
Anthropic's June 10 letter to Congress details 28.8 million prompts run through 25,000 accounts. It seeks penalties for foreign extraction of American AI models.
Alpha Score of 46 reflects weak overall profile with poor momentum, strong value, weak quality, weak sentiment.
Anthropic told Congress that Alibaba ran a three-month distillation attack on its Claude chatbot, a technique in which a rival model is trained on another lab's prompts and responses. The operation used 25,000 fraudulent accounts to pull 28.8 million prompt-response exchanges, about 57.6 billion tokens, which Anthropic said went to train Alibaba's own model.
The letter, dated June 10, says the extraction ran from April through June and targeted agentic reasoning, the ability of AI agents to plan and execute multi-step work, and software engineering. Anthropic described those as areas that involve complex knowledge, harder to source from public data than general text. Anthropic called the campaign industrial-scale siphoning of its intellectual property and asked Congress to act.
Anthropic's disclosure describes the standard shape of such attacks: automated scripts create accounts by the thousand and run them from servers spread across different countries, keeping each account's usage light enough to stay inside the range of normal traffic. The counts fit that template: 28.8 million exchanges over the April-to-June window, roughly 90 days, works out to about 1,150 exchanges per account, 12 or 13 a day.
Anthropic said the accounts were designed to mimic ordinary user behavior. They were hiding inside a massive user base. OpenAI has said ChatGPT has about 1 billion weekly active users. The major chatbots each hold hundreds of millions of accounts, the disclosure notes, and new signups arrive constantly across all of them, which makes a batch of 25,000 look unremarkable.
At a high-end estimate of 2,000 tokens per exchange, tokens being roughly words or word fragments, the extracted output totals about 57.6 billion tokens, the equivalent of roughly 576,000 books at 100,000 tokens each. Measured against the 10 to 15 trillion tokens used to train a major model from scratch, the haul is between 0.4 percent and 0.6 percent of a full training run. Forbes' account of the letter cautions that the raw comparison understates the loss, because distilled output is refined capability rather than raw crawl text.
Forbes' account notes mundane knowledge would not be worth the risk of running an operation this large. The value sits in output that is hard to find elsewhere, which is why the letter highlights agentic reasoning and software engineering. Those capabilities are not reconstructable from public web data alone; the behavior they require is expensive to produce. On Anthropic's telling, the extraction was aimed at that hard-to-reproduce layer.
Anthropic's letter is not the first time the issue has reached Washington. Earlier this year the White House Office of Science and Technology Policy published "Adversarial Distillation of American AI Models," a memorandum by policy director Michael J. Kratsios. It proposed information sharing among US AI labs on extraction campaigns and federal coordination on best practices for detecting and responding to them. Congress has been watching Chinese attempts to repurpose American AI models, according to reporting that accompanied the disclosure.
The letter adds a penalty regime to the memorandum's proposals and names Alibaba as the operator of the 25,000 accounts. Forbes' account compares the campaigns to Cold War espionage; bot swarms now play the role human spies once played. The economics make the practice attractive: renting server capacity and running bot accounts costs a fraction of generating equivalent training data from scratch, and the entire campaign fit inside three months.
For any lab that runs a public chatbot, the exposure is the same. A model with an API or a consumer tier can be probed this way, because extraction looks like routine queries until patterns are matched across millions of accounts. No single exchange is obviously abusive; the theft becomes visible only when the volume and the destination model are seen together. Anthropic's argument to Congress is that tightening account controls within one lab does not surface a campaign spread across the industry. The letter's answer is information sharing. The disclosure warns that foreign actors keep maneuvering across a wide swath of models as individual labs patch their defenses.
The commercial exposure runs through Alibaba Group, the listed company behind the AI work Anthropic named in the letter. Alibaba Group carries an Alpha Score of 55 out of 100 on AlphaScala's scale, a Mixed label.
The letter is dated June 10. Anthropic asked Congress to build the information-sharing mechanism the White House memorandum had proposed and to add penalties for foreign entities that run extraction campaigns at industrial scale.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.