All news
AIJun 25, 2026

Anthropic accuses Alibaba's Qwen lab of the largest known "distillation attack" on Claude

A letter Anthropic sent the US Senate Banking Committee, made public this week, accuses Alibaba's Qwen lab of what it calls the largest known distillation attack against Claude — roughly 25,000 fraudulent accounts and about 28.8 million interactions between April 22 and June 5, allegedly to extract Claude's most advanced software-engineering and agentic-reasoning behavior. Distillation here means systematically prompting a rival model and training on its outputs to replicate its behavior, which Anthropic says breached its terms. Senators reacted by floating an amendment to sanction foreign firms that improperly access US model outputs.

Why it matters: Distillation is a normal, widely used technique — the entire premise of many smaller open models is learning from a stronger one's outputs — so the fight isn't about the method, it's about doing it to a competitor at industrial scale and against its terms. That reframes model behavior as intellectual property that can allegedly be stolen through the front door of an API, which raises a genuinely hard question the industry hasn't settled: if capabilities can be siphoned by anyone with enough accounts and prompts, what exactly does a frontier lead protect, and for how long? The move to Washington is the real escalation — routing this through a Senate committee and a sanctions amendment folds model-output IP into US-China tech tensions and invites regulation of what labs are permitted to learn from each other. Expect a defensive arms race in response: tighter rate limits, aggressive anti-abuse detection, and stricter terms of service, all of which quietly raise the cost and friction of legitimate API use for ordinary builders caught in the blast radius.

Read the full story at CNBC
Share

Comments