Fetching from the wire…
Top 5 · 2026-06-25 · source-backed
25,000 fake accounts. 28.8 million Claude conversations. Six weeks. And the thing they were harvesting wasn't trivia, it was software engineering and agentic reasoning.
In a June 24 letter to US senators and the White House, Anthropic alleged that operators tied to Alibaba's Qwen lab ran roughly 25,000 fraudulent accounts to conduct 28.8 million Claude interactions between April 22 and June 5, specifically to extract software-engineering and agentic-reasoning capability (CNBC). This is the first time Anthropic has put a major Chinese conglomerate's name in writing. The campaign on its own exceeds the combined ~16 million exchanges the company previously attributed to DeepSeek, MiniMax, and Moonshot put together. It lands while US export controls already restrict Chinese access to Anthropic's Mythos and Fable 5 models.
Here's what makes this different from the usual "everyone distills everyone" shrug. Distillation used to mean scraping clever answers to look smart on benchmarks. What 28.8 million targeted agentic-coding sessions buys you is the behavioral data to clone how a frontier model plans, calls tools, recovers from errors, and chains steps over a long horizon. That's not the knowledge layer. That's the orchestration layer. And orchestration is exactly the thing I keep saying is the real moat now that writing code is cheap.
The economics are brutal for the labs. If you can reconstruct most of a frontier model's agentic behavior for the cost of API calls routed through stolen accounts, the moat isn't the weights, it's enforcement. Anthropic going to senators instead of just banning accounts tells you they've concluded they can't win this on the platform alone. They want it to be a trade-policy problem.
What should you do about it? Two things. First, if you ship anything where your prompts, tool schemas, or agent scaffolding are the value, assume they're harvestable through normal usage and design accordingly. Rate limits and account verification are now product security, not ops hygiene. Second, watch the next story, because the flip side of "labs can't stop distillation" is that the distilled models are getting really good, really cheap, and they're already in your router.
Each link below shares sources, entities, or timing with this story.
Moonshot AI released Kimi K3, a sparse mixture-of-experts activating 16 of 896 experts per token. That's about 1.8% of the pool live at any moment, with a 1M-token context window and native vision. Two new architectural pieces show up: Kimi Delta Attention and Attention Residu...
A researcher found that Claude Code, since v2.1.91 back in April, had been silently embedding invisible Unicode steganographic markers in its system prompts. The technique: tweaking date and apostrophe characters, XOR-obfuscated with key 91, to flag requests routed through thi...
Martin Alderson's essay "The upcoming AI margin collapse, part 1: GLM 5.2" hit 675 points and 462 comments on Hacker News, and it's the rare HN chart-topper that's actually about spreadsheet math instead of vibes. The argument is simple. Z.ai's GLM 5.2 delivers frontier-adjace...
Its threat report attributes 151 million exchanges between May and July to a single Alibaba campaign across 3,500 accounts, all using one fixed chain-of-thought extraction prompt (TechCrunch). It counts more than 12 million DeepSeek exchanges over 14 days. It also says Moonsho...
Anthropic identified 24,000+ fraudulent accounts generating 16M+ exchanges with Claude from DeepSeek, Moonshot AI, and MiniMax. The agent-specific targeting is key: Moonshot (3.4M exchanges) targeted agentic reasoning and tool use; MiniMax (13M) targeted agentic coding; DeepSe...
Anthropic identified industrial-scale capability theft: 24K fake accounts generating 16M+ exchanges from DeepSeek, Moonshot, and MiniMax. MiniMax pivoted to new models within 24 hours of each Claude release — suggesting automated distillation pipelines. ---
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.