Anthropic just named seven Chinese AI labs for stealing Claude's reasoning. I read the full report and the Qwen part doesn't hold up the way the headline does.
The article critiques Anthropic's report accusing seven Chinese AI labs of illicitly distilling Claude's reasoning, highlighting weak evidence for Alibaba's Qwen and suggesting political framing in the accusations.
Anthropic published a 154 page threat intelligence report in September naming seven Chinese labs for what they call illicit distillation, and the internet is already treating all seven as guilty. I read the whole thing, plus the earlier one from February, and I want to say plainly where the evidence is real and where it just is not. The campaign itself is real. Over 150 million exchanges pulled from Claude over three months, peaking around three million a day, running through thousands of fake accounts built on residential proxies and disposable emails. They describe the injection technique in detail, a fixed prompt that forced Claude to write out its reasoning traces before answering, and they show example prompts from these campaigns. That part is in the API logs, timestamped and measurable. Nobody should argue it didn't happen. It did. But here's the thing. The report says, in one sentence, that operators affiliated with Alibaba ran this campaign, and that the stolen reasoning traces were used to help train Qwen 3.5, 3.6, and 3.7. That's the whole attribution. One sentence. No named researcher. No IP range. No email domain. Nothing that lets you actually check the work. And this matters because in the earlier February report they do show the work on the metadata side, saying they traced accounts to specific researchers and matched metadata to public profiles of senior staff. And in the September report, the DeepSeek and Moonshot cases stand on something even harder to fake, the relay itself. For Qwen, it's operators affiliated with Alibaba and move on. Same publisher, different standard, and nobody seems to have noticed. And the claim that the stolen data actually went into Qwen's models is just a story they tell. No training data inspection. No ablation. Nothing. The logic is basically we saw reasoning data being stolen and Qwen shipped better reasoning models so the stolen data must have trained them. But everyone shipped better reasoning models in that window. OpenAI, Google, xAI, Mistral, Meta. Qwen getting better at reasoning is what the whole industry was doing. That's not a fingerprint, that's the trend. Now look at why the DeepSeek and Moonshot cases are actually strong. The report says both labs were silently relaying their own customers' traffic to Claude instead of their own models. People thought they were talking to Kimi or DeepSeek and were getting Claude, and the labs saved those conversations for training. That happens inside the lab's own serving stack. You can't fake it. And the leaked user content, things like a PLA engineer analyzing CCTV footage and internal code from a state owned enterprise, identifies the actual users as employees of those companies. Qwen has none of that. It's fake accounts, a pattern, and one attribution sentence. And I think we should be honest about who's doing the accusing here. Anthropic is a US frontier lab. The report is built around the word illicit, which is a choice, because distillation is a completely normal training technique that every lab uses on their own models. And the whole thing is framed around export controls. The February report literally says that without this kind of disclosure, Chinese labs' progress gets misread as proof that export controls don't work, when really the advancements depend in significant part on capabilities extracted from American models. That is a political argument wearing a threat report costume. Naming seven Chinese companies to the world serves a very specific narrative, and Anthropic gets to be the responsible one in it. So what actually happened here is that Anthropic observed the traffic, made the attribution call themselves, kept the underlying metadata private, which I get, security reasons, and then named a company publicly in a document that's explicitly tied to national security framing. Some labs haven't responded, but silence isn't an admission. And the public has no way to verify any of it. If they really had a metadata match to named Qwen researchers, they could have redacted the names and shown the chain. They didn't. They showed the crime and asserted the criminal. I'm not saying Qwen is in the clear. I'm not. I'm saying this is a huge claim, basically that one of the largest AI companies in the world stole reasoning from a US competitor, and the public evidence for it is one sentence and a timing coincidence. I need to see actual evidence before I accept that. And the way the headline got written, Anthropic names seven Chinese labs, makes all seven sound equally proven when the report itself treats them completely differently. The strongest case in the document is also the only one where the lab is caught with its own customers' data in hand. If Anthropic wants the export control argument to hold up, the attributions need to hold up too. Right now, for Qwen, what's in the public record is a claim.
Anthropic alleged that Alibaba's Qwen lab used nearly 25,000 fake accounts to run 29 million Claude model exchanges, surpassing all prior distillation campaigns, prompting U.S. senators to consider legislation sanctioning Chinese firms for unauthorized access to AI model outputs.
Anthropic has accused Alibaba of illicitly extracting capabilities from its Claude AI model, highlighting ongoing tensions over intellectual property in the AI industry.
Anthropic's report details extensive misuse of Claude by foreign spies, hackers, and AI companies for espionage, fraud, and unethical model training, accusing organizations like Alibaba and DeepSeek of stealing and laundering responses.
Anthropic accuses Alibaba of a campaign to illicitly extract its AI capabilities through model distillation, highlighting ongoing tensions in AI intellectual property.