Anthropic exposes large-scale Chinese distillation campaigns targeting Claude
Anthropic has disclosed five separate campaigns, largely traced to Chinese AI firms, that harvested nearly 200 million exchanges to extract Claude's capabilities. The largest, linked to Alibaba, dwarfs prior efforts, while another tied to Moonshot AI reportedly routed requests from China's military.

Anthropic released a report on Thursday detailing persistent and increasingly sophisticated distillation attacks carried out by China-based AI companies. According to the report, unauthorized labs have in recent months developed new methods to bypass Anthropic's safeguards and extract valuable capabilities from its Claude models, including agentic functions, tool use, coding, data analysis, and logical reasoning.
Anthropic first raised concerns about distillation attacks in February, when it named specific labs. OpenAI has separately reported similar activity, attributing it to DeepSeek. However, the campaigns described in Anthropic's latest report are described as both larger in scale and more aggressive than previously documented. In total, the company identified nearly 200 million exchanges connected to distillation efforts, spread across five distinct campaigns.
How the attacks work
Distillation attacks aim to extract a model's chain-of-thought reasoning, which can then be used to train smaller models through supervised fine-tuning. Anthropic normally withholds Claude's full internal reasoning from users, showing only a summarized version instead. Attackers, however, found techniques to trick the model into revealing its raw thinking traces — in one instance by disguising the request as a translation task, asking Claude to render its "previous working memory" into Japanese.
Alibaba and Moonshot AI campaigns
The largest share of exchanges came from a campaign Anthropic attributes to Alibaba, which the company describes as the biggest wholesale distillation operation it has ever observed. Between May and July 2026, Anthropic recorded 151 million exchanges tied to the effort, peaking at nearly three million per day. The activity was spread across 3,500 accounts, but a shared fixed prompt used to extract reasoning traces allowed Anthropic to link them all to a single operation aimed at generating training data for Alibaba's Qwen model family.
A separate campaign attributed to Moonshot AI, maker of the Kimi model, appeared to channel requests directly from China's military. One such request asked Claude to review surveillance camera footage and determine whether a subject was "behaving abnormally." Over a 10-day span, Anthropic says nearly 300,000 requests reached Claude through a network of 5,000 accounts, primarily targeting its Opus model.

