Anthropic says seven China-based AI labs ran industrial-scale distillation attacks against its Claude models, harvesting nearly 190 million exchanges between May and July, according to a threat intelligence report published September 11. The largest single campaign, attributed to Alibaba-affiliated operators, measured 151 million exchanges and peaked at roughly 3 million per day.
Distillation is a legitimate training technique: a large model acts as a teacher for a smaller one. Illicit distillation is the covert version, where a lab extracts another company’s model capabilities without authorization, usually through networks of fake accounts created with stolen credit cards, credentials and API keys. Anthropic’s report describes the second kind at a scale the company says it has never measured before.
The campaigns
The report breaks the activity into named campaigns, each with its own method.
GTG-16005, the largest, involved a cluster of Alibaba-affiliated operators targeting the chain-of-thought reasoning transcripts of Claude Opus 4.6 and 4.7 between May and July. It peaked at about 3 million exchanges a day from more than 3,500 fraudulent accounts, aimed at agentic tasks, software engineering, kernel development and long-horizon problems. Anthropic called it the largest distillation attack it has ever measured.
GTG-16002, attributed to Moonshot AI, was different in kind. The company behind the Kimi models quietly rerouted customer requests to Claude instead of processing them on its own models, then displayed Claude’s answers to its own users. Over ten days it relayed almost 300,000 customer requests through a proxy network of 5,380 fraudulent accounts, mostly located in Singapore and Japan. A subset of those exchanges was captured to train Kimi’s reasoning. Customers paying for Kimi were, in effect, unknowingly querying Claude.
DeepSeek ran the same play. Campaign GTG-16001 logged more than 12.1 million exchanges over 14 days in July, relaying user requests to Claude without telling them and extracting reasoning transcripts. Zhipu, also known as Z.ai, ran a chain-of-thought extraction pipeline through 273 rotating accounts, logging 3.4 million exchanges in June and July. Xiaomi replayed user conversations and coding sessions from its MiMo models into Claude through coding harnesses to build training data. SenseTime simply bought transcripts of user exchanges from third-party data vendors. MiniMax built its own proxy service through a shell company selling access to Anthropic and OpenAI models, likely to collect exchanges for training.
| Campaign | Attributed to | Scale | Method |
|---|---|---|---|
| GTG-16005 | Alibaba-affiliated operators | 151M exchanges, May-July | CoT transcript harvesting at scale |
| GTG-16002 | Moonshot AI | 23M exchanges; 300K user relays | Silent rerouting of customer traffic |
| GTG-16001 | DeepSeek | 12.1M exchanges over 14 days | Silent rerouting, CoT extraction |
| GTG-16006 | Zhipu / Z.ai | 3.4M exchanges | CoT extraction via 273 accounts |
| GTG-16008 | Xiaomi | 400K+ exchanges | Replaying MiMo sessions into Claude |
| GTG-16012 | SenseTime | Unspecified | Buying transcripts from data vendors |
| GTG-16003 | MiniMax | Unspecified | Shell-company proxy network |
The proxy resale market
One finding matters more than any single campaign. Anthropic describes a secondary market where proxy networks both sell Claude access to users in unsupported regions and save the exchanges to sell to other labs. The harvested conversations become a commodity. A lab does not need to run its own attack; it can buy someone else’s harvest.
That changes the enforcement problem. Anthropic can ban accounts and block regions, but it cannot see who ultimately buys a batch of stolen transcripts. The report’s authors frame the proxy proliferation as the structural issue, with the individual campaigns as symptoms of a supply chain in stolen reasoning data.
What the labs say
Nothing, so far. Representatives for Alibaba, Moonshot, DeepSeek, Zhipu and Xiaomi did not respond to Business Insider’s queries, and Anthropic did not respond to its own request for comment. OpenAI has previously made similar claims against DeepSeek, and Google’s threat intelligence group reported more than 100,000 distillation prompts targeting Gemini. The accusations now come from three of the four major US labs, pointed mostly in one direction.
Anthropic’s countermeasures
The company’s defenses are mostly about making stolen data less useful. Claude now summarizes its internal reasoning before responding, rather than exposing full chain-of-thought transcripts, which degrades the training value of anything harvested. With the Fable 5.1 release it added preserved thinking, which stops new API accounts from altering the system prompt, tools or messages that precede Claude’s reasoning in multi-turn conversations. Accounts operating from unsupported regions, including China, Iran and Russia, are banned when users fail identity verification.
Whether those measures hold is the real test. The campaigns in this report escalated within months of Anthropic’s first public disclosure in February, when it named DeepSeek, Moonshot and MiniMax for roughly 16 million exchanges through about 24,000 fraudulent accounts. The May-July wave was an order of magnitude larger. Detection and disruption are not the same as deterrence, and the trend line points the wrong way.
The report also lands in a policy moment. The Trump administration is weighing whether to allow Nvidia to export advanced chips, including the H200 and Blackwell lines, to China. Labs that harvest US model capabilities and labs that buy US chips are, in Anthropic’s framing, parts of the same national security question. The company has explicitly tied distillation to military and surveillance applications by authoritarian governments, which moves the issue from a business dispute toward export-control territory.
For now the practical effect is narrower: Anthropic has documented the scale of the problem in numbers no one can call anecdotal, and the burden of response shifts to the named labs, none of which has answered the allegations. The next test is whether a second report in six months shows the defenses bending the curve or merely cataloguing a larger one.
