to protect proprietary model capabilities.
Credits: CNBC
How Alibaba Allegedly Extracted Claude’s Reasoning
The campaign reportedly relied on a systematic pipeline designed to capture Claude’s chain-of-thought reasoning. A fixed prompt was inserted into requests, instructing Claude to provide its reasoning inside inline text tags before producing its final answer.
Those reasoning transcripts were then converted into supervised fine-tuning data, which Anthropic says was used to help train Qwen 3.5, 3.6 and 3.7.
The operation focused heavily on tasks requiring advanced reasoning and technical capabilities. These included software engineering, kernel development, agentic workflows and long-horizon problem-solving.
At its peak, Anthropic said the operation generated almost 3 million exchanges per day through more than 3,500 fraudulent accounts.
The alleged use of Claude extended beyond simply collecting model outputs. Anthropic said Alibaba also used Claude to assist with internal model-development infrastructure, reinforcement-learning environments and research into model architecture.
Thousands of Fraudulent Accounts Used
Anthropic said the campaign operated through two major waves of fraudulent accounts.
The first pool reportedly contained around 5,000 accounts and relied on residential proxies, disposable email addresses and virtual-card payments to conceal the operation’s origins.
After Anthropic banned those accounts, activity shifted to a second pool. The company said some traffic associated with this network was also linked to requests made on behalf of DeepSeek and Xiaomi, suggesting that proxy infrastructure may be shared between multiple Chinese AI companies.
Anthropic defines illicit distillation as the industrial-scale and unauthorised extraction of a rival AI model’s capabilities, typically through fraudulent access to the model.
The company warned that the implications go beyond intellectual property theft. A model trained using distilled outputs can potentially acquire improvements across a broad range of capabilities, including areas that were not directly targeted by the original extraction campaign.
Alibaba Among Seven Chinese AI Labs Named
Alibaba is one of seven China-based AI companies Anthropic says it has identified conducting illicit distillation campaigns against Claude since the company first disclosed the practice in February 2026.
The other companies named in the report are DeepSeek, Moonshot AI, Xiaomi, Zhipu (Z.ai), SenseTime and MiniMax.
Anthropic said none of the identified campaigns successfully extracted capabilities from its Mythos-class models, which are not publicly accessible.
The findings underscore the increasingly competitive nature of the global AI race, where access to leading models can provide valuable training data for rival systems without requiring developers to reproduce every capability from scratch.

Credits: Reuters
Anthropic Tightens Defences Against Model Extraction
Anthropic said it has introduced several measures to counter large-scale distillation attempts. The company has developed classifiers designed to identify adversarial extraction and has shifted towards banning accounts associated with an attributed organisation rather than removing fraudulent accounts individually.
It has also introduced identity verification for accounts displaying signs of abuse or originating from unsupported countries, including China, Russia and Iran.
The company has further modified how Claude handles its reasoning. Anthropic said Claude now summarises its reasoning before responding, while its Fable 5.1 model includes a “preserved thinking” mechanism designed to prevent new API accounts from manipulating the conversation context preceding Claude’s reasoning.
Anthropic’s allegations against Alibaba are based solely on the company’s own investigation and have not been independently corroborated. The report also does not publicly disclose the technical evidence underlying its attribution of the campaign to Alibaba. Alibaba had not publicly responded to the allegations at the time of writing.




