Claude Distillation Attacks Top 200M
Exchanges, Anthropic Says
Seven China-based AI labs allegedly ran industrial-scale campaigns to copy Claude’s reasoning and coding skills, and Washington just backed up the claim with its own advisory.
Anthropic’s new threat intelligence report accuses seven China-based AI labs of running industrial-scale campaigns to copy Claude’s capabilities, in what the company describes as the largest wave of model distillation it has ever tracked. Published Thursday, the report names Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, MiniMax, and StepFun, and puts the combined activity at nearly 200 million exchanges between December 2025 and August 2026.
The biggest single operation came from accounts linked to Alibaba, which Anthropic calls the largest distillation attack it has ever measured. Between May and July 2026, more than 151 million exchanges flowed through roughly 3,500 fraudulent accounts, all sharing a single fixed prompt designed to extract Claude’s chain-of-thought reasoning — material Anthropic says was funneled into training Alibaba’s Qwen models.
Moonshot AI and DeepSeek allegedly took a quieter approach: routing their own customers’ requests to Claude without telling them, then showing those customers Claude’s answers as if they came from Kimi or DeepSeek’s own models. Over a single 10-day window, Anthropic says Moonshot relayed close to 300,000 customer requests through a network of 5,380 fraudulent accounts. Days later, the FBI, NSA, and CISA issued a joint advisory backing up the pattern, naming six Chinese firms and assessing the activity was likely conducted with awareness from the Chinese government.
How big was this, really?
Nearly 200 million exchanges across seven labs — the largest distillation campaign Anthropic says it has ever tracked.
How did they hide it?
Moonshot and DeepSeek allegedly routed real customer traffic to Claude, then displayed Claude’s answers as their own models’ output.
Why did the FBI get involved?
The FBI, NSA, and CISA issued a joint advisory naming six Chinese firms and citing likely state awareness.
Is this the first accusation?
No — in July 2026, the White House OSTP accused Moonshot of distilling Anthropic’s Fable model to build Kimi K3.
Alibaba: The Largest Campaign Ever Measured
The headlineAnthropic tracked more than 151 million exchanges tied to accounts linked to Alibaba between May and July 2026, peaking at nearly 3 million exchanges in a single day. The traffic came from roughly 3,500 accounts that all shared one fixed prompt built to pull out Claude’s chain-of-thought reasoning — the exact material needed to train a competing model’s step-by-step problem-solving.
Moonshot & DeepSeek: The Proxy Trick
The disguiseRather than scraping Claude directly, Anthropic says Moonshot AI quietly rerouted its own Kimi users’ requests to Claude, then presented Claude’s answers back to those users as if they’d come from Kimi. Over one 10-day stretch, close to 300,000 customer requests were relayed this way through a network of 5,380 fraudulent accounts. DeepSeek is accused of running a similar playbook, generating more than 12.1 million exchanges over 14 days in July.
Zhipu and the Wider Field
The full listAnthropic’s report ties a total of seven labs to distillation activity, including Zhipu (also known as Z.ai), which allegedly ran its own chain-of-thought extraction pipeline generating over 3.4 million exchanges across 17 days. MiniMax, StepFun, and Xiaomi were also named as part of the broader pattern the company disrupted between December 2025 and August 2026.
Washington Steps In
The bigger pictureDays after Anthropic’s report, the FBI, NSA, and CISA issued a joint cybersecurity advisory naming six China-based firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Zhipu — and stating the agencies assess the activity was likely conducted with awareness from the Chinese government. It’s a rare case of a private AI lab’s threat report and a US government advisory landing on nearly the same names within days of each other.
The largest distillation attack
we have ever measured.
⚠️ Why This Isn’t a Simple Good-Guys-vs-Bad-Guys Story
1. These are allegations, not court findings. Anthropic’s report is its own threat intelligence analysis; the named labs haven’t had their side independently tested in a legal proceeding.
2. This is the second major accusation this year. The White House already raised a similar claim against Moonshot in July 2026, so this report builds on an existing dispute rather than starting a new one.
3. Distillation itself isn’t automatically illegal. The dispute is over doing it covertly, at industrial scale, and through fraudulent accounts — not over the underlying technique, which is used legitimately across the industry too.
Every frontier lab is now also
a target for the next one.