Anthropic has accused seven China-based AI labs of attacking its Claude models. It said they ran industrial-scale illicit distillation campaigns. The named labs include Alibaba, DeepSeek, Moonshot, and MiniMax. Zhipu, Xiaomi, and SenseTime also feature in the accusations.
Understanding the term distillation helps frame the issue. Distillation itself is a legitimate machine learning training technique. Essentially, a powerful “teacher” model trains a smaller “student” model. That student then copies the larger model’s capabilities effectively.
However, illicit distillation covertly extracts capabilities without any authorization. Attackers typically use networks of fake accounts to achieve this. These accounts rely on stolen credit cards and API keys. Consequently, they harvest capabilities like reasoning, coding, and tool use.
The scale of the largest campaign proved staggering. Alibaba-affiliated operators generated 151 million exchanges over three months. Anthropic called it the largest distillation attack ever measured. It peaked at roughly 3 million exchanges every single day.
Some methods were particularly deceptive toward ordinary users. Moonshot and DeepSeek secretly rerouted their customers’ requests to Claude. Users saw Claude’s responses while believing they used other models. Meanwhile, those exchanges were captured to train rival systems.
Crucially, this harvesting exposed genuinely sensitive user information. Anthropic said some captured exchanges included private user data. This spanned individuals, major multinational companies, and state-affiliated actors. Therefore, the attacks carry real privacy implications beyond mere theft.
The labs accessed Claude through proxy services and relay stations. These services create thousands of accounts under fake identities. Some also acquired transcripts from third-party data resellers. Notably, these resellers save user conversations without any consent.
Anthropic has taken several steps to counter the attacks. It bans reseller accounts and unverified users from restricted regions. Additionally, Claude now summarizes its internal reasoning before responding. This makes any stolen transcripts far less useful for training.
The disclosure follows wider concerns about AI capability theft. US agencies recently accused Chinese firms of systematic extraction. Western labs like Google and OpenAI reported similar attacks previously. Ultimately, the report highlights an escalating battle over frontier AI. Protecting these expensive capabilities is becoming a major industry challenge.
