3D isometric illustration of a glowing AI brain with data siphoning into copies, representing model distillation attacks
🤖 AI News · Anthropic

Claude Distillation Attacks Top 200M
Exchanges, Anthropic Says

Seven China-based AI labs allegedly ran industrial-scale campaigns to copy Claude’s reasoning and coding skills, and Washington just backed up the claim with its own advisory.

📅 September 2026 ⏱ 7 min read
Nearly 200M exchanges tied to distillation
7 China-based labs named by Anthropic
FBI, NSA, and CISA issued a joint advisory
Alibaba
Largest Campaign Ever
151 M
Moonshot AI
Fraudulent Accounts
5,380
Labs Named
By Anthropic + US Agencies
7

Anthropic’s new threat intelligence report accuses seven China-based AI labs of running industrial-scale campaigns to copy Claude’s capabilities, in what the company describes as the largest wave of model distillation it has ever tracked. Published Thursday, the report names Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, MiniMax, and StepFun, and puts the combined activity at nearly 200 million exchanges between December 2025 and August 2026.

The biggest single operation came from accounts linked to Alibaba, which Anthropic calls the largest distillation attack it has ever measured. Between May and July 2026, more than 151 million exchanges flowed through roughly 3,500 fraudulent accounts, all sharing a single fixed prompt designed to extract Claude’s chain-of-thought reasoning — material Anthropic says was funneled into training Alibaba’s Qwen models.

Moonshot AI and DeepSeek allegedly took a quieter approach: routing their own customers’ requests to Claude without telling them, then showing those customers Claude’s answers as if they came from Kimi or DeepSeek’s own models. Over a single 10-day window, Anthropic says Moonshot relayed close to 300,000 customer requests through a network of 5,380 fraudulent accounts. Days later, the FBI, NSA, and CISA issued a joint advisory backing up the pattern, naming six Chinese firms and assessing the activity was likely conducted with awareness from the Chinese government.

📊 Key Takeaways
Scale

How big was this, really?

Nearly 200 million exchanges across seven labs — the largest distillation campaign Anthropic says it has ever tracked.

Tactic

How did they hide it?

Moonshot and DeepSeek allegedly routed real customer traffic to Claude, then displayed Claude’s answers as their own models’ output.

Government

Why did the FBI get involved?

The FBI, NSA, and CISA issued a joint advisory naming six Chinese firms and citing likely state awareness.

History

Is this the first accusation?

No — in July 2026, the White House OSTP accused Moonshot of distilling Anthropic’s Fable model to build Kimi K3.

Inside Anthropic’s Threat Report
01

Alibaba: The Largest Campaign Ever Measured

The headline

Anthropic tracked more than 151 million exchanges tied to accounts linked to Alibaba between May and July 2026, peaking at nearly 3 million exchanges in a single day. The traffic came from roughly 3,500 accounts that all shared one fixed prompt built to pull out Claude’s chain-of-thought reasoning — the exact material needed to train a competing model’s step-by-step problem-solving.

💡 What it was used for. Anthropic says the harvested transcripts were funneled into training material for Alibaba’s Qwen family of models, alongside broader AI research and development work.
02

Moonshot & DeepSeek: The Proxy Trick

The disguise

Rather than scraping Claude directly, Anthropic says Moonshot AI quietly rerouted its own Kimi users’ requests to Claude, then presented Claude’s answers back to those users as if they’d come from Kimi. Over one 10-day stretch, close to 300,000 customer requests were relayed this way through a network of 5,380 fraudulent accounts. DeepSeek is accused of running a similar playbook, generating more than 12.1 million exchanges over 14 days in July.

💡 Why it’s sneakier. Real paying customers reportedly had no idea their questions were being silently forwarded to a rival’s model.
03

Zhipu and the Wider Field

The full list

Anthropic’s report ties a total of seven labs to distillation activity, including Zhipu (also known as Z.ai), which allegedly ran its own chain-of-thought extraction pipeline generating over 3.4 million exchanges across 17 days. MiniMax, StepFun, and Xiaomi were also named as part of the broader pattern the company disrupted between December 2025 and August 2026.

💡 Not a one-off. Anthropic first raised distillation concerns publicly back in February 2026, when it named specific labs for the first time.
04

Washington Steps In

The bigger picture

Days after Anthropic’s report, the FBI, NSA, and CISA issued a joint cybersecurity advisory naming six China-based firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Zhipu — and stating the agencies assess the activity was likely conducted with awareness from the Chinese government. It’s a rare case of a private AI lab’s threat report and a US government advisory landing on nearly the same names within days of each other.

💡 Not the first friction point. In July 2026, the White House’s Office of Science and Technology Policy had already accused Moonshot of distilling Anthropic’s Fable model to build Kimi K3, prompting the Treasury Department to threaten sanctions.

The largest distillation attack
we have ever measured.

Anthropic · On the Alibaba Campaign

⚠️ Why This Isn’t a Simple Good-Guys-vs-Bad-Guys Story

1. These are allegations, not court findings. Anthropic’s report is its own threat intelligence analysis; the named labs haven’t had their side independently tested in a legal proceeding.

2. This is the second major accusation this year. The White House already raised a similar claim against Moonshot in July 2026, so this report builds on an existing dispute rather than starting a new one.

3. Distillation itself isn’t automatically illegal. The dispute is over doing it covertly, at industrial scale, and through fraudulent accounts — not over the underlying technique, which is used legitimately across the industry too.

Every frontier lab is now also
a target for the next one.

Industry Analysts · On the AI Arms Race
✅ The Bottom Line

The Claude Distillation Report, in Five Numbers

1
~200M exchanges — total distillation activity Anthropic tracked across seven China-based labs
2
151M from Alibaba alone — the largest single distillation campaign Anthropic says it has ever measured
3
5,380 fraudulent accounts — used by Moonshot AI to quietly reroute customer requests to Claude
4
7 labs named — Alibaba, Moonshot, DeepSeek, Zhipu, Xiaomi, MiniMax, and StepFun
5
3 US agencies responded — FBI, NSA, and CISA issued a joint advisory days later
🔗 Full reporting on Anthropic’s threat intelligence findings is available from TechCrunch.
💬 Frequently Asked Questions
Q. What is AI model distillation?
It’s a technique where one lab feeds a more capable model’s outputs into its own training pipeline to copy that model’s abilities at a fraction of the cost of training from scratch.
Q. Which companies did Anthropic name?
Anthropic’s report ties distillation activity to Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, MiniMax, and StepFun — seven China-based AI labs in total.
Q. Has this happened before?
Yes. Anthropic first named specific labs over distillation concerns in February 2026, and in July 2026 the White House separately accused Moonshot of distilling Anthropic’s Fable model to build Kimi K3.
Q. Did the US government respond?
Yes — the FBI, NSA, and CISA issued a joint advisory naming six of the same firms and assessing the activity was likely conducted with awareness from the Chinese government.
Editor’s Note. This article is based on Anthropic’s September 2026 threat intelligence report and reporting from TechCrunch, The Hacker News, and a joint FBI/NSA/CISA cybersecurity advisory.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top