Anthropic Says Chinese AI Labs Harvested Nearly 200 Million Claude Exchanges
Model distillation is a standard technique in which a smaller “student” system learns from outputs generated by a stronger “teacher” model. Anthropic says the practice becomes illicit when rivals covertly use fake accounts, stolen credentials and proxy networks to extract proprietary capabilities without permission. The dispute matters because such campaigns can compress years of research and large computing costs into reusable training data, while potentially exposing customer information and weakening the safeguards built into frontier AI systems.
In a report released on Sept. 10, 2026, Anthropic said it observed nearly 200 million Claude exchanges across five distillation campaigns. It attributed more than 151 million exchanges from May through July to Alibaba, peaking at nearly 3 million a day and targeting Qwen training. Moonshot AI was linked to more than 23 million exchanges over the same period, while DeepSeek generated more than 12.1 million in 14 days in July. Anthropic said the operations sought Opus chain-of-thought traces, coding and agentic capabilities, and that some customer prompts were rerouted without users’ knowledge.
All Coverage
2 original reportsThe Backstory
The history behind this eventAnthropic Accuses Alibaba of Largest-Ever Distillation Attack on Claude
Anthropic accused Alibaba’s Qwen AI lab of using “distillation” to extract Claude’s software engineering and agentic reasoning capabilities from its outputs. Such practices could circumvent the high cost of training models and have renewed scrutiny in the U.S. Congress over the national security risks of giving Chinese companies access to advanced AI models.
Anthropic recently told the U.S. Senate that Qwen used nearly 25,000 accounts to interact with Claude 28.8 million times, making it the largest distillation attack the company has detected to date. Following the disclosure, Alibaba reportedly instructed employees to uninstall all Claude products. The incident could also spur bipartisan efforts in the United States to consider restrictions on foreign access to AI models.
Anthropic Urges U.S. to Lead China on AI to Safeguard Democracy and Counter Distillation Attacks
Anthropic said frontier AI models will shape more than industrial competition and could embed the governance values of the countries that develop them into global infrastructure. The company argued that if the United States loses its advantage over China in models and computing power, authoritarian uses such as surveillance and censorship could spread abroad. Maintaining the technological lead is therefore critical to democratic norms and national security, it said.
Anthropic’s latest policy report identifies 2028 as a pivotal point in the U.S.-China AI race, warning that chip smuggling, leaks of model weights and “distillation attacks” could rapidly erase the U.S. advantage. It recommends tighter AI chip export controls and stronger enforcement, as well as criminalizing distillation attacks that extract model capabilities without authorization. The report did not propose a funding amount for these policies.
China’s Moonshot and Other AI Firms Accused of Stealing Anthropic Claude Technology Through ‘Distillation Attacks’
Model distillation uses the outputs of a powerful model to train a smaller one and can legitimately reduce development costs. But competitors that use fake accounts to evade terms of service and extract Claude responses at scale may violate Anthropic’s intellectual property rights and service restrictions. The dispute also has national security implications, as copied reasoning, tool-use and coding capabilities could operate without the original safeguards.
On February 23, 2026, Anthropic accused Moonshot AI, DeepSeek and MiniMax of using about 24,000 fraudulent accounts to generate more than 16 million interactions with Claude. These included more than 3.4 million interactions by Moonshot, more than 13 million by MiniMax and more than 150,000 by DeepSeek. Distillation concerns resurfaced recently after Moonshot’s Kimi bot identified itself as Claude in a response. Anthropic did not disclose the amount involved or estimate its losses.
Anthropic Accuses DeepSeek and Other Chinese AI Labs of Illegally Using Claude Data to Train Models
Model distillation can be a legitimate technique in which a more powerful model is queried at scale and its outputs are collected to train a smaller model to replicate its reasoning and coding capabilities. Anthropic, however, accused DeepSeek, MiniMax and Moonshot AI of circumventing Claude's terms of service and regional restrictions. The case touches on U.S.-China AI competition, intellectual property and model security, and could also result in existing safeguards being removed.
On Feb. 23, 2026, Anthropic released an investigation alleging that the three labs used about 24,000 noncompliant accounts to interact with Claude more than 16 million times. MiniMax accounted for more than 13 million interactions, Moonshot AI more than 3.4 million and DeepSeek more than 150,000. Anthropic did not disclose any financial losses. It said it had strengthened account verification and detection systems and shared attack indicators with industry peers and cloud providers.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →