Distillation Technologies Request Access

Home  /  Newsroom  / 

Anthropic alleges the largest known distillation campaign against a commercial model

In a letter to the Senate Banking Committee, Anthropic said operators connected to Alibaba’s Qwen lab ran roughly 28.8 million exchanges with Claude through about 25,000 fraudulent accounts over 44 days.

Analysis Sourced

On 10 June 2026 Anthropic wrote to senior members of the US Senate Banking Committee alleging that operators connected to Alibaba’s Qwen laboratory had conducted what it described as the largest known distillation attack ever carried out against a commercial AI model.

The specific allegations

According to the letter as reported, the campaign involved approximately 25,000 fraudulently created accounts running roughly 28.8 million exchanges with Claude across a 44-day window between 22 April and 5 June 2026. Anthropic characterised the activity as industrial-scale capability extraction rather than ordinary use, and said it was directed at specific capability areas: software engineering, multi-step reasoning, and cybersecurity tasks.

Reporting also attributed a separate and smaller volume, on the order of 3.4 million exchanges, to operators associated with Moonshot AI, targeting agentic reasoning and tool use, coding and data analysis, computer-use agent development, and computer vision.

Why the numbers matter

The figures are the substance of the complaint. Distillation at a scale sufficient to move frontier capability requires enormous query volume, because each response is a single training example. Twenty-eight million exchanges is consistent with building a substantial instruction-following corpus. It is also, notably, the kind of volume that is difficult to obtain through a single legitimate commercial account, which is where the fraudulent-account allegation does its work: it converts a terms-of-service dispute into something closer to a fraud claim.

What the letter did not establish

A volume of queries is not, by itself, proof that a specific competing model was trained on the results. Establishing that link requires either internal evidence from the accused party or a reliable attribution method applied to the resulting model, and reliable attribution remains an open research problem. The letter set out an allegation supported by traffic analysis. It did not, on the public record, demonstrate that any particular released model was a product of that traffic.

That distinction became central six weeks later, when the same evidentiary question was raised about the White House’s claims regarding Kimi K3.