The distillation campaigns against Anthropic’s Claude models have grown large enough to count in the hundreds of millions. In a report released Thursday, Anthropic said it observed roughly 199 million exchanges tied to unauthorized distillation attacks, spread across five separate campaigns that it attributes to China-based AI labs, with the largest single effort linked to Alibaba’s Qwen model family.
What Anthropic says the campaigns look like
Distillation is a standard machine-learning technique: a smaller model is trained on the outputs of a larger one to transfer reasoning ability. The friction point is consent. Anthropic says its models’ internal chain of thought is not exposed to users, and that the campaigns found ways to extract those traces anyway.
Also read: Meta's AI Agent Muse Hits No. 2 on US App Store With 83,000 Downloads
One documented technique framed a query as a translation task, asking the model to render its previous working memory in Japanese. The company characterized the broader pattern as an attempt to harvest “some of Claude’s most valuable capabilities, including agentic capabilities and tool use, coding and data analysis, and logical reasoning.”
Alibaba campaign dwarfs prior disclosures
Anthropic describes the Alibaba-attributed effort as the largest wholesale distillation it has ever documented. Between May and July 2026, the company observed 151 million exchanges, peaking at close to three million per day, spread across about 3,500 accounts.
Also read: Apple's new foldable iPhone 'Duo' relies on an AI-crafted, 3D-printed hinge to fight wear and tear
What tied those accounts together, according to Anthropic, was a single fixed extraction prompt. That shared signature is why the company attributes the activity to one orchestrated effort to generate training material for the Qwen family of models rather than thousands of independent users.
The scale stands out against Anthropic’s own earlier disclosures. The company first spoke publicly about distillation attacks in February, naming specific labs at the time. OpenAI has reported similar activity, which it attributed to DeepSeek. Anthropic’s new report describes campaigns it characterizes as both larger and more aggressive than that prior wave.
Moonshot AI and the military routing claim
The second campaign Anthropic details is attributed to Moonshot AI, maker of the Kimi assistant. According to the report, requests appeared to be routed directly from the Chinese military. Anthropic cites one example in which Claude was asked to assess a cache of closed-circuit surveillance footage to determine whether a subject was “behaving abnormally.”
Over one ten-day stretch, Anthropic says nearly 300,000 requests flowed through a network of about 5,000 accounts, primarily targeting the company’s Opus model.
What the disclosure means for AI policy and competition
Anthropic’s findings land in the middle of a broader regulatory argument about how much of a frontier model’s value lives in its weights versus in its deployment. US export-control debates have increasingly treated advanced chips and model know-how as strategically sensitive, and distillation findings give regulators a concrete category of behavior to point to.
For enterprise buyers, the practical question is different: whether the safeguards Anthropic describes — summarized thinking blocks rather than raw traces — hold up against increasingly creative extraction methods. The company’s report suggests attackers iterate faster than the defenses do.
What to watch next is less about Claude and more about the industry’s response. Detection tools, usage-pattern monitoring and possibly contractual or legislative limits on model harvesting are now an active area of discussion. Whether vendors coordinate on enforcement, or leave each other to defend separate moats, will shape both the pace of capability diffusion and the trust that buyers place in frontier AI providers going forward.

Be the first to comment