Anthropic Alleges Massive Model Distillation Campaigns by Chinese AI Firms

AI-generated image · US National Wire
The company reports nearly 200 million exchanges aimed at extracting proprietary reasoning capabilities to train competing models.
Anthropic has released a report detailing aggressive "distillation attacks" from China-based AI companies designed to harvest the capabilities of U.S. frontier models. According to reporting from TechCrunch, these campaigns target high-value functions including tool use, agentic capabilities, logical reasoning, coding, and data analysis.
Distillation occurs when attackers extract a model's "chain of thought" to train smaller models on general reasoning via supervised fine-tuning. While Anthropic typically hides internal thinking traces, TechCrunch reports that attackers used sophisticated prompts—such as framing requests as Japanese translations—to trick the model into revealing its reasoning.
Anthropic identified five separate campaigns totaling nearly 200 million exchanges. The largest effort was attributed to Alibaba, which TechCrunch says is the biggest wholesale distillation attempt the company has ever seen. Between May and July 2026, Alibaba allegedly used 3,500 accounts to conduct 151 million exchanges to produce training material for its Qwen family of models, peaking at nearly three million exchanges per day.
Additionally, Anthropic identified a campaign from Moonshot AI, the creator of Kimi, which the company alleges routed requests directly from the Chinese military. TechCrunch notes that over a 10-day window, nearly 300,000 requests were sent through 5,000 accounts primarily targeting the Opus model, including one request to analyze surveillance footage for abnormal behavior. OpenAI has also reported similar distillation activity, which it attributed specifically to DeepSeek.

