Sunday Jun 28

Anthropic Says Alibaba Copied Claude

24JUN
KNOCKOFFCLAUDEALIBABA COPY

Someone ran 25,000 fake accounts to clone Claude. Anthropic told the Senate it was Alibaba's Qwen lab. They mimicked normal users, just 28.8 million times.

Distillation means querying a rival model to train your own. Anthropic says the attack targeted Claude's best skills: coding and agentic reasoning.

The accounts ran 28.8 million exchanges between April and June. Anthropic sent the evidence to Senators Tim Scott and Elizabeth Warren. The timing lands right before a Senate AI hearing.

Distillation is cheap, fast, and nearly impossible to prove. This is the first time a lab named a rival publicly to lawmakers.

full brief & sources

Why this matters

  • First time a US lab has publicly named a foreign rival as a model thief.
  • Distillation could erase the cost gap that justifies billion-dollar training runs.
  • It hands Washington a concrete case as AI export rules are debated.

🔍 What happened

  • Anthropic letter to the Senate Banking Committee, reported by CNBC June 24.
  • About 25,000 fraudulent accounts, 28.8 million exchanges, April 22 to June 5.
  • Queries targeted software engineering and agentic reasoning, Claude's priciest skills.
  • Attackers behaved like ordinary users to dodge detection.
  • Sent to Senators Tim Scott and Elizabeth Warren, plus White House officials.

💬 Smart takes

  • Anthropic: the operators acted 'brazenly' and 'illicitly' to extract its capabilities.
  • CNBC: Alibaba's stock slid as the accusation spread.
  • Skeptic: querying a public API is not obviously illegal, and proving intent in court is hard.

🧭 Where this goes

  1. LikelyAnthropic adds tighter rate limits and account verification to the API.
  2. Likelythe letter fuels new US export and access limits on Chinese labs.
  3. Possibleother labs disclose their own distillation cases to regulators.
  4. PossibleAlibaba denies it and the dispute stalls without hard proof.
  5. Wild Carddistillation defense becomes a paid enterprise feature within a year.

🥄 The Spoon Take

The moat was never just the model. It is the data and the cost to train it. If a rival can copy your best skills for the price of API calls, the lead you paid billions for shrinks fast. Anthropic is turning a technical problem into a political weapon.

🤔 Pushback

Querying a public API at scale may be sleazy but not clearly illegal, and Anthropic has shown a letter, not a verdict.