TechNewsReel
Live

Anthropic Accuses Chinese AI Labs of Harvesting Millions of Claude Exchanges

A threat intelligence report alleges Alibaba, Moonshot AI, and DeepSeek used fraudulent accounts to distill frontier model capabilities.

TechNewsReel Newsroom · September 11, 2026

Anthropic has accused several China-based AI laboratories of conducting large-scale "distillation" attacks to systematically harvest the capabilities of its Claude models. The company alleges that these labs used networks of fraudulent accounts to extract millions of exchanges to train competing AI systems.

According to a threat intelligence report released in September 2026, Anthropic identified nearly 200 million unauthorized exchanges across five separate campaigns between December 2025 and August 2026. The report specifically names Alibaba, Moonshot AI, and DeepSeek as participants in these efforts. Alibaba's Qwen AI lab is accused of running the largest operation, with 151 million exchanges observed between May and July 2026, peaking at nearly 3 million requests per day.

The Mechanics of Distillation

Model distillation is a process where a smaller, more cost-effective AI model is trained using the outputs of a larger "teacher" model to mimic its reasoning and performance. In this instance, the attackers targeted Claude's most high-value capabilities, including logical reasoning, coding, data analysis, and agentic tool use.

To bypass security filters, the labs employed sophisticated prompting techniques. Anthropic noted that some attackers framed queries as translation requests into katakana-only Japanese to trick the model into revealing its internal "chain of thought" reasoning traces. In one specific campaign, Moonshot AI—the developer of Kimi—reportedly routed nearly 300,000 requests through 5,000 accounts over a 10-day period, primarily targeting the high-end Opus model.

National Security and Industry Impact

This incident represents a significant escalation in industrial espionage within the AI sector. By harvesting frontier capabilities, competing labs can bypass the immense financial costs and massive data requirements typically required for original model training. Anthropic's Terms of Service explicitly prohibit using its API responses to develop competing models.

Beyond corporate intellectual property, the report introduces a national security dimension. Anthropic alleges that Moonshot AI routed requests that appeared to originate from the Chinese military, including a specific request to analyze CCTV footage for "abnormal" behavior. This occurs amidst intensifying global tensions over AI chip exports and the race for frontier model supremacy between the U.S. and China.

The Path Forward

Anthropic stated in its report that unauthorized labs have developed "increasingly sophisticated methods" to circumvent defenses and harvest U.S. frontier models. This follows similar previous reports from OpenAI regarding DeepSeek, suggesting a systemic pattern of distillation across the industry.

Industry observers are now watching to see if these allegations will trigger further regulatory actions or stricter API access controls for international users. It remains to be seen if the accused labs will respond to the specific figures cited in the threat intelligence report or if the U.S. government will intervene given the alleged military connections.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.