Today's edition — the main read
Anthropic says Qwen's last three models were trained on harvested Claude transcripts
On 10th Sep’26, Anthropic published its September threat report and attributed the largest model-distillation campaign it has ever measured to Alibaba. The account: more than 3,500 fraudulent accounts pulling chain-of-thought output from Claude Opus 4.6 and 4.7, peaking at close to 3 million exchanges a day, and over 151 million exchanges observed between May and July 2026. Anthropic says the harvested transcripts were used to train Qwen 3.5, 3.6 and 3.7. This is Anthropic's attribution, not a finding of fact; Alibaba has not confirmed it, and the report sits alongside six other categories of misuse Anthropic says it disrupted, from cyber operations to biological research.
What it actually means
Qwen is not a fringe model, it is the community's base layer If Anthropic's account holds, part of that price-performance ratio was never an engineering achievement. Someone paid to build the expensive reasoning; someone else copied the answers.
That matters to you whether or not you care who was right. The cheap-model economics a lot of roadmaps are quietly built on assume the gap keeps closing for free. It doesn't close for free, it closes because there's a pipeline at the top of it, and that pipeline is now being actively policed, litigated and shut. Price the possibility that the cheap tier gets slower to catch up from here, because the shortcut is being closed.
The second thing worth sitting with: Anthropic detected it by profiling API traffic well enough to group 3,500 accounts into one actor and infer intent from usage shape. Your API calls are not a black box to the vendor. If you run high-volume, repetitive, output-harvesting workloads; evaluation suites, synthetic data generation, bulk classification against a frontier model - you now know that pattern is visible, attributable, and has a name in somebody's threat taxonomy.