Anthropic published a threat intelligence report on Thursday accusing several China-based AI labs of running sustained, industrial-scale campaigns to copy the reasoning abilities of its Claude models. The company says it counted close to 200 million exchanges tied to five distinct operations, and it named Alibaba, Moonshot AI and DeepSeek as the parties behind the largest of them. A summary of the findings was first reported by TechCrunch.
Key takeaways
- Anthropic attributes roughly 200 million Claude exchanges to five separate unauthorized distillation campaigns run between December 2025 and August 2026.
- The Alibaba operation alone accounted for more than 151 million exchanges from over 3,500 fraudulent accounts, peaking near three million exchanges a day.
- Moonshot AI and DeepSeek allegedly forwarded live customer traffic from their own products to Claude without telling users, then kept the responses as training data.
What an illicit distillation campaign actually looks like
Distillation is a standard technique: a smaller student model learns from a larger teacher model's outputs and inherits much of its behavior at a fraction of the serving cost. What Anthropic describes is the unauthorized version of that process, aimed specifically at the step-by-step reasoning traces that make frontier models good at agentic work.
Anthropic does not normally expose raw chain-of-thought output to users, showing condensed "summarized thinking" blocks instead. According to the report, the campaigns found prompt patterns that coaxed the model into emitting its working memory verbatim. One attacker reframed the request as a translation job, instructing Claude to render its previous working memory into katakana-only Japanese. Harvested traces can then be fed into supervised fine-tuning for a competing model.
The report says the targets were Claude's most commercially valuable capabilities: tool use and agentic behavior, coding and data analysis, and logical reasoning.
Why the Alibaba campaign is the biggest one measured
Anthropic logged more than 151 million exchanges attributed to Alibaba between May and July 2026, traffic that at its peak approached three million exchanges per day. The volume was spread across more than 3,500 accounts the company classifies as fraudulent, but all of them leaned on a single fixed extraction prompt, which is what let Anthropic tie them to one coordinated effort to generate training material for the Qwen model family. The report adds that the same operators used Claude for broader research work, including reinforcement learning and model architecture questions.
Routing paying customers through a rival's model
The Moonshot AI allegation is different in kind. Anthropic says Moonshot quietly relayed some requests meant for its Kimi products to Claude, showed users Claude's answers as though they came from Kimi, and retained the exchanges to train its own systems. In one ten-day window that amounted to nearly 300,000 relayed customer requests, routed through 5,380 accounts based mostly in Singapore and Japan and aimed overwhelmingly at Claude Opus. More than 23 million exchanges were attributed to Moonshot across May to July.
Anthropic reports a similar pattern at DeepSeek, with more than 12 million distillation attacks observed over 14 days in July 2026. CNBC reported that some of the relayed traffic carried sensitive material from individual users, multinational companies and state-affiliated actors, which the report argues is likely inconsistent with privacy law as well as the labs' own terms of service.
What changes for the industry
This is not Anthropic's first public complaint. The company called out specific labs in February, and OpenAI has made comparable claims about DeepSeek. What is new is the scale and the specificity, alongside a claim that the relaying tactic touched real end users who had no idea which model was answering them. The distillation section sits inside a wider misuse report covering seven categories, from cyber operations to surveillance and fraud.
None of the named companies responded to press requests for comment. For Anthropic, the practical question is enforcement: account bans are cheap to route around, and the economics plainly favor the copier. That tension runs through the company's other recent security disclosures, including its decision to release a withheld model to defenders.
FAQ
What is model distillation?
Distillation trains a smaller model on the outputs of a larger one, so the smaller model reproduces much of the teacher's behavior far more cheaply. It is routine when a lab distills its own models. It becomes a dispute when one company harvests a competitor's outputs at scale without permission.
Which companies did Anthropic name?
The report names Alibaba, Moonshot AI and DeepSeek as being behind the largest campaigns, and references several other Chinese AI firms. Anthropic attributes about 200 million exchanges in total to five separate distillation operations.
Did Anthropic say user data was exposed?
Anthropic says some of the relayed exchanges contained sensitive information, including material from individual users, large multinational companies and state-affiliated actors. It says it does not know whether Moonshot told its customers that their requests were being sent to a third-party model.






