Anthropic Reports Large-Scale Distillation Campaigns from Alibaba, Moonshot AI and DeepSeek
Anthropic says it has identified five separate campaigns by China-based AI firms, including Alibaba and Moonshot AI, attempting to extract Claude's capabilities to train their own models. Nearly 200 million related exchanges were recorded in total.

In a report published Thursday, Anthropic warned that China-based companies have been using increasingly sophisticated methods to bypass its safeguards and extract the capabilities of its Claude models. The company says such efforts have intensified in recent months amid growing competition in the AI sector. Targeted capabilities reportedly include Claude's agentic functions, tool use, coding, data analysis, and logical reasoning.
Anthropic first raised concerns about this type of activity in February, when it named specific companies. OpenAI has also previously reported similar behavior, attributing it specifically to DeepSeek. However, the campaigns described in Anthropic's latest report are described as both larger in scale and more aggressive than before. Across all five campaigns, the company recorded close to 200 million related exchanges.
How the extraction works
These so-called distillation attacks generally aim to capture a model's internal chain of thought as it responds to queries. That extracted reasoning can then be used to train a smaller model through supervised fine-tuning, effectively transferring reasoning ability. Anthropic normally withholds Claude's full internal reasoning from users, showing only a summarized version instead. However, attackers found ways to prompt the model into revealing its raw thinking process directly — in one documented case, by disguising the request as a translation task into Japanese.
Largest campaign linked to Alibaba
The bulk of the activity came from a campaign Anthropic attributes to Alibaba, which it describes as the largest wholesale distillation effort it has ever observed. Between May and July, the company recorded 151 million related exchanges, peaking at nearly three million per day. The requests came from 3,500 different accounts, but because they all relied on the same fixed prompt to extract Claude's reasoning, Anthropic attributes them to a single coordinated effort aimed at producing training data for Alibaba's Qwen model family.
A separate campaign, linked to Moonshot AI, maker of the Kimi model, appeared to route some requests directly from the Chinese military, according to Anthropic. One such request asked Claude to review surveillance camera footage and assess whether a subject was behaving abnormally. Over a 10-day period, nearly 300,000 requests were sent to Claude through a network of 5,000 accounts, primarily targeting the company's Opus model.


