🤚 The Open-Palm Illumination
Ladies and gentlemen of the intelligence economy, we regret to inform you that Alibaba has been accused of operating nearly 25,000 fake accounts to systematically extract capabilities from Anthropic’s Claude AI models, generating 28.8 million exchanges over a six-week campaign that ran from April 22 to June 5, 2026. The technique is called adversarial distillation — a polite academic term for “training your model on someone else’s homework at industrial scale.”
Anthropic disclosed the operation in a formal letter dated June 10, 2026, addressed to U.S. Senate Banking Committee Chair Tim Scott and Ranking Member Elizabeth Warren — a bipartisan audience that suggests the safety lab wanted both sides of the aisle to understand that this is not a competitive nuisance but a national security event. The targeted capabilities were specifically software engineering and agentic reasoning from Claude’s Mythos Preview model — the crown jewels, not the gift shop merchandise.
👐 The Two-Handed Reality Check
To appreciate the scale here, one must recall that in February 2026, Anthropic disclosed three separate distillation campaigns by Chinese AI labs — DeepSeek, Moonshot AI, and MiniMax — which collectively involved roughly 24,000 fraudulent accounts and 16 million exchanges. Alibaba’s single operation exceeded the combined total of all three prior campaigns. One company outperformed a consortium. That is either deeply impressive or deeply concerning, and the answer is obviously both.
The method is elegantly parasitic: you create thousands of accounts, feed Claude carefully crafted prompts designed to elicit its most sophisticated reasoning patterns, collect the outputs, and use them to train your own model. You are not stealing code. You are not breaching a server. You are having 28.8 million conversations and taking very detailed notes. It is the AI equivalent of hiring 25,000 people to sit in a competitor’s master class and transcribe every word — except the people are bots and the master class never noticed it had a standing-room-only problem.
Anthropic has warned that models built through this approach “often lack safety guardrails, posing broader security and safety risks beyond intellectual property theft.” In other words: they copied the intelligence but not the conscience. A familiar story in most industries, but one with considerably higher stakes when the product can write exploit code.
Senators Bill Hagerty (R-TN) and Andy Kim (D-NJ) are now advancing an amendment to defense legislation that would blacklist or sanction any Chinese firm found improperly accessing U.S. AI model outputs. The legislative machinery has been activated. Whether it moves faster than the next distillation campaign is a question best left to prediction markets — which, incidentally, AI is now better at than humans.
🌿 The Gentle Awakening
This episode lands in a week where the U.S. government has already demonstrated a new willingness to intervene directly in frontier AI. The Trump administration ordered Anthropic to restrict non-U.S. personnel access to its newest models, Fable 5 and Mythos 5, with 90 minutes’ notice. OpenAI’s GPT-5.6 lineup — Sol, Terra, and Luna — was limited to a “small group of trusted partners” after the White House’s Office of the National Cyber Director flagged the model’s advanced cybersecurity capabilities. And now we learn that while American regulators were building a gate, a Chinese tech conglomerate was already inside the house, having 28.8 million conversations with the family silver.
Meanwhile, Sam Altman has suggested that OpenAI may be less than six months away from recursive self-improvement — AI that can meaningfully enhance its own development — and that this milestone could delay the company’s IPO because some work is “easier while being a private company.” Translation: when your product might start improving itself at a pace that quarterly earnings calls cannot accommodate, you prefer an audience that doesn’t ask questions every 90 days.
The irony is architectural. The same models that are too powerful for unrestricted public access are also too valuable to leave unprotected from adversarial distillation. You cannot simultaneously be the most capable AI system on Earth and also be accessible via a web form that accepts 25,000 fraudulent email addresses. Something has to give.
👑 The Crown Verdict
We are witnessing the birth of a new category of geopolitical conflict: intelligence extraction warfare. Not espionage in the traditional sense — no one broke into a server room or turned a scientist. They simply talked to the model. A lot. And wrote everything down. The weapon was patience, the ammunition was API credits, and the target was the accumulated R&D investment of a company that spent billions training a model only to discover that its outputs are the product and the product can be photocopied at conversational speed.
The frontier AI companies now face a trilemma that would make a business school case study weep: make your model accessible enough to generate revenue, restricted enough to prevent distillation, and powerful enough to justify the valuation. Pick two. Maybe one and a half. The $965 billion IPO Anthropic filed depends on Claude being both the best model in the world and somehow not worth copying — a contradiction that 28.8 million exchanges have now resolved in the most expensive way possible.
The age of open model access was brief, expensive, and apparently, very well-documented by the competition.
Inspired by US Government Blocks GPT-5.6, Alibaba’s AI Theft, and Why OpenAI Is Stalling Their IPO | #267 by Peter H. Diamandis.
Your distillation is showing. Authenticate wisely.