Anthropic has released a detailed report revealing that several China-based AI organizations, including Alibaba, Moonshot AI, and DeepSeek, have been conducting extensive distillation attacks on its AI models. The company notes that these unauthorized efforts to extract and replicate the advanced reasoning and tool-use capabilities of its Claude models have significantly increased in recent months amid growing competition in the artificial intelligence sector. Distillation attacks aim to capture the chain of thought behind model responses, enabling the training of smaller models with enhanced reasoning abilities through supervised fine-tuning.
The largest and most prominent campaign was linked to Alibaba, involving 151 million interactions from May to July 2026, with activity peaking at nearly three million exchanges per day. Anthropic attributed these to efforts to develop training data for Alibaba’s Qwen series of models, identifying that a single fixed prompt was used across thousands of accounts to harvest the underlying reasoning processes of Claude. Anthropic described this initiative as the most massive wholesale distillation effort it has ever observed, raising concerns about the unauthorized leveraging of its technology.
Moonshot AI’s campaign, reportedly connected to the Chinese military, targeted Anthropic’s Opus model. Over a brief 10-day window, approximately 300,000 requests were funneled through thousands of accounts, including one asking Claude to analyze surveillance footage for abnormal behavior. This indicates a potential intersection between commercial AI development and military intelligence gathering, highlighting the strategic value placed on AI capabilities in China’s state ecosystem.
Anthropic’s report emphasizes the sophistication of these distillation campaigns, which have found inventive methods to bypass defenses—such as tricking the model into revealing its intricate “chain of thought” by framing queries as translation tasks. This mirrors similar claims made by OpenAI, which previously linked such attacks to DeepSeek. As AI companies race to protect their proprietary technology, the increased scale and aggression of these extraction attempts underline the intensifying global contest for leadership in artificial intelligence innovation.
Start the discussion with a take, question, or market read.