cd /news/ai-safety/anthropic-disrupts-massive-distillat… · home topics ai-safety article
[ARTICLE · art-127059] src=cryptobriefing.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Anthropic disrupts massive distillation attack from Chinese AI labs targeting Claude

Anthropic's September 2026 threat intelligence report documented five distillation campaigns that generated nearly 190 million exchanges with its Claude model between May and July 2026, with operators linked to Alibaba accounting for over 151 million of them. Moonshot routed more than 300,000 customer requests through Claude in 10 days via roughly 5,000 fraudulent accounts, DeepSeek contributed over 12 million exchanges in a 14-day July 2026 burst, and a fifth campaign involved MiniMax. Anthropic banned accounts at the organizational level, added identity verification in high-risk regions, and limited detail in Claude's reasoning outputs, and has urged Congress to strengthen export controls.

read2 min views1 publishedSep 11, 2026
Anthropic disrupts massive distillation attack from Chinese AI labs targeting Claude
Image: Cryptobriefing (auto-discovered)

Logo via Wikimedia Commons; license to verify on approval

Nearly 190 million exchanges were harvested from Claude by operators linked to Alibaba, DeepSeek, and Moonshot in an escalating AI arms race between the US and China.

Anthropic just revealed that several major Chinese AI labs ran coordinated campaigns to siphon knowledge from Claude, its flagship AI model, using networks of fake accounts and hundreds of millions of carefully crafted queries. The company says it caught and shut down the operations.

The company’s September 2026 threat intelligence report details five distinct distillation campaigns that collectively generated nearly 190 million exchanges with Claude between May and July 2026. The biggest offender, according to Anthropic: operators linked to Alibaba.

What distillation actually means here #

Model distillation is a technique where a smaller or less capable AI model learns by studying the outputs of a more powerful one.

The Alibaba-linked campaign alone accounted for over 151 million exchanges with Claude during the May-to-July window. Operators systematically queried Claude’s reasoning capabilities and harvested the detailed “reasoning traces” that the model produces when working through complex problems. Those traces were then fed back into rival models, including Alibaba’s Qwen series.

Moonshot, the Beijing-based company behind the Kimi AI assistant, routed more than 300,000 customer requests through Claude over just 10 days using approximately 5,000 fraudulent accounts. DeepSeek contributed over 12 million exchanges in a 14-day burst during July 2026.

A fifth campaign involved MiniMax, another Chinese AI startup, though Anthropic’s report provided fewer details on that operation’s scope.

Not just homework copying #

The report flags that some of the queries routed through Claude dealt with sensitive topics related to military applications and surveillance capabilities.

Anthropic has responded with a layered set of countermeasures. The company banned accounts at the organizational level rather than picking off individual fake profiles one by one. It implemented identity verification requirements for users in high-risk regions. And it began limiting the detail provided in Claude’s reasoning outputs, reducing the nutritional value of distillation attempts without degrading the experience for legitimate users.

The geopolitical backdrop #

Anthropic has urged Congress to strengthen export controls specifically in response to threats like these distillation campaigns. The company’s argument is straightforward: if you can’t stop adversaries from accessing the chips to train frontier models, you at least need to prevent them from stealing the outputs of models that were trained on those chips.

The nearly 190 million total distillation exchanges Anthropic documented represent only what it detected and attributed.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-disrupts-m…] indexed:0 read:2min 2026-09-11 ·