Anthropic just accused one of China’s biggest tech companies of pulling off the largest known AI model theft in history. And the method was almost embarrassingly simple: create a bunch of fake accounts and just… ask questions. A lot of them.
The company alleges that Alibaba’s Qwen AI lab orchestrated a coordinated distillation attack using roughly 25,000 fake accounts that generated over 28.8 million interactions with Claude between April 22 and June 5, 2026. The operation’s goal, according to Anthropic, was to extract Claude’s advanced coding capabilities and use the outputs to train Alibaba’s own Qwen models.
How distillation attacks actually work
Model distillation is one of those techniques that sounds innocuous until you see it weaponized at scale. In plain English: you feed a powerful AI model carefully crafted prompts, collect the responses, and then use those responses as training data for your own, cheaper model. The student learns from the teacher’s answers without ever seeing the teacher’s textbook.
What makes this particular attack notable is how it stayed under the radar. The operation reportedly kept individual account activity below standard rate limits, meaning no single account was behaving suspiciously enough to trigger automated defenses. Spread across 25,000 accounts over roughly six weeks, that works out to an average of about 1,152 queries per account, or roughly 26 queries per account per day.






