Anthropic says Alibaba ran the largest known distillation attack on its models, training their own systems on Claude's outputs without authorization.
The problem with closed models is that thereโs no verifiable trail showing which outputs ended up in downstream training. Onchain provenance is the fix because it can create receipts for what a model was actually built on. Without that, model theft stays almost impossible to prove cleanly.