Anthropic accuses operators linked to Alibaba of scraping Claude for Qwen
Anthropic is at the center of a dispute that goes far beyond a simple violation of terms of service. The company accused operators linked to Alibaba's AI lab, Qwen, of using nearly 25,000 fraudulent accounts to extract capabilities from Claude between April and June 2026. The accusation, which gained traction in a post on social network X, raises questions about who can access cutting-edge US AI and how cloud accounts are verified.
Anthropic claims the campaign generated over 28.8 million interactions with Claude, focusing on software engineering and agentic reasoning. These are capabilities that make Claude valuable to developers and enterprise workflows. Dario Amodei, co-founder of Anthropic, is turning this issue into a political fight over export controls, arguing that if a restricted entity can access a cutting-edge model via proxy accounts, it amounts to indirect access to the underlying capability.
What Anthropic says happened
The distillation technique, common in AI labs, involves training a smaller or cheaper model with the outputs of a stronger model. Anthropic alleges that external operators used fraudulent accounts to generate large volumes of Claude responses, which could be used to train or improve another model. In February, Anthropic had already accused other companies of similar campaigns, but the allegation against Alibaba is larger in volume.
The letter sent to the US Senate highlights that the operation was the largest known against the company to date. Anthropic is pushing for distillation attacks to be treated as an export control issue, especially when large volumes of compute and infrastructure are involved.
Why Qwen is the point of contention
Alibaba has made Qwen the center of its AI strategy, offering access to developers and businesses through the Alibaba Cloud Model Studio. This puts Qwen in direct competition with models from other giants like OpenAI and Google. Anthropic's accusation does not prove Qwen's capabilities came from Claude, but points out that operators affiliated with Alibaba conducted the extraction campaign.
The timing of the accusation is crucial. If true, the campaign happened after Anthropic had already publicly warned about Chinese labs using networks of accounts to mine Claude. This suggests that the problem may have shifted from specialized labs to a larger company with clear incentives to compete with cutting-edge US labs.
Political and technical strategy
Anthropic argues that distillation attacks reinforce the need for export controls, as large-scale extraction still requires compute and infrastructure. The June letter takes this argument to Congress, targeting Alibaba as a politically more visible target. Anthropic benefits if lawmakers treat model access, cloud account verification, and cutting-edge model outputs as part of the same control as chips.
The unanswered question is attribution. Anthropic says it can identify distillation campaigns through IP correlation, request metadata, and infrastructure indicators. These methods may be sufficient for account bans and government briefings, but they are not the same as a public forensic record linking a model's benchmark gains to data derived from Claude.
The accusation against Alibaba is the clearest sign yet that model providers now see access control as product strategy, policy, and intellectual property defense all at once. The battle for access and data control is just beginning.





Comments (0)
Comments are moderated and if they violate our Terms and Conditions of use, the comment will be deleted. Persistence in violation will result in a ban of your account.