Connect with us

AI

Alibaba’s Claude Harvest Outran the Mythos Freeze

Anthropic’s June letter put Alibaba at 28.8 million Claude exchanges. Its September report raised that tally to 151 million.

Published

on

Anthropic told U.S. senators on June 10 that operators tied to Alibaba and its Qwen lab ran more than 28.8 million exchanges with Claude through almost 25,000 fraudulent accounts. The company said the campaign ran from April 22 to June 5 and went after agentic reasoning, software engineering, and long-horizon tasks.

On September 10, Anthropic published a threat report that attributed over 151 million Claude exchanges to Alibaba between May and July, peaking at nearly 3 million a day. The models Washington froze two days after the letter, Mythos 5 and Fable 5, were not the ones in that pipeline.

Anthropic Took Alibaba to the Banking Committee

Sarah Heck, Anthropic’s head of policy, sent the June 10 letter to Sen. Tim Scott and Sen. Elizabeth Warren, chair and ranking member of the Senate Banking Committee, ahead of a June 11 hearing titled “AI and the American Dream.” It was the first time the company had put a distillation file in front of that committee, and the first time it had named a firm of Alibaba’s size rather than a specialist lab.

Claude is not sold commercially in China, or to subsidiaries of PRC-headquartered companies. Heck wrote that the operators still reached it, in violation of Anthropic’s terms of service and access rules, and that the traffic followed patterns the company had already laid out in February against DeepSeek, Moonshot, and MiniMax.

Beyond its scale, this campaign was striking for its brazen nature. Alibaba is listed on the New York Stock Exchange, maintains business operations in the United States, and is accountable to US investors and regulators.

Sarah Heck, Head of Policy, Anthropic, June 10 letter to the Senate Banking Committee

She asked Congress to make it easier for U.S. labs to share threat data, including by clarifying antitrust rules, to close loopholes that let PRC labs reach advanced U.S. chips and overseas data centers, and to penalize labs that run industrial-scale extraction. The letter also said the work unfolded in the weeks after the White House OSTP NSTM-4 memo, which had already called PRC distillation campaigns unacceptable.

151 Million Queries Landed After That Letter

The June filing treated April 22 to June 5 as a closed window. The September report did not. Tracked as GTG 16005, the Alibaba case is the largest distillation attack Anthropic says it has measured, and it kept counting through July, after senators had already been told the campaign was over.

THE THREE DISCLOSURES, SIDE BY SIDE

Disclosure Window Who Anthropic named Exchanges Accounts
February 23 blog Not dated as a single window DeepSeek, Moonshot, MiniMax Over 16 million combined About 24,000
June 10 Senate letter April 22 to June 5 Alibaba / Qwen More than 28.8 million Almost 25,000
September 10 threat report May to July Alibaba / Qwen Over 151 million More than 3,500 on the peak run

Those account columns are not the same census. The letter counted almost 25,000 fraudulent accounts across six weeks in spring. The later report counted more than 3,500 accounts on the May-to-July run it tied to a single fixed prompt, plus a first pool of nearly 5,000 that used residential proxies, disposable emails, and virtual-card payments. Anthropic says that when it banned the first pool, traffic moved to a second one.

February’s three-lab file still matters as a baseline. DeepSeek was logged at over 150,000 exchanges, Moonshot at over 3.4 million, and MiniMax at over 13 million, together 16 million exchanges through 24,000 accounts. The June Alibaba letter already exceeded that combined total on its own. The September Alibaba tally is larger still, and it sits on a different clock.

Anthropic posted the September report from its official account the day it went up.

A Fixed Prompt Forced Claude to Show Its Work

Distillation, in the ordinary lab sense, is how a company shrinks its own teacher model into a cheaper student. Anthropic’s complaint is the covert version: industrial-scale querying of someone else’s system, through fake accounts, to copy capabilities without paying to train them. The September write-up says Alibaba’s pipeline did not need Mythos-class weights. It needed Claude to write its reasoning down.

The campaign targeted chain-of-thought transcripts from Opus 4.6 and 4.7. A fixed prompt injected into each request forced the model to put those traces inside inline text tags before the final answer. The transcripts were saved, converted into supervised fine-tuning data, and, Anthropic says, used to distill Claude’s behavior into Qwen 3.5, 3.6, and 3.7. The same report says Claude was also used on Alibaba’s own research stack, including reinforcement-learning environments and model-architecture work.

WHAT THE QWEN PIPELINE DID

  • The prompt: A single fixed instruction made Claude spell out its reasoning traces in tagged text before answering.
  • The tasks: Traffic concentrated on agentic work, software engineering, kernel development, and long-horizon jobs rather than casual chat.
  • The peak: Nearly 3 million exchanges in a day, from more than 3,500 fraudulent accounts.
  • The product: Those traces, Anthropic says, went into Qwen 3.5, 3.6, and 3.7 as supervised fine-tuning data.

That is a different picture from a smash-and-grab on model weights. No chip shipment has to clear a port. The student model learns from answers the teacher was paid, or tricked, into giving. Cheap Qwen inference can keep shipping in public while that training question sits unanswered, which is why token prices will sort this faster than a caption on a Senate letter.

Why Mythos and Fable Went Offline

India-facing coverage in late June treated the Alibaba letter as the reason Mythos 5 and Fable 5 vanished. Anthropic’s own June 12 notice points somewhere else. The U.S. government, citing national security authorities, issued an export-control directive at 5:21 p.m. Eastern to suspend all access to those two models by any foreign national, including Anthropic’s own non-citizen staff. Because the company could not check nationality in real time, it took both models down for every customer. Access to all other Anthropic models, the notice said, would not be affected.

The concern described in that notice was a method of bypassing, or jailbreaking, Fable 5, demonstrated on a small set of already known, minor software flaws. Anthropic said it had reviewed the technique, that other public models could find the same flaws, and that it had not been shown a universal jailbreak. It called the recall a misunderstanding and said it was working to restore access.

THE TWO WEEKS THE FLAGSHIP MODELS WERE DARK

  1. June 8, 2026: The Pentagon adds Alibaba to its Section 1260H list of Chinese military companies.
  2. June 10, 2026: Heck’s letter reaches the Banking Committee with the 28.8 million-exchange Alibaba file.
  3. June 12, 2026: The government orders a foreign-national cutoff on Fable 5 and Mythos 5; Anthropic disables both for all users.
  4. June 23, 2026: Alibaba sues the Defense Department in the Northern District of California over the 1260H label.
  5. June 30, 2026: The Commerce Department lifts the export controls; Anthropic says it will start restoring access the next day.
  6. July 1, 2026: Fable 5 restoration begins, after the Fable 5 public launch with Mythos guardrails had already made that model the widely sold face of the same underlying system.

Mythos 5 came back first for approved U.S. organizations, then under new conditions on restored Mythos 5 access. The September report is blunt about what that freeze did not touch. Anthropic says it has not observed distillation attempts against Mythos 5 or Mythos Preview, which are not sold to the general public. The one Fable exception in the report is Zhipu, which tried to copy Fable’s cyber skills, ran into the extra safeguards, and switched to Opus 4.6 and to another U.S. lab’s top model because those guards were weaker.

So the models that left the market from June 12 to June 30 were not the models in the Alibaba count. Opus-class systems stayed up. The harvest Anthropic later put at 151 million exchanges between May and July ran on that remaining surface.

Alibaba Is Fighting a Separate Pentagon Label

The letter leaned on a second Washington track that is easy to mash into the same headline. On June 8 the Pentagon listed Alibaba as a Chinese military company under Section 1260H, a roster that also took in Baidu, BYD, and other large commercial names. Direct Pentagon purchasing from listed firms was set to stop on June 30. Alibaba said there was “no basis” for the designation and that it is “not a Chinese military company nor part of any military-civil fusion strategy.”

On June 23 it filed a federal complaint seeking removal in San Jose, arguing the label had no basis in fact or law and that the department had misread its ties to Chinese regulators. Heck’s letter cited that listing as evidence that Alibaba’s AI work sits inside a military-civil story. The complaint is a procurement and reputation fight. It does not answer the Claude-account file.

WHAT WE KNOW

  • The letter: Anthropic attributed the spring campaign to operators affiliated with Alibaba and Alibaba Qwen and put the count at more than 28.8 million exchanges.
  • The later report: The same company attributed over 151 million May-to-July exchanges to Alibaba and said the traces fed Qwen 3.5, 3.6, and 3.7.
  • The freeze: Mythos 5 and Fable 5 were pulled over a Fable jailbreak finding, then restored after Commerce lifted the controls on June 30.

WHAT IS UNCONFIRMED

  • Alibaba’s reply: The company has not issued a public answer to the distillation attribution, including the Qwen training claim.
  • Independent audit: No outside party has published a replica of Anthropic’s account-to-lab mapping.
  • The 1260H case: The Pentagon listing and Alibaba’s lawsuit are still a live fight, separate from Claude access logs.

Mixing those tracks makes the Senate letter look like a switch that turned two models off. The documents do not line up that way. One is a terms-of-service and national-security brief about API traffic. The other is a defense-list designation Alibaba is trying to wipe in court.

The Chat Window the Chip Ban Never Covered

Heck told the committee that distillation turns American training spend into a subsidy for rivals, because the student lab skips the frontier run and still ships a nearer-term model. Dario Amodei, Anthropic’s chief executive, made the same point in a July 27 note on open-weights policy, while arguing against a blanket ban on open models.

Distillation is a much more compute-efficient process than training models from scratch. It allows China to build much better models than its number of chips would ordinarily enable, and thus partially evade chip bans. Distillation does not allow the CCP to obtain equivalent or superior AI capabilities to the US, but it can bring the Chinese frontier to within a few months of the US frontier.

Dario Amodei, CEO, Anthropic, July 27 note on open-weights models

That is the hole export control was not built to close. A ban on advanced chips tries to starve a training cluster. A freeze on Mythos-class weights tries to keep the most restricted systems off foreign laptops. Neither rule stops a hydra of proxy accounts from hitting a generally available chat and coding API. Anthropic already does not sell Claude in China. The September report says unauthorized labs still arrive through “transfer stations” that mint false identities, fake or stolen cards, and stolen API keys, then mix distillation traffic with ordinary customer requests so a single ban does not kill the cluster.

Amodei’s own footnote on that July note is the operational limit. Accounts often become visible only after a lot of distillation has already happened, and the fake-account set is a moving target. One company’s bans cannot finish the job, which is why the June letter asked for penalties and for permission for rival U.S. labs to compare notes.

Proxy Farms Recycled Fake Accounts Across Labs

The Alibaba file is the largest line in the September report, not the only one. Anthropic says that since February it has disrupted additional distillation attacks from seven China-based labs, all aimed at generally available models. Moonshot, which builds the Kimi models, was logged at over 23 million exchanges between May and July. In one ten-day slice it relayed almost 300,000 customer requests to Anthropic, mostly to Opus, through 5,380 fraudulent accounts that looked as if they sat in Singapore and Japan. Users thought they were talking to Kimi. Some of those prompts, Anthropic says, included surveillance video from Chengdu that it assessed as likely PLA-affiliated.

DeepSeek was logged at over 12.1 million exchanges across 14 days in July and, like Moonshot, silently relayed some of its own customers onto Claude, including traffic that had started in Claude Code and other coding harnesses. Zhipu, branded overseas as Z.ai, was put at over 3.4 million exchanges over 17 days, including 770,609 passes through a chain-of-thought “cleaner.” Xiaomi was put at over 400,000 exchanges across 20 days in March and April. MiniMax, Anthropic says, ran a shell proxy that sold access only to Anthropic and OpenAI models, not to MiniMax’s own.

Some of the second-pool accounts in the Alibaba case were also found funneling requests for DeepSeek and Xiaomi, which is how a circumvention market starts to look like shared plumbing rather than seven separate heists. The privacy sting in that plumbing runs the other way too. People who thought they were talking to Kimi or DeepSeek had prompts land at Anthropic, including live credentials and internal documents, without a notice from the app they opened. Replies under Anthropic’s September post went straight at that point, and at the older complaint that U.S. labs already trained on the public web. The company’s own definition tries to draw a line at industrial covert copying through fraud. The product those labs sell still has to live with the cheaper student sitting next to it.

Anthropic says it banned the attributed accounts, built classifiers for adversarial extraction, and tightened those classifiers around the Fable 5 launch. Alibaba has not publicly answered the distillation file. The Qwen versions named in the September report are already in the market.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending