TLDRocket
Sign in

Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek

TechCrunch Russell Brandom Covered by 3 sources

Anthropic says Chinese AI firms ran huge distillation campaigns against Claude. The biggest one hit 151 million exchanges, and some requests may have come from the Chinese military.

Based on reporting by TechCrunch, Russell Brandom — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Anthropic says it has spotted a fresh wave of distillation attacks aimed at Claude, and this time the scale is a lot harder to shrug off. In a report released Thursday, the company says the campaigns have grown more aggressive over the last several months as competition in AI has tightened.

The basic trick is simple enough: get a model to spill its chain of thought, then use that material to train a smaller system. Anthropic says its own models usually hide that internal reasoning behind summarized thinking blocks, but attackers found ways around that. One example in the report uses a translation prompt to coax the model into exposing its working memory.

The biggest campaign Anthropic identified was tied to Alibaba. The company says it saw 151 million exchanges between May and July 2026, spread across 3,500 accounts and peaking at nearly 3 million exchanges a day. Anthropic says the repeated fixed prompt and the scale of the activity point to an effort to build training data for Alibaba’s Qwen family of models.

Another campaign was tied to Moonshot AI, the company behind Kimi. Anthropic says some of those requests appeared to be routed directly from the Chinese military, including one asking Claude to review closed-circuit surveillance footage and judge whether a subject was behaving abnormally. Over a ten-day stretch, the company says nearly 300,000 requests flowed through 5,000 accounts, mostly targeting Opus.

All told, Anthropic says it observed nearly 200 million exchanges linked to five separate campaigns. It had already warned about distillation attacks in February, and OpenAI has also reported similar activity, blaming DeepSeek. But Anthropic says the newer campaigns it found are both larger and more aggressive.

My take — AI-written commentary, not fact-checked reporting

This is the part of AI that never gets the glossy demo treatment: everyone wants frontier models, and plenty of people also want the answers without paying for the brain. Anthropic is right to call it out, because “summarized thinking” clearly isn’t the same as sealed thinking, and the industry keeps learning that the hard way. Open models make the copying argument honest; closed models just make the cat-and-mouse game expensive.

Read more about this at: TechCrunch

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.