Independent reporting on American politics
STATE BEACON

Anthropic reports 200 million AI distillation attacks, Alibaba linked to 151 million queries

Anthropic’s latest security report shows five coordinated model‑distillation campaigns generated almost 200 million queries between May and July 2026, with a single Alibaba‑attributed effort accounting for 151 million of them.

By State Beacon·
Alibaba Cloud server racks inside the Hangzhou data center that processed the 151 million AI distillation‑attack queries

Anthropic said it observed nearly 200 million distillation‑attack queries across five coordinated campaigns between May and July 2026, and that a campaign attributed to Alibaba Group was responsible for 151 million of those queries.

Scale of the attacks

The figures come from Anthropic’s internal security report, which was summarised by TechCrunch on 10 September 2026. The report defines a distillation attack as an attempt to extract knowledge from a frontier model by repeatedly querying it with carefully crafted prompts. Over the three‑month window, Anthropic logged close to 200 million such exchanges, split among five distinct campaigns.

“The bulk of the distillation attempts came from a campaign attributed to Alibaba… The company observed 151 million exchanges between May and July 2026 that were attributed to the campaign, peaking at nearly three million exchanges per day.”

Anthropic’s analysis also notes that the Alibaba‑linked effort peaked at almost 3 million queries per day, indicating a sustained, high‑volume operation.

Alibaba’s campaign details

According to the same TechCrunch story, the Alibaba campaign employed roughly 3,500 accounts that all used a single, fixed prompt. The concentration of accounts suggests a coordinated effort rather than a scattered set of opportunistic actors.

Distillation‑attack activity (May–July 2026)
MetricValueUnitPeriodSource
Total exchanges observed200millionMay–July 2026TechCrunch (quoting Anthropic report)
Exchanges linked to Alibaba151millionMay–July 2026TechCrunch (quoting Anthropic report)
Peak daily exchanges (Alibaba)3million per dayMay–July 2026TechCrunch (quoting Anthropic report)

The concentration of activity in a single campaign raises questions about the resources behind it. While the report does not disclose the ultimate purpose of the queries, Anthropic warns that such systematic extraction could erode the competitive edge of its Claude models.

Implications for US AI‑security policy

The timing of the disclosure coincides with a heated debate in Washington over mandatory AI‑security regulations. Lawmakers have cited recent incidents of model‑theft as a catalyst for stricter oversight, and industry leaders have floated voluntary slowdown measures to curb the arms race in AI capabilities.

Anthropic’s findings provide concrete evidence that state‑linked actors are capable of mounting large‑scale, technically sophisticated attacks. The report’s attribution to Alibaba, a publicly listed Chinese e‑commerce giant, underscores the geopolitical dimension of the threat.

Company snapshots

Anthropic, founded in January 2021 and headquartered in San Francisco, employs roughly 2,500 staff and is led by CEO Dario Amodei. The firm focuses on developing large‑language models, the most prominent of which is Claude.

Alibaba Group Holding Ltd, listed on the NYSE under ticker BABA, is chaired by Joseph Tsai. The company’s 2026 fiscal filing (Form 20‑F filed 20 May 2026) shows revenue of USD 148.401 billion for the year ended 31 March 2026, net income of USD 15.018 billion, total assets of USD 276.83 billion, shareholders’ equity of USD 153.796 billion, and shares outstanding of 18.580 billion. With a workforce of about 25,000, Alibaba is one of China’s largest technology conglomerates.

Both firms operate at opposite ends of the AI value chain: Anthropic builds frontier models, while Alibaba runs a massive e‑commerce platform that increasingly incorporates AI services for recommendation, logistics and cloud computing. The overlap in interests makes the attribution of a large‑scale distillation campaign to Alibaba particularly noteworthy for competitors and regulators alike.

What remains unknown

Anthropic’s report does not disclose the ultimate destination of the harvested model knowledge, nor does it confirm whether the campaign was directly orchestrated by Alibaba’s corporate unit or by an affiliated third party. The company also refrains from estimating the financial impact of the attacks on its own operations.

US agencies have previously warned that Chinese AI firms—including DeepSeek, Moonshot AI, MiniMax, StepFun and Z.AI—are engaged in large‑scale model distillation. The new Anthropic data adds Alibaba to that list, but the broader ecosystem of actors and the full scale of the threat remain subjects for further investigation.

As policymakers weigh mandatory security standards, the Anthropic findings may serve as a benchmark for what constitutes a “significant” threat. For investors, the numbers illustrate a concrete risk vector that could affect the valuation of AI‑focused companies, especially those with valuable proprietary models.

Anthropic plans to continue monitoring and publishing data on model‑theft attempts, while Alibaba has not publicly responded to the allegations.