Thursday, September 10, 2026
Tech Beat
Sep 10, 2026, 8:57 PMArtificial Intelligence

Anthropic Alleges Nearly 200 Million Claude Distillation Exchanges Led by Alibaba

Anthropic says five AI distillation campaigns generated nearly 200 million Claude exchanges, led by Alibaba, with Moonshot AI routing military requests.

Listen to this briefingAudio briefing

Summary

Anthropic said on September 10, 2026, that five persistent distillation campaigns tied to China-based AI companies produced nearly 200 million Claude exchanges, escalating in recent months as competition intensified. Attackers targeted agentic behavior and tool use, coding, data analysis, and logical reasoning. Distillation captures reasoning traces to train smaller models through supervised fine-tuning. Although Claude normally reveals only summarized thinking, attackers induced direct traces, including by posing as a translator and requesting prior working memory in natural Japanese written only in katakana. Anthropic first named labs over such attacks in February, while OpenAI separately attributed similar activity specifically to DeepSeek.

Alibaba was linked to 151 million exchanges from May to July 2026, Anthropic’s largest observed wholesale distillation effort, peaking at nearly 3 million daily across 3,500 accounts. A shared fixed extraction prompt tied the accounts to one campaign intended to generate training material for Alibaba’s Qwen models. Moonshot AI, maker of Kimi, allegedly routed nearly 300,000 requests over 10 days through 5,000 accounts, mainly targeting Claude Opus. The campaign appeared to relay requests directly from the Chinese military, including one asking Claude to analyze closed-circuit surveillance footage and determine whether a subject was behaving abnormally.

Positives

  • Anthropic identified five campaigns totaling nearly 200 million exchanges, exposing the scale and methods of attempted model extraction.
  • A single fixed prompt connected 3,500 Alibaba-linked accounts to training efforts for the Qwen model family.
  • Claude normally displays summarized thinking rather than internal reasoning traces, limiting direct exposure during ordinary use.
  • Anthropic’s September 10 disclosure follows its February warning, while OpenAI has separately identified similar DeepSeek activity.

Risks & concerns

  • Alibaba’s campaign generated 151 million exchanges from May to July 2026, reaching nearly 3 million requests per day.
  • Attackers bypassed Claude’s safeguards and extracted reasoning traces intended to remain hidden from users.
  • Moonshot AI allegedly routed nearly 300,000 requests through 5,000 accounts over just 10 days.
  • Chinese military requests included using Claude to assess surveillance footage for supposedly abnormal behavior.
  • Agentic tool use, coding, data analysis and logical reasoning were targeted as training material for rival models.
Primary sourceTechCrunchhttps://techcrunch.com/2026/09/10/anthropic-details-distillation-campaigns-from-alibaba-moonshot-ai-and-deepseek/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

Artificial IntelligenceSep 10

Nvidia CEO Jensen Huang Targets 70% Revenue Growth to $680 Billion

Artificial IntelligenceSep 10

OpenAI Pauses $200 Pro Signups as Astra Demand Strains Capacity

Artificial IntelligenceSep 10

Meta Muse Hits No. 2 on the U.S. App Store as AI Agent Race Intensifies