Illicit model distillation · GTG-16005
Report's allegations about Alibaba-related distillation activity: GTG-16005 case
This page is a Chinese-to-English translation of content from pages 147–148 of Anthropic's September 2026 report. Actor attribution and scale figures come from the report's unilateral allegations; this site has not independently verified them. The GTG number is Anthropic's internal tracking identifier, not a judicial case number; a platform rules finding does not equal a judicial conclusion.
According to Anthropic's September 2026 report, an operator linked to Alibaba is alleged to have launched the largest distillation attack the report has measured, targeting the chain-of-thought reasoning records of Claude Opus 4.6 and 4.7. The report says the data was used to train the Qwen series of models. All attribution and figures come from the report's unilateral allegations; the companies involved have not confirmed them on this site.
What happened
An operator linked to Alibaba ran the largest distillation attack we have measured. This illicit distillation activity targeted the chain-of-thought (CoT) reasoning records of Opus 4.6 and 4.7.
Alibaba's CoT distillation pipeline injected a fixed prompt into each request, forcing Claude to write its reasoning trace within inline text tags before providing the final answer. These CoT records were then saved and converted into data usable for supervised fine-tuning (SFT). These SFT records were used to help train Alibaba's Qwen models and were used to distill Claude's capabilities into Qwen 3.5, 3.6, and 3.7.
Alibaba's illicit distillation activity peaked at nearly 3 million interactions per day from more than 3,500 fraudulent accounts. The distillation attack targeted agent tasks, software engineering, kernel development, and long-cycle tasks. The collected records were used to improve the reasoning capabilities of Alibaba's models.
In addition to distillation, Alibaba also used Claude to advance its AI R&D work. Alibaba used Claude to help develop the internal infrastructure for its model development. Claude was used to help develop Alibaba's reinforcement learning (RL) environment and advance model architecture research.
Alibaba accessed Claude through two main pools of fraudulent accounts. The first pool consisted of nearly 5,000 fraudulent accounts, using residential proxies, disposable email addresses, and virtual card payments to mask its access. When we banned this account pool, Alibaba quickly shifted its traffic to a second pool. Some of these accounts were found to simultaneously forward requests from DeepSeek and Xiaomi, indicating that the same proxy service network is often used by various organizations.
The scale of the distillation attack attributed to Alibaba between May and July 2026: more than 151 million interactions observed.
What AI did in this case
In this allegation, Claude played two roles: first, as the object of extraction — its reasoning records were collected at scale to be used as training material for another model; second, as an R&D assistant — the report says Claude was used to help build the internal infrastructure for model development.
The report says the distillation attack targeted Claude's capabilities in agent tasks, software engineering, kernel development, and long-cycle tasks.
What the report observed
The report says Alibaba accessed Claude through two main pools of fraudulent accounts: the first pool contained nearly 5,000 accounts, which the report says used residential proxies, disposable email addresses, and virtual card payments to mask the source of access; when Anthropic banned the first pool, traffic quickly shifted to the second pool.
The report also says some of these accounts were found to simultaneously forward requests from DeepSeek and Xiaomi, from which the report concludes that the same proxy service network is often shared by multiple organizations. Between May and July 2026, the report attributes more than 151 million interactions to Alibaba's distillation attack.
Confirmed & unknown
Confirmed
- The report says the activity targeted Opus 4.6 and 4.7 chain-of-thought reasoning records (per the report)
- The report says more than 151 million interactions were attributed to Alibaba between May and July 2026
- The report says after the first account pool was banned, traffic shifted to a second account pool
- The report says some accounts simultaneously forwarded requests from DeepSeek and Xiaomi
Unknown
- What proportion of the extracted reasoning records actually entered the final training of the Qwen models, the report does not give
- The report does not provide independently verifiable measurements of the resulting capability improvements of the relevant models
- The report does not state Alibaba's response to these allegations
- The full start and end times of the activity outside the observation window are not given
Platform response
Anthropic says it has banned the relevant accounts and deployed measures to detect and disrupt future abuse.
Limits of response:Banning accounts cannot recover the reasoning records already extracted; the report does not state whether the relevant models have already completed training using these records.
Takeaways
- Chain-of-thought reasoning records are a model's core asset; large-scale extraction can be used to train competing models.
- Fraudulent account pools and proxy networks are common infrastructure for large-scale distillation attacks.
- The same proxy service network may be shared by multiple organizations, indicating a mature illicit access supply chain.