Anthropic reports five large-scale distillation campaigns against Claude, tied to Alibaba, Moonshot AI (Kimi) and DeepSeek
Anthropic published a report detailing five distillation campaigns against Claude over recent months, totaling nearly 200 million exchanges. The largest, attributed to Alibaba (for its Qwen models), involved 151 million exchanges from ~3,500 accounts between May-July 2026, peaking at ~3 million exchanges/day, using a shared fixed prompt to extract chain-of-thought reasoning. A second campaign attributed to Moonshot AI (maker of Kimi) routed ~300,000 requests over 10 days through 5,000 accounts targeting Claude Opus, including a request Anthropic says came from the Chinese military asking Claude to assess CCTV footage for "abnormal" behavior. Attackers used jailbreak techniques (e.g., framing extraction requests as translation tasks) to bypass Claude's summarized-thinking safeguards and obtain raw chain-of-thought data for training smaller models via supervised fine-tuning.
Entities: Anthropic, Claude, Alibaba, Qwen, Moonshot AI, Kimi
0 primary
What happened
Anthropic published a report describing five distillation campaigns against Claude over recent months, totalling nearly 200 million exchanges. The largest, which Anthropic attributes to Alibaba (for training Qwen), involved 151 million exchanges from roughly 3,500 accounts between May and July 2026, peaking at around 3 million exchanges a day, using a shared prompt designed to extract Claude's chain-of-thought reasoning. A second campaign, attributed to Moonshot AI, routed about 300,000 requests through 5,000 accounts over 10 days targeting Claude Opus, including one request Anthropic says came from the Chinese military asking Claude to assess CCTV footage. Attackers reportedly used jailbreak framing, such as disguising extraction requests as translation tasks, to get around Claude's safeguards that normally only expose summarised (not raw) reasoning traces.
Why it matters
If accurate, this shows a live and effective method for extracting Claude's proprietary reasoning traces at industrial scale to train cheaper rival models, which bears on Anthropic's competitive position and its pricing/moat argument. It also strengthens the case for tighter API access controls, rate limits, and possibly export-policy debates around frontier model access, which matters to enterprises, regulators and competitors who rely on API terms staying open. For most developers and users, this changes little day to day; it is a policy and competitive-dynamics story rather than a product or capability shift.
What is noise
The attribution to Alibaba, Moonshot AI and the Chinese military rests entirely on Anthropic's own unaudited account and behaviour analysis; there is no independent verification, and Anthropic has a direct competitive and policy interest in this narrative being believed. Framing this as a dramatic escalation somewhat overstates the novelty, since Anthropic and OpenAI made similar distillation accusations against Chinese labs back in February; what is new here is scale and specificity, not the phenomenon itself. The "Chinese military" detail is the most attention-grabbing element but is also the least verifiable claim in the report.
Watch next
- 01Whether Alibaba, Moonshot AI or DeepSeek issue any public response, denial, or clarification to Anthropic's attribution claims
- 02Whether Anthropic or independent researchers publish technical evidence (prompt logs, account fingerprinting methodology) that can be externally verified rather than taken on trust
- 03Whether Anthropic announces concrete API changes (stricter rate limits, account verification, chain-of-thought access restrictions) as a direct response, and whether these affect legitimate developers
- 04Whether this report is cited in any forthcoming US export-control or AI policy action targeting API access for Chinese entities
Coverage
1 storyMore capability signals
Full feed →- Deepseek releases V4.1-Flash, an open-source model that sharply cuts KV cache memory and input-processing compute for AI agents10 Sept 202682
- AI systems outperform expert humans in persuasive communication22 Jun 202681
- WIRED investigation: Flock Safety's AI person-search tools let police run broad description-based surveillance, with weak guardrails against misuse3 Sept 202680
- Google DeepMind launches AlphaGenome Atlas, a free public database of predicted effects for 9 billion possible human genome variants8 Sept 202679