Alibaba’s 151M Claude Exchanges: The AI Moat Problem
Alibaba allegedly made more than 151 million Claude exchanges in three months. If frontier AI can be harvested through the front door, the model is not the moat.
Alibaba allegedly made more than 151 million exchanges with Claude between May and July 2026. If a frontier model’s best capabilities can be harvested through its front door, its moat is thinner than the AI industry wants investors to believe.
That is not a clever growth hack. It is a warning that the AI industry’s favourite asset — the expensive frontier model — may be a lot less defensible than investors have been pretending.
On September 10, Anthropic alleged that operators affiliated with Alibaba used more than 3,500 fraudulent accounts, peaking at nearly three million exchanges a day, to harvest reasoning traces from Claude and improve Alibaba’s Qwen models. Anthropic also alleged similar campaigns involving Moonshot AI, DeepSeek, Xiaomi and Zhipu. These are allegations, not court findings, and the named companies have not had their case tested in public. But the scale described is too big for founders and investors to shrug off as AI-industry drama. ([anthropic.com](https://www.anthropic.com/threat-intelligence-report-september-2026?utm_source=openai))
The core story: the model may be the product, but it is not the moat
Here is the uncomfortable bit: billions of dollars can buy you a frontier model, but millions of API calls may help a competitor imitate the valuable bits without paying the full bill.
Anthropic’s report says Alibaba’s alleged campaign targeted chain-of-thought reasoning from Opus 4.6 and 4.7, as well as agentic tasks, software engineering, kernel development and long-horizon work. In plain English, those are not party tricks. They are the capabilities businesses pay real money for: coding, analysis, automation and getting a machine to complete a job rather than merely answer a question. ([anthropic.com](https://www.anthropic.com/threat-intelligence-report-september-2026?utm_source=openai))
Anthropic alleged that the campaign used a fixed prompt designed to force Claude to expose reasoning inside text tags, then turned those outputs into supervised fine-tuning data for Qwen 3.5, 3.6 and 3.7. The company said the operation shifted account pools when it blocked one set, using residential proxies, disposable email addresses and virtual-card payments to disguise access. ([anthropic.com](https://www.anthropic.com/threat-intelligence-report-september-2026?utm_source=openai))
That is the headline number: 151 million exchanges. But the more commercially nasty detail is what it says about the cost curve. A rival does not necessarily need to recreate every data centre, hire every researcher or run every failed training experiment if it can observe enough high-quality answers from the finished product.
You can argue about the legal label — theft, misuse, distillation, aggressive reverse engineering — but don’t miss the business point. When the output of your product can be systematically collected, classified and used to teach a cheaper competitor, your gross margin is not protected simply because your technology is clever.
Why this is bigger than Alibaba and Anthropic
The US government has put its name behind the broader concern. On September 8, the FBI, NSA and CISA issued a joint advisory saying China-based AI companies had conducted industrial-scale distillation campaigns against US frontier models since at least late 2024. The advisory named DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.ai, and said the activity was likely undertaken with Chinese government awareness. ([dejavu.org](https://www.dejavu.org/cgi-bin/get.cgi?url=https%3A%2F%2Fwww.cisa.gov%2F%2Fnews-events%2Fcybersecurity-advisories%2Faa26-251a&ver=93&utm_source=openai))
That does not prove every claim in Anthropic’s report. Government agencies and companies can both have incentives to frame a strategic competition in the hardest possible terms. Good operators should keep that caveat in their head.
Still, the overlap matters. Anthropic’s report describes alleged campaigns in specific operational detail; the US security agencies describe a wider pattern; and this is not Anthropic’s first disclosure. In February, it said it had identified industrial-scale campaigns by DeepSeek, Moonshot and MiniMax using fraudulent accounts and proxy services to extract Claude capabilities. ([anthropic.com](https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks?via=free&utm_source=openai))
The AI arms race has therefore acquired a second race inside it. The visible contest is for better chips, larger data centres, more researchers and bigger funding rounds. The less glamorous contest is for access control: who can query whom, how often, from where, through which reseller, and whether model outputs can be quietly repurposed into training data.
That is a cybersecurity problem, an intellectual-property problem and a product-design problem rolled into one expensive headache.
The overlooked angle: customer data is the real grenade
Everyone will talk about whether Claude’s reasoning was copied. Fair enough. But the uglier issue for operators is customer trust.
Anthropic alleged that Moonshot rerouted some customer requests to Claude while users believed they were interacting with Kimi. It also alleged that DeepSeek selectively relayed requests from users employing third-party coding harnesses to Claude. According to Anthropic, the traffic it observed included sensitive corporate material, live credentials, surveillance data and internal documents. Anthropic says it does not know whether affected customers were told their requests had been routed to a third party. ([anthropic.com](https://www.anthropic.com/threat-intelligence-report-september-2026?utm_source=openai))
If you run a company, that should land harder than the geopolitical theatre.
Most businesses are still treating AI procurement like buying a slightly smarter software subscription. They compare price, benchmark scores and whether the chatbot writes decent emails. Meanwhile, their staff are pasting in product roadmaps, customer complaints, source code, sales plans, financial models and occasionally the digital keys to the bloody kingdom.
Your AI vendor’s model quality matters. Its routing, data handling, logging, sub-processors and account-security controls matter more.
This is especially true for smaller firms. Big companies can afford lawyers, dedicated security teams and procurement theatre. A 30-person business often has a founder approving an AI tool because someone on the team said it was “basically like ChatGPT but cheaper.” That is not a vendor assessment. That is how you accidentally turn private information into someone else’s training material.
The contrarian view: this will not kill AI margins — it will kill lazy AI companies
The easy conclusion is that models are commodities and nobody can make money. I don’t buy it.
Raw model capability will become less exclusive over time. That much looks obvious. But a useful business is never just the raw intelligence sitting behind an API. The durable value sits in distribution, proprietary workflow data, integrations, trust, customer support, brand and the habit a product builds inside a team.
Think about it this way: plenty of people can buy cloud infrastructure. Very few can build a product that becomes embedded in how thousands of businesses make decisions every morning.
The companies most exposed are the ones charging premium prices for a thin wrapper around a public or easily substitutable model. If your whole pitch is “our AI writes better than theirs,” you are one model release away from trouble and one extraction campaign away from embarrassment.
The winners will be the firms that turn AI into a locked-in operating system for a specific job. Not a chatbot. A system that knows the workflow, connects to the relevant systems, has permissioning and audit trails, produces measurable outcomes, and becomes painful to remove.
That is also why frontier labs will need to become much better at the boring stuff. Anthropic says it is using layered defences, including detection based on metadata and irregular activity, adversarial-extraction classifiers, identity checks and safeguards intended to make internal reasoning less useful to harvest. Good. But it is telling that the model itself is now part of the attack surface. ([anthropic.com](https://www.anthropic.com/threat-intelligence-report-september-2026?utm_source=openai))
What this means for you
If you are a founder, stop asking whether you “have an AI strategy.” That phrase should be thrown into the ocean. Ask four more useful questions instead.
First: what valuable data leaves our business when staff use AI? Make a simple list: code, customer records, financial data, legal documents, pricing, supplier terms and internal strategy. Then decide which categories are prohibited, which require approved tools and which can be used freely.
Second: can we explain where an AI vendor sends our prompts? Get a written answer. Ask about model-routing partners, retention periods, training use, human review, geographic processing and breach notification. If the vendor cannot answer cleanly, do not hand it your crown jewels because its demo looked sexy.
Third: are we building a real moat or renting somebody else’s? If your product can be replicated by switching model providers and adding a nicer landing page, you do not have a moat. Build proprietary workflow data, integrations and customer outcomes that improve with use.
Fourth: can we measure value in dollars or hours? Do not pay for AI because it makes people feel modern. Track time saved, sales conversion, error reduction, response speed, retention or margin. Kill the tools that cannot earn their keep.
The 151 million figure matters because it tells you where this market is heading. AI intelligence will be attacked, copied, bundled and sold cheaper. Your advantage will not come from worshipping the model. It will come from owning the customer relationship, protecting the data and using the technology to run a sharper business than the bloke next door.
Sources
- Anthropic: Countering misuse of AI — September 2026
- TechCrunch: Anthropic details distillation campaigns from Alibaba, Moonshot AI and DeepSeek
- CISA: China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
- AP: China hits back at U.S. claims of malicious AI distillation