Anthropic has revealed that three China-based AI labs—Alibaba, Moonshot AI, and DeepSeek—have conducted massive “distillation” operations aimed at extracting capabilities from its Claude models without authorization. The disclosure details how dozens of millions of exchanges were used to harvest Claude’s reasoning, tool use, coding, and logical analysis in order to build competitive models. These campaigns represent some of the most aggressive and large-scale distillation efforts yet documented.
What are distillation attacks and how they work
Distillation, in this context, refers to repeatedly querying a more powerful AI model (like Claude) to gather responses, especially internal reasoning or “chain of thought” traces, then using those outputs to train a smaller model. While model distillation is a standard research technique when done with permission, Anthropic identifies it in these cases as illicit and adversarial—conducted via fraudulent accounts and proxy servers to bypass access restrictions. These attacks target the most valuable differentiators of its models: advanced reasoning, tool integration, multi-step logic, and coding abilities.
Scale, actors and tactics
The Alibaba campaign stands out as the largest: between May and July 2026, roughly 151 million exchanges were recorded over thousands of accounts, peaking at nearly 3 million exchanges per day. Anthropic attributes this effort to operators affiliated with Alibaba’s Qwen lab, using a consistent prompt structure to extract Claude’s internal thinking for training. This campaign likely dwarfs previous ones in both volume and scope.
The Moonshot AI campaign—makers of the Kimi model—also showed signs of sophisticated and state-linked operations. One example given was a request to analyze whether a subject in surveillance footage was “behaving abnormally,” routed through thousands of accounts over a short period. Moonshot allegedly focused on Claude’s capabilities in coding, agentic reasoning, tool-use, and data analysis.
Earlier in 2026, Anthropic had already exposed distillation efforts by DeepSeek and MiniMax, along with Moonshot, which collectively involved over 16 million exchanges via some 24,000 fraudulent accounts. DeepSeek’s campaign totaled only around 150,000 exchanges, but it was designed specifically to extract reasoning and grading-type tasks, censorship-safe alternatives, and chain-of-thought outputs. MiniMax engaged in agentic coding and orchestrated tool use, while Moonshot’s previous campaign aimed at multiple advanced capabilities. These earlier operations set the stage for the even bigger Alibaba campaign.
Implications & Anthropic’s response
Anthropic treats these campaigns as serious violations of its terms of service and regional use restrictions. In its public statements and a letter to the U.S. Senate Banking Committee, the company argues they represent intellectual property theft on an industrial scale. It also sees them as a way for foreign labs—particularly in China—to leapfrog research and save costs by taking advantage of U.S. frontier models without investing in comparable R&D.
To counter these attacks, Anthropic says it is investing in new defensive measures, including infrastructure to detect suspicious usage patterns, fraud-account detection, behavior fingerprinting, and classifiers designed to flag when user queries are structured in ways consistent with distillation. The company notes that distillation attacks can also undermine export-control policies and are difficult to police if access to model outputs is broadly available.
These distillation campaigns align with warnings issued by U.S. agencies (FBI, NSA, CISA) that Chinese AI labs have been using proxy networks, fraudulent accounts, and bulk queries to extract capabilities from Claude, GPT, Gemini, and Grok since at least late 2024. The scale and sophistication of the techniques—including masking traffic, coordinating bursts of queries, and framing requests under plausible usage categories—underscore both the technological and geopolitical stakes.
What this means is a shift in how frontier AI labs need to think about IP security. As distillation attacks scale, controlling access alone isn’t enough: the structure of queries, user metadata, and prompt patterns must also factor into defense. For downstream users, this trend suggests that reliance on a single closed API could carry hidden risks—of output copying, model imitation, or even regulatory backlash.
Ultimately, the Anthropic disclosures mark a turning point. They illuminate a broader strategy among foreign AI actors to shortcut their way to frontier capabilities by repurposing output from powerful models rather than building them from scratch. It’s a challenge not only for Anthropic but for all major AI labs—and it forces renewed consideration of policy, export controls, and technical safeguards. What to watch: whether affected labs respond publicly, how regulators act, and whether defensive tools to detect distillation at scale become a standard part of model deployment.