[{"data":1,"prerenderedAt":28},["ShallowReactive",2],{"nr-en-alibaba-anthropic-claude-prompt-siphoning":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":10,"trackerLabel":10,"headlineStat":22,"image":23,"ogImage":24,"imageAlt":5,"csv":10,"minutes":25,"words":26,"html":27},"alibaba-anthropic-claude-prompt-siphoning","Alibaba allegedly stole millions of prompts from Anthropic's Claude","US AI firm Anthropic accuses Chinese conglomerate of extracting knowledge via 25,000 fraudulent accounts. Anthropic calls on Congress to act.","2026-08-03","10:17","2026-08-03T10:17:00+02:00","","August 3, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"AI Security","Geopolitics","Data Theft","Anthropic","China","28.8 million prompts extracted in three months","\u002Fnewsroom\u002Fimg\u002Falibaba-anthropic-claude-prompt-siphoning.webp","\u002Fog-nr\u002Falibaba-anthropic-claude-prompt-siphoning.en.png",2,397,"\u003Cp>Anthropic has gone public with a major data theft by Chinese conglomerate Alibaba. According to a Forbes report, Alibaba allegedly used 25,000 fraudulent accounts to conduct 28.8 million prompt-response exchanges over three months—extracting an estimated 57.6 billion tokens from Claude. The goal: to harvest Anthropic&#39;s knowledge for training its own language model, particularly in advanced areas like agentic reasoning.\u003C\u002Fp>\n\u003Ch2>The essentials\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Alibaba\u003C\u002Fstrong> allegedly accessed Claude via \u003Cstrong>25,000 fake accounts\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>28.8 million\u003C\u002Fstrong> prompt-answer pairs extracted in \u003Cstrong>three months\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Estimated data volume: \u003Cstrong>57.6 billion tokens\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Anthropic has called on \u003Cstrong>Congress\u003C\u002Fstrong> for countermeasures and information sharing\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>The technique: Distillation as a weapon\u003C\u002Fh2>\n\u003Cp>The attack exploits a method called \u003Cstrong>distillation\u003C\u002Fstrong>—a technique originally designed for legitimate purposes. Normally, AI makers use distillation to transfer knowledge from large models to smaller ones, like a teacher-student relationship. Alibaba appears to have weaponized this approach: instead of legitimate use, Claude was systematically &quot;squeezed&quot; to extract advanced capabilities and integrate them into its own model.\u003C\u002Fp>\n\u003Ch2>Disguised as normal usage\u003C\u002Fh2>\n\u003Cp>The insidious part: the operation was designed to look normal. The 25,000 accounts mimicked genuine user behavior to avoid detection. Over three months, millions of prompts were submitted—an industrial-scale data heist only possible through automated systems. Anthropic discovered the pattern and reported it.\u003C\u002Fp>\n\u003Ch2>What Anthropic demands from Congress\u003C\u002Fh2>\n\u003Cp>In a letter to Congress, Anthropic calls for concrete measures:\u003C\u002Fp>\n\u003Cdiv class=\"tbl-scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Demand\u003C\u002Fth>\n\u003Cth>Purpose\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Information sharing between agencies\u003C\u002Ftd>\n\u003Ctd>Early detection of similar attacks\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Penalties for industrial siphoning operations\u003C\u002Ftd>\n\u003Ctd>Deterring foreign actors\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Access pattern monitoring\u003C\u002Ftd>\n\u003Ctd>Prevention of mass extraction\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>The company warns this won&#39;t be the last such attack—a signal to the US government that AI competition increasingly involves security concerns.\u003C\u002Fp>\n\u003Ch2>What this means for German companies\u003C\u002Fh2>\n\u003Cp>The Anthropic breach is a wake-up call for every German AI provider and company running proprietary models. If even a well-guarded US firm can be exploited through millions of prompts, German companies aren&#39;t automatically safer—likely the opposite, given fewer resources for security monitoring. The question becomes: how do you detect systematic model extraction? What technical and organizational safeguards do you need? At the same time, the case shows that terms of service alone aren&#39;t enough—you need active anomaly detection and possibly regulatory support.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.forbes.com\u002Fsites\u002Flanceeliot\u002F2026\u002F08\u002F03\u002Fchinese-ai-firm-siphoned-american-ai-knowledge-from-claude-by-using-millions-of-prompts-and-trained-on-the-responses\u002F\">Forbes\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1785758986392]