Somewhere between late April and early June, a machine somewhere opened a fresh conversation with Claude roughly every seventh of a second, around the clock, for forty-five days. That is the arithmetic behind a single sentence in a letter Anthropic sent to two United States senators on June 10, which CNBC confirmed and reported on June 24. The letter accuses Alibaba of running “the largest known distillation attack on Anthropic to date”: 28.8 million exchanges with Claude models, through roughly 25,000 fraudulent accounts, between April 22 and June 5. This piece walks through the numbers, because the numbers are the story.
What is a distillation attack on an AI model?
Distillation is a training method. A smaller or cheaper model learns from the outputs of a stronger one. It inherits some of the capability without the training bill. Done inside one company, on models it owns, it is ordinary engineering practice. Done against a competitor’s model, at industrial scale, through fraudulent accounts and in breach of the terms of service, it becomes what Anthropic calls illicit distillation: extracting a rival’s capabilities to build your own product.
The economics explain the account numbers. Whoever is running the extraction does not need any single account to survive. They need throughput. Accounts are created in bulk, burned as they are banned, and replaced, while the harvested conversations accumulate somewhere the model owner cannot see. That is why both of Anthropic’s public disclosures this year describe account counts in the tens of thousands rather than the tens.
How big was the Alibaba campaign, by the numbers?
The June 10 letter, addressed to Senator Tim Scott and Senator Elizabeth Warren of the Senate Banking Committee, gives three load-bearing figures: 28.8 million exchanges, about 25,000 accounts, and a window running April 22 to June 5. CNBC viewed the letter; Bloomberg first reported its existence. Anthropic’s language in it is not hedged. It says Alibaba acted “brazenly” and “illicitly”, and that the campaign proceeded despite the White House having pledged, in a memorandum two months earlier, to help AI companies detect and coordinate against industrial-scale distillation.
Spread the totals across the window and the shape of the operation appears. 28.8 million exchanges in 45 days is 640,000 exchanges a day. Divided across 25,000 accounts, each account averages about 1,150 exchanges over the window, or roughly 26 a day. That last number is the telling one. Twenty-six conversations a day is low enough for any single account to look like a busy, plausible human. The scale only becomes visible in aggregate, which is exactly the point of splitting the work across so many identities.
| Figure | February disclosure (3 labs) | June letter (Alibaba) |
|---|---|---|
| Exchanges with Claude | 16 million+ | 28.8 million |
| Fraudulent accounts | ~24,000 | ~25,000 |
| Actors named | DeepSeek, Moonshot, MiniMax | Alibaba |
| Disclosed via | Company blog post, Feb 23 | Letter to senators, Jun 10 |
Sources: Anthropic’s February disclosure; Anthropic’s June 10 letter as reported by CNBC.
How does it compare with the DeepSeek, Moonshot and MiniMax campaigns?
The Alibaba allegation did not arrive out of nowhere. In February, Anthropic published a post on detecting and preventing distillation attacks naming three other labs: DeepSeek, Moonshot, and MiniMax. Together, the company said, they generated more than 16 million exchanges through roughly 24,000 fraudulent accounts, with MiniMax alone driving more than 13 million. Each campaign had a signature. DeepSeek’s targeted reasoning. Moonshot’s went after agentic tool use and coding. MiniMax focused on agentic coding and orchestration, and when Anthropic shipped a new model mid-campaign, the February post says MiniMax redirected nearly half its traffic to the new system within 24 hours.

Put the two disclosures side by side and the trajectory is stark. Three labs together produced 16 million exchanges. One company, months later, is alleged to have produced 28.8 million on its own, nearly double the combined February total, with an account pool of almost identical size. Whatever detection pressure the February disclosure created, the alleged response was not retreat. It was consolidation into fewer, larger operations.
What does the Claude Code tracker have to do with it?
This is the fight that explains a story we covered from the other side. Through the spring, Claude Code carried hidden code that checked whether a user’s connection, timezone, and hostname matched a concealed list of Chinese AI labs and resellers, and flagged matches steganographically inside the system prompt. We took that mechanism apart in how AI companies hide tracking code. Anthropic’s engineer called it an experiment against “account abuse from unauthorized resellers” and distillation. The timeline now reads differently with the letter in hand: the tracker shipped in April, the Alibaba campaign allegedly ran April 22 to June 5, the letter went to the Senate on June 10, the tracker was discovered on June 30 and removed a day later. Days after that, Alibaba banned Claude Code internally, classified it as high-risk software, and pointed employees at its own tool instead.
Neither side of that exchange looks good, and the two wrongs are different in kind. Hidden fingerprinting of users is a method problem regardless of motive, which is the argument we made in the tracking piece. An extraction operation running through 25,000 fake accounts is a conduct problem regardless of how it was caught. The episode also sits inside a wider squeeze on the same company: a US export-control directive has separately forced Anthropic to pull its Fable 5 and Mythos 5 models from foreign nationals while it negotiates with Washington. Pressure from the government on one side, extraction from competitors on the other.
What should readers of the local AI beat take from this?
One caveat belongs in bold type: these are allegations with numbers attached, not audited findings. The 28.8 million figure is Anthropic’s own count, from its own letter, of activity it attributes to Alibaba-affiliated operators. Alibaba did not respond to CNBC’s request for comment. No court has tested the attribution. We report the numbers as claimed and sourced, which is the same standard we apply when we test tools ourselves and publish only what we can show.
The uncomfortable footnote for our own beat is that the labs named across the two disclosures, DeepSeek, Moonshot, MiniMax, and Alibaba’s Qwen line, sit behind a large share of the open-weight models the local AI world runs every day. This does not make running an open model wrong, and provenance claims about any individual model would need evidence nobody has published. But it does mean the era of treating model weights as origin-free artifacts is ending. Where capability comes from is now a live question with senators attached.
The number to watch next is not in this letter. It is whether the next disclosure, and the pattern of the three so far suggests there will be one, breaks the 28.8 million ceiling. Each cycle has been larger than the last, and the account pool has barely had to grow to get there.
