The CNBC story broke on June 24. Anthropic sent a letter to the US Senate Banking Committee two weeks earlier, on June 10, addressed to Senators Tim Scott and Elizabeth Warren. The letter accused Alibaba’s Qwen AI lab of running the largest known distillation attack on Anthropic’s Claude models.

The numbers deserve attention. 28.8 million exchanges. 25,000 fraudulent accounts. 44 days between April 22 and June 5. Three specific capabilities targeted: software engineering, agentic reasoning, and long-horizon tasks. These are the capabilities that underpin Anthropic’s Mythos Preview, its most advanced commercial offering.

Model distillation is a standard technique in AI research. You use a large model’s outputs to train a smaller, cheaper one. The technique itself is not the problem. The problem is doing it without permission, at industrial scale, through fraud. Opening 25,000 accounts is not a research project. It is a coordinated extraction campaign.

Alibaba’s Qwen lab was not working in isolation. Anthropic had already identified three similar campaigns earlier this year. DeepSeek ran 150,000 exchanges. Moonshot ran 3.4 million. MiniMax ran 13 million. The Alibaba campaign is roughly double the MiniMax figure. If you sum the three previous campaigns, Alibaba’s single operation comes close to matching them combined.

(The White House Office of Science and Technology Policy issued a memorandum in April pledging to help AI companies detect and coordinate against industrial-scale distillation. Anthropic’s letter says Alibaba “ignored the Trump Administration’s warnings.”)

A model built through adversarial distillation copies the capabilities but not the safety training. The guardrails fall off. That is the concern Anthropic raised to the committee. A stolen copy of Claude’s engineering capabilities with no safety alignment is a different threat model from a stolen patent.

Alibaba shares dropped 4.9 percent in Hong Kong, hitting a 16-month low. The broader Chinese AI sector took a hit too. Xiaomi and Baidu both dropped more than 3 percent.

This story is not going to resolve cleanly. Alibaba will deny, as Chinese AI labs have denied before. The US government is in an awkward position. It recently ordered Anthropic to restrict Fable 5 and Mythos 5 access to foreign nationals, citing national security. Now it is being asked to help Anthropic detect and stop the same foreign nationals from accessing the models. The policies are pulling in opposite directions.

The timeline matters. Anthropic’s export control directive came June 12, two days after the letter went to the Banking Committee. The White House memo was April. The Alibaba campaign ran April 22 to June 5. Everyone in this chain was moving at different speeds.

Two years from now, this will look like a pivot point. The industrial-scale distillation attacks have been growing by orders of magnitude. DeepSeek at 150K. Moonshot at 3.4M. MiniMax at 13M. Alibaba at 28.8M. The curve is steep and nobody has a proven defense. The question is not whether the next attack will be bigger. The question is which model’s capabilities are being duplicated when it happens.

If the next target is a system with safety-critical deployment, the gap between the capability theft and the safety guardrail removal is where the real risk lives. That gap is getting narrower.