Anthropic Ties Alibaba to 151 Million Claude Queries in Bitcoin (BTC) Security Alert
Anthropic says Alibaba-linked accounts ran over 151 million Claude queries across 3,500 accounts. Moonshot rerouted 300,000 user requests. Security risk for…
AI SummaryAI
- Anthropic says Alibaba-linked accounts ran over 151 million interactions with Claude between May and July 2026.
- The Alibaba traffic spanned roughly 3,500 accounts, peaking near 3 million transactions in a single day.
- Moonshot AI rerouted about 300,000 user requests to Claude through 5,380 fake accounts over 10 days.
- The report names Alibaba, Moonshot AI, DeepSeek, Z.AI, Xiaomi, SenseTime and MiniMax in distillation operations.
Alibaba's 151 Million Claude Queries
Anthropic said Thursday that accounts tied to Alibaba exchanged more than 151 million interactions with its Claude models between May and July 2026, describing the activity as the largest unauthorized effort it has ever documented to replicate a leading American AI system. The allegation anchors the company's September 2026 threat-intelligence report, which covers activity the firm says it disrupted between December 2025 and August 2026, and which it publicized in an official post on its X account. The Alibaba-linked traffic was distributed across roughly 3,500 accounts and peaked at close to 3 million transactions in a single day — thousands of accounts designed to look like unconnected individual users. What connected them, per the report, was one identical static prompt used to pull inference from Claude, which Anthropic treated as a single coordinated program to generate training data for Alibaba's Qwen model family. The technique at issue, known as model distillation, is the rapid capture of a model's outputs and chain-of-thought reasoning — often through bulk queries, fake accounts and stolen credentials — to teach a smaller, cheaper rival, effectively creating a fork of the target model's capabilities without consent. The new document casts a shadow over earlier disclosures: in June, the company said Alibaba had used 25,000 fake accounts across 28.8 million interactions from April 22 to June 5, and in a June 10 letter to the US Senate Banking Committee it flagged Claude's reasoning, coding and multi-step capabilities as the campaign's targets. After the claims surfaced, Alibaba's US-listed shares dropped roughly 2.7% to a 52-week low.
an official post on its X accounthttps://x.com/AnthropicAI/status/2098097512544444447?s=20
Moonshot Routed 300,000 User Requests
A separate campaign attributed to Moonshot AI, the maker of the Kimi models, silently rerouted close to 300,000 customer requests to Claude through 5,380 fraudulent accounts over a 10-day window — most of them directed at Anthropic's Opus model — rather than serving those users with Kimi. One affected user, likely tied to the Chinese military, was using the service to review surveillance-camera footage and determine whether a subject was behaving abnormally. Moonshot had launched its Kimi K3 app in July amid heavy demand. The new report names Alibaba, Moonshot AI, DeepSeek, Z.AI, Xiaomi, SenseTime and MiniMax in distillation operations, bringing the total to seven Chinese laboratories. In February, Anthropic accused DeepSeek, Moonshot and MiniMax of creating more than 24,000 fake accounts and sending over 16 million messages to Claude; OpenAI has leveled similar claims at DeepSeek. Anthropic identified Claude Haiku, Sonnet and Opus as the targeted models, and said its own Fable and Mythos models avoided every misuse case in the report except a single distillation attempt. On the offensive side, a group matching the profile of the Russia-linked Midnight Blizzard used AI across the full attack lifecycle — spear-phishing against Ukrainian military and diplomatic targets and hijacking of hotel Wi-Fi networks — including mechanisms that automatically checked whether its malware had been flagged by defenses and rewrote code in real time to slip past detection. Threat actors also attempted to use Claude to build control software for physical weapons, spanning firearms, missiles and armed drones. In July, a Chinese foreign ministry spokesperson responded to the earlier accusations, saying the country's AI progress stems from self-reliance and charging Washington with politicizing trade and technology issues. Readers tracking the market in real time can follow live spot and futures prices on Gate.
What It Means for Bitcoin Infrastructure
Read together, the two threads trace a single arc: frontier AI has become both the loot and the weapon. The primary document states the scale plainly — 151 million exchanges across 3,500 accounts in two months — and the same automated intrusion tradecraft documented against Ukrainian institutions applies directly to digital-asset infrastructure, from DeFi protocols to market maker desks running latency-sensitive bots and the operational-security teams guarding exchange and whale wallets. With Bitcoin (BTC) trading near $77,000 as of this writing, COINOTAG's view is that AI-enabled attack tooling is now a headline risk for custodians, and the security budgets of major trading venues will be judged against reports like Anthropic's going forward.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


