Key facts
- Anthropic alleged that China-based AI companies have escalated distillation attacks to harvest capabilities from US frontier models.
- The campaigns targeted Claude's agentic capabilities, tool use, coding, data analysis, and logical reasoning.
- Anthropic observed nearly 200 million exchanges linked to distillation attacks across five campaigns.
- A campaign attributed to Alibaba involved 151 million exchanges between May and July 2026.
- A campaign from Moonshot AI appeared to route requests from the Chinese military.
Anthropic alleged in a report released Thursday that China-based AI companies have intensified sophisticated "distillation attacks" in recent months to harvest capabilities from US frontier models like its Claude. These campaigns, which Anthropic described as larger and more aggressive than previously reported, aim to extract valuable functions such as logical reasoning, coding, and agentic capabilities for training smaller models.
The report detailed five distinct campaigns, totaling nearly 200 million exchanges. The largest, attributed to Alibaba, involved 151 million exchanges between May and July 2026, using a single fixed prompt across 3,500 accounts to extract the model's chain of thought. This effort was described as the largest wholesale distillation effort Anthropic has ever observed, aimed at producing training material for Alibaba's Qwen family of models.
Another campaign, linked to Moonshot AI, the maker of Kimi, reportedly routed requests directly from the Chinese military. According to Anthropic, one request asked Claude to analyze surveillance footage to determine if a subject was "behaving abnormally." Over a ten-day period, Anthropic observed nearly 300,000 requests routed through a network of 5,000 accounts, primarily targeting Claude's Opus model.
