VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog
← Value Add PulseAI28.8M exchanges

Anthropic Accuses Alibaba of Largest-Ever Attempt to Distill Claude's Capabilities

Anthropic accused Alibaba of illicitly extracting capabilities from its Claude models in what it called the largest known attack of its kind, according to a letter seen by Reuters. The campaign ran from April 22 to June 5, generating more than 28.8 million exchanges with Claude across nearly 25,000 fraudulent accounts, in what Anthropic describes as a distillation effort to accelerate China toward its frontier 'Mythos' capabilities.

Alibaba
Accused
28.8M
Exchanges
~25,000
Fake Accounts
Apr 22 – Jun 5, 2026
Window
Model distillation
Method
TC
Trace Cohen
Early-stage VC & angel · Founder, New York Venture Partners
June 24, 2026
2 min read
KEY TAKEAWAYS FOR VCs & FOUNDERS
1

Distillation -- training a weaker model on a stronger one's outputs -- is the central IP-theft fear of the frontier-AI era

2

28.8M exchanges across 25,000 fake accounts makes this the largest such campaign Anthropic has disclosed

3

It escalates the US-China AI cold war from chips and export controls to model capabilities themselves

4

It follows Anthropic's February claims against DeepSeek and others, suggesting a sustained pattern

TC
The VC Read · Trace's TakeTrace Cohen

This is the moat question every AI investor should be losing sleep over: if a frontier lab's best capabilities can be partially cloned with 29 million clever queries, how durable is any model-based advantage -- and the valuations stacked on it? The cold war just jumped from chips to capabilities, which is a fight Washington's export controls can't fight. Notably, distillation is easy against an API and hard against open weights, which quietly strengthens the case for shipping open models. Watch whether Anthropic escalates to litigation or policy -- a letter isn't a lawsuit, and proving distillation is genuinely hard, but if other labs come forward, this becomes a systemic risk, not a one-off.

🤖 AI Landscape →⚡ AI Chip Wars →

Anthropic has accused Alibaba of illicitly extracting capabilities from its Claude models in what the AI lab called the largest known attack of its kind against the company, according to a letter seen by Reuters. The campaign ran from April 22 to June 5, 2026, and generated more than 28.8 million exchanges with Claude through nearly 25,000 fraudulent accounts -- a scale that dwarfs prior incidents.

The alleged technique is distillation: systematically querying a stronger model and using its outputs to train a less capable one, effectively cloning hard-won capabilities at a fraction of the cost. Anthropic said in the letter that the effort was designed to help accelerate China's path toward the advanced 'Mythos Preview' capabilities Anthropic is developing -- framing it not as ordinary scraping but as a targeted attempt to short-circuit years of frontier research.

The accusation lands on a fault line that has been widening all year. In February, Anthropic said it had identified a campaign by Chinese AI startup DeepSeek and two other Chinese labs to extract Claude capabilities, though those operations involved far fewer exchanges. The Alibaba claim suggests both that the practice is intensifying and that the biggest Chinese tech players -- not just upstarts -- may be involved, even as Alibaba's Qwen models earn genuine praise for original research.

“The accusation lands on a fault line that has been widening all year.”

The context is a US-China AI rivalry that has so far centered on hardware: export controls on Nvidia GPUs, the fight over ASML's lithography machines, and Washington's effort to choke China's access to advanced chips. Anthropic's allegation moves the battlefield to the models themselves, raising the prospect that capability theft -- not just compute denial -- becomes the next front. It also complicates the open-weight debate, since distillation is far easier against API-accessible frontier models than against the open models Chinese labs increasingly ship.

For founders and investors, the episode is a warning about how fragile the frontier moat may be. If a leading lab's best capabilities can be partially reconstructed through 29 million well-designed queries, the durability of model-based advantages -- and the valuations built on them -- comes into question. It also strengthens the case for the labs to lock down API access, watermark outputs and pursue legal and policy remedies.

The bear case for Anthropic's framing: distillation is notoriously hard to prove, the line between legitimate benchmarking and illicit extraction is blurry, and a letter is not a lawsuit. Alibaba has strong incentives to dispute the characterization, and independent verification of the claim is not yet public. What to watch: whether Anthropic escalates to legal action or pushes for policy intervention, how Alibaba responds, and whether other frontier labs disclose similar campaigns -- the tell that capability theft has become a systemic risk to the whole industry.

ShareXLinkedInEmail
More onAnthropic →

Originally reported by Reuters. Analysis and editorial commentary by Value Add Pulse.

← Back to Pulse

Markets Now

live
SPCX▲+1.89%
$231.40
CBRS▲+0.51%
$258.10
SPY▲+0.09%
5,948.20
QQQ▲+0.13%
20,038.10
NVDA▲+0.46%
$153.60
MSFT▲+0.29%
$481.20
GOOGL▼-0.33%
$208.40
META▲+0.38%
$653.90

Read Next

AI

Meta Revives Facebook's Creator Studio as a Standalone AI Companion App

Meta has relaunched Facebook's Creator Studio as an AI companion app, repositioning a dormant publishing dashboard into an AI-powered assistant for content creators. The move folds Meta's generative tools into a dedicated creator product, part of a broader push to embed AI across its apps and keep creators inside its ecosystem rather than defecting to rival tools.

AI

Google Keeps Losing AI Researchers to Rivals as the Talent War Intensifies

AI researchers are continuing to depart Google for its rivals, according to TechCrunch, extending a steady exodus of senior talent from the company that pioneered the transformer. The brain drain -- toward OpenAI, Anthropic, startups and well-funded new labs -- underscores how the scarcest resource in AI is not compute or capital but the small pool of people who can build frontier systems.

AI

AI Was Supposed to Kill Engineering Jobs -- New Data Suggests They're the Most Resilient

Despite predictions that AI coding tools would gut software engineering employment, new data suggests engineering roles are among the most resilient to AI disruption, according to TechCrunch. The finding complicates the dominant narrative -- reinforced this week by SpaceX's $60B Cursor deal -- that agentic coding is rapidly replacing human developers.

@Trace_Cohen·t@nyvp.com