· via TechCrunch
Anthropic report details 200 million exchanges in Chinese labs' Claude distillation campaigns
Anthropic's September 2026 threat report attributes five distillation campaigns — including a 151-million-exchange effort tied to Alibaba — to Chinese AI labs, and says it disrupted all detected activity.

Anthropic has published a threat intelligence report describing what it says are escalating, unauthorized attempts by China-based AI labs to distill capabilities from its Claude models. According to TechCrunch, the report, released Thursday, links nearly 200 million exchanges to five separate distillation campaigns, with the bulk attributed to Alibaba.
The report says that over the past several months unauthorized labs have found increasingly sophisticated ways around Anthropic's defenses to harvest the capabilities of US frontier models. The campaigns targeted some of Claude's most valuable skills, according to TechCrunch: agentic behavior and tool use, coding and data analysis, and logical reasoning.
How the extraction worked
Distillation, in this context, means extracting a model's chain of thought — its step-by-step reasoning — and using that output as supervised fine-tuning data to teach another model general reasoning ability. Anthropic does not normally expose raw chain of thought to users, instead showing summarized thinking blocks. But according to the report, attackers developed specific prompt techniques that tricked the model into revealing its actual reasoning traces. In one example described by TechCrunch, a request was framed as a translation task, asking the model to render its previous working memory in katakana-only Japanese.
The Alibaba campaign
The largest of the five efforts was attributed to Alibaba, and Anthropic describes it as the biggest wholesale distillation operation the company has ever observed. Between May and July 2026, Anthropic counted 151 million exchanges tied to the campaign, peaking at nearly three million exchanges per day. The traffic was spread across roughly 3,500 accounts, but because every request relied on a single fixed prompt for extracting chain of thought, Anthropic attributed the activity to one coordinated effort to produce training material for Alibaba's Qwen family of models.
Moonshot AI and surveillance-linked requests
A second campaign, attributed to Moonshot AI, the company behind the Kimi assistant, appeared to route requests directly from the Chinese military. One request cited in the report asked Claude to assess a cache of closed-circuit surveillance footage and determine whether the subject was behaving abnormally. Over a ten-day period, nearly 300,000 requests reached Claude through a network of about 5,000 accounts, aimed primarily at Anthropic's Opus model.
TechCrunch notes that Anthropic publicly called out distillation activity in February, and that OpenAI has previously reported similar behavior it attributed to DeepSeek. DeepSeek also appears among the labs named in the new report, though the detailed figures in the available coverage cover the Alibaba and Moonshot campaigns.
The wider report and the response
Distillation is one of seven harm areas in the report, which covers activity Anthropic says it identified and disrupted between December 2025 and August 2026. The others are cyber operations, influence operations, surveillance, scams and fraud, biological misuse, and conventional weapons development. Anthropic says the misuse cases involved its Haiku, Sonnet and Opus models, with a single illicit distillation case the only exception involving its Fable or Mythos-class models. In each case, the company says it disrupted the activity, used what it learned to strengthen safeguards, and shared intelligence with authorities and industry partners where appropriate. The publication follows earlier Anthropic threat reports in March, August and November 2025.
A write-up on dev.to characterizes the document as a redacted August 2026 risk report covering frontier-model risk through mid-July, while Anthropic's own page is dated September 2026 and covers disrupted activity through August — the same release under slightly different dating. The dev.to piece also cautions that the redacted public version should not be treated as a complete record of every investigated case.
Why it matters
Distillation strikes at the economics of frontier AI. The reasoning traces of a top model are among the most expensive artifacts a lab produces, and mass extraction effectively transfers that investment to a competitor at API prices. The scale documented here — hundreds of millions of exchanges — shows that terms-of-service bans are not self-enforcing, and that detection depends on pattern analysis across thousands of accounts rather than filtering any single request.
The chain-of-thought extraction techniques matter on their own. They demonstrate that hiding raw reasoning behind summarized output is a security boundary that can be probed and broken with careful prompt engineering, giving every lab that exposes or withholds reasoning traces a concrete attack class to defend against.
Finally, the Moonshot case connects commercial model access to military-linked surveillance workflows. That linkage is likely to sharpen policy debates over API access for foreign actors, and the report itself feeds that discussion — Anthropic says it published the findings to help other developers recognize similar patterns on their own platforms and to give governments a clearer view of how emerging threats take shape.
- #anthropic
- #ai-security
- #distillation
- #threat-intelligence
- #claude