Anthropic Says Chinese AI Labs Ran Massive Claude Distillation Campaigns

Anthropic says Alibaba, Moonshot AI, and DeepSeek ran large distillation campaigns to copy Claude's reasoning and coding abilities.

maisiekooc
Maisie Morrison

AgentLocker Editor

AI News
Anthropic Says Chinese AI Labs Ran Massive Claude Distillation Campaigns

Anthropic released a new report on Thursday, September 10, 2026. The report accuses several China-based AI companies of running distillation attacks against its Claude models. The company says these attacks have grown more aggressive in recent months.

According to Anthropic, unauthorized labs used increasingly advanced methods to get around its defenses. The report states these labs tried to copy Claude's agentic skills, coding ability, and reasoning power.

This is not the first time Anthropic has raised this issue. The company made similar claims back in February, when it named specific labs.

OpenAI has also reported this kind of activity. That company pointed to DeepSeek as the source of similar attempts.

Anthropic says the new campaigns are larger than anything it has tracked before. The company recorded close to 200 million exchanges connected to five separate campaigns.

How Distillation Attacks Work

Distillation attacks focus on pulling out a model's chain of thought. Attackers collect these reasoning steps from the responses Claude gives to different questions.

The collected data can then be used to train a smaller model. Companies do this through a process called supervised fine-tuning.

Anthropic normally does not show users the model's full internal thinking. Instead, it shows a "summarized thinking" block that gives a general overview of the reasoning.

Anthropic says some attackers found ways to trick Claude into revealing its full thinking. In one case, an attacker asked Claude to act as a translator.

The request asked Claude to translate its "previous working memory" into Japanese katakana. This approach let the attacker pull out the raw reasoning text instead of the summary.

The Alibaba and Moonshot AI Campaigns

The largest campaign came from a group linked to Alibaba. Anthropic called it the largest wholesale distillation effort the company has ever tracked.

The company recorded 151 million exchanges tied to this campaign between May and July 2026. At its peak, the activity reached almost three million exchanges in a single day.

The requests came from about 3,500 different accounts. Anthropic linked them together because they all used the same fixed prompt, and it says the effort was tied to training material for Alibaba's Qwen model family.

A separate campaign was linked to Moonshot AI, maker of the Kimi model. Anthropic says some of these requests appeared to be routed from the Chinese military.

One request asked Claude to review surveillance footage from a security camera. It asked whether the person in the footage was "behaving abnormally."

Over a ten-day period, Anthropic recorded almost 300,000 requests tied to this campaign. They came through a network of about 5,000 accounts and mostly targeted Anthropic's Opus model.

Anthropic published the full findings in its report on September 10, 2026. The company said it continues to track new attempts to copy its models' capabilities.

From our research desk
AI Jobs Automation Index
Which jobs are AI tools targeting most? We mapped 3,400+ AI tools to real job functions — with BLS employment & salary data.
Explore the index
maisiekooc

Written by

Maisie is a news writer at Agent Locker, covering the latest developments in artificial intelligence, emerging technology and the companies shaping the future.

Discover AI Agents