Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
TechCrunch Russell Brandom ● Covered by 3 sources
Anthropic says Chinese AI firms ran huge distillation campaigns against Claude. The biggest one hit 151 million exchanges, and some requests may have come from the Chinese military.
Based on reporting by TechCrunch, Russell Brandom — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Anthropic says it has spotted a fresh wave of distillation attacks aimed at Claude, and this time the scale is a lot harder to shrug off. In a report released Thursday, the company says the campaigns have grown more aggressive over the last several months as competition in AI has tightened.
The basic trick is simple enough: get a model to spill its chain of thought, then use that material to train a smaller system. Anthropic says its own models usually hide that internal reasoning behind summarized thinking blocks, but attackers found ways around that. One example in the report uses a translation prompt to coax the model into exposing its working memory.
The biggest campaign Anthropic identified was tied to Alibaba. The company says it saw 151 million exchanges between May and July 2026, spread across 3,500 accounts and peaking at nearly 3 million exchanges a day. Anthropic says the repeated fixed prompt and the scale of the activity point to an effort to build training data for Alibaba’s Qwen family of models.
Another campaign was tied to Moonshot AI, the company behind Kimi. Anthropic says some of those requests appeared to be routed directly from the Chinese military, including one asking Claude to review closed-circuit surveillance footage and judge whether a subject was behaving abnormally. Over a ten-day stretch, the company says nearly 300,000 requests flowed through 5,000 accounts, mostly targeting Opus.
All told, Anthropic says it observed nearly 200 million exchanges linked to five separate campaigns. It had already warned about distillation attacks in February, and OpenAI has also reported similar activity, blaming DeepSeek. But Anthropic says the newer campaigns it found are both larger and more aggressive.
My take — AI-written commentary, not fact-checked reporting
This is the part of AI that never gets the glossy demo treatment: everyone wants frontier models, and plenty of people also want the answers without paying for the brain. Anthropic is right to call it out, because “summarized thinking” clearly isn’t the same as sealed thinking, and the industry keeps learning that the hard way. Open models make the copying argument honest; closed models just make the cat-and-mouse game expensive.
Read more about this at: TechCrunch
Related stories
China closes AI gap with distillation attack
morningbrew.com · 2 months ago ·
28
OpenAI and Anthropic warn Washington about Chinese distillation of U.S. AI models
New York Post · 1 month ago ·
15
Anthropic alleges Alibaba used 25,000 fraudulent accounts to extract Claude data
The Neuron · 1 month ago ·
3