Anthropic disrupts massive distillation attack from Chinese AI labs targeting Claude

1 hour ago 24

Anthropic just revealed that several major Chinese AI labs ran coordinated campaigns to siphon knowledge from Claude, its flagship AI model, using networks of fake accounts and hundreds of millions of carefully crafted queries. The company says it caught and shut down the operations.

The company’s September 2026 threat intelligence report details five distinct distillation campaigns that collectively generated nearly 190 million exchanges with Claude between May and July 2026. The biggest offender, according to Anthropic: operators linked to Alibaba.

What distillation actually means here

Model distillation is a technique where a smaller or less capable AI model learns by studying the outputs of a more powerful one.

The Alibaba-linked campaign alone accounted for over 151 million exchanges with Claude during the May-to-July window. Operators systematically queried Claude’s reasoning capabilities and harvested the detailed “reasoning traces” that the model produces when working through complex problems. Those traces were then fed back into rival models, including Alibaba’s Qwen series.

Moonshot, the Beijing-based company behind the Kimi AI assistant, routed more than 300,000 customer requests through Claude over just 10 days using approximately 5,000 fraudulent accounts. DeepSeek contributed over 12 million exchanges in a 14-day burst during July 2026.

A fifth campaign involved MiniMax, another Chinese AI startup, though Anthropic’s report provided fewer details on that operation’s scope.

Not just homework copying

The report flags that some of the queries routed through Claude dealt with sensitive topics related to military applications and surveillance capabilities.

Anthropic has responded with a layered set of countermeasures. The company banned accounts at the organizational level rather than picking off individual fake profiles one by one. It implemented identity verification requirements for users in high-risk regions. And it began limiting the detail provided in Claude’s reasoning outputs, reducing the nutritional value of distillation attempts without degrading the experience for legitimate users.

The geopolitical backdrop

Anthropic has urged Congress to strengthen export controls specifically in response to threats like these distillation campaigns. The company’s argument is straightforward: if you can’t stop adversaries from accessing the chips to train frontier models, you at least need to prevent them from stealing the outputs of models that were trained on those chips.

The nearly 190 million total distillation exchanges Anthropic documented represent only what it detected and attributed.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article