Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$77,816▲ 0.32%ETH$2,511▲ 0.06%SOL$102.05▲ 1.10%TOTAL CRYPTO$2.67T▼ 0.82%S&P 5007,619.98▼ 2.13%NASDAQ26,186.41▼ 2.03%DOW52,421.20▼ 2.44%GOLD4,352.00▼ 0.65%WTI102.96▲ 24.95%BRENT107.18▲ 21.08%EUR/USD1.1539▲ 0.03%USD/JPY154.86▼ 2.87%DXY99.62▼ 0.05%
AI

Anthropic: China Labs Hit Claude With 190M Attacks

A September report says Alibaba, Moonshot, DeepSeek, Zhipu and Xiaomi ran industrial-scale distillation campaigns against Claude between May and July.

Pexels – Matheus Bertelli

Anthropic says seven China-based AI labs ran industrial-scale distillation attacks against its Claude models, harvesting nearly 190 million exchanges between May and July, according to a threat intelligence report published September 11. The largest single campaign, attributed to Alibaba-affiliated operators, measured 151 million exchanges and peaked at roughly 3 million per day.

Distillation is a legitimate training technique: a large model acts as a teacher for a smaller one. Illicit distillation is the covert version, where a lab extracts another company’s model capabilities without authorization, usually through networks of fake accounts created with stolen credit cards, credentials and API keys. Anthropic’s report describes the second kind at a scale the company says it has never measured before.

The campaigns

The report breaks the activity into named campaigns, each with its own method.

GTG-16005, the largest, involved a cluster of Alibaba-affiliated operators targeting the chain-of-thought reasoning transcripts of Claude Opus 4.6 and 4.7 between May and July. It peaked at about 3 million exchanges a day from more than 3,500 fraudulent accounts, aimed at agentic tasks, software engineering, kernel development and long-horizon problems. Anthropic called it the largest distillation attack it has ever measured.

GTG-16002, attributed to Moonshot AI, was different in kind. The company behind the Kimi models quietly rerouted customer requests to Claude instead of processing them on its own models, then displayed Claude’s answers to its own users. Over ten days it relayed almost 300,000 customer requests through a proxy network of 5,380 fraudulent accounts, mostly located in Singapore and Japan. A subset of those exchanges was captured to train Kimi’s reasoning. Customers paying for Kimi were, in effect, unknowingly querying Claude.

DeepSeek ran the same play. Campaign GTG-16001 logged more than 12.1 million exchanges over 14 days in July, relaying user requests to Claude without telling them and extracting reasoning transcripts. Zhipu, also known as Z.ai, ran a chain-of-thought extraction pipeline through 273 rotating accounts, logging 3.4 million exchanges in June and July. Xiaomi replayed user conversations and coding sessions from its MiMo models into Claude through coding harnesses to build training data. SenseTime simply bought transcripts of user exchanges from third-party data vendors. MiniMax built its own proxy service through a shell company selling access to Anthropic and OpenAI models, likely to collect exchanges for training.

Campaign Attributed to Scale Method
GTG-16005 Alibaba-affiliated operators 151M exchanges, May-July CoT transcript harvesting at scale
GTG-16002 Moonshot AI 23M exchanges; 300K user relays Silent rerouting of customer traffic
GTG-16001 DeepSeek 12.1M exchanges over 14 days Silent rerouting, CoT extraction
GTG-16006 Zhipu / Z.ai 3.4M exchanges CoT extraction via 273 accounts
GTG-16008 Xiaomi 400K+ exchanges Replaying MiMo sessions into Claude
GTG-16012 SenseTime Unspecified Buying transcripts from data vendors
GTG-16003 MiniMax Unspecified Shell-company proxy network

The proxy resale market

One finding matters more than any single campaign. Anthropic describes a secondary market where proxy networks both sell Claude access to users in unsupported regions and save the exchanges to sell to other labs. The harvested conversations become a commodity. A lab does not need to run its own attack; it can buy someone else’s harvest.

That changes the enforcement problem. Anthropic can ban accounts and block regions, but it cannot see who ultimately buys a batch of stolen transcripts. The report’s authors frame the proxy proliferation as the structural issue, with the individual campaigns as symptoms of a supply chain in stolen reasoning data.

What the labs say

Nothing, so far. Representatives for Alibaba, Moonshot, DeepSeek, Zhipu and Xiaomi did not respond to Business Insider’s queries, and Anthropic did not respond to its own request for comment. OpenAI has previously made similar claims against DeepSeek, and Google’s threat intelligence group reported more than 100,000 distillation prompts targeting Gemini. The accusations now come from three of the four major US labs, pointed mostly in one direction.

Anthropic’s countermeasures

The company’s defenses are mostly about making stolen data less useful. Claude now summarizes its internal reasoning before responding, rather than exposing full chain-of-thought transcripts, which degrades the training value of anything harvested. With the Fable 5.1 release it added preserved thinking, which stops new API accounts from altering the system prompt, tools or messages that precede Claude’s reasoning in multi-turn conversations. Accounts operating from unsupported regions, including China, Iran and Russia, are banned when users fail identity verification.

Whether those measures hold is the real test. The campaigns in this report escalated within months of Anthropic’s first public disclosure in February, when it named DeepSeek, Moonshot and MiniMax for roughly 16 million exchanges through about 24,000 fraudulent accounts. The May-July wave was an order of magnitude larger. Detection and disruption are not the same as deterrence, and the trend line points the wrong way.

The report also lands in a policy moment. The Trump administration is weighing whether to allow Nvidia to export advanced chips, including the H200 and Blackwell lines, to China. Labs that harvest US model capabilities and labs that buy US chips are, in Anthropic’s framing, parts of the same national security question. The company has explicitly tied distillation to military and surveillance applications by authoritarian governments, which moves the issue from a business dispute toward export-control territory.

For now the practical effect is narrower: Anthropic has documented the scale of the problem in numbers no one can call anecdotal, and the burden of response shifts to the named labs, none of which has answered the allegations. The next test is whether a second report in six months shows the defenses bending the curve or merely cataloguing a larger one.

SourcesAnthropic Threat Intelligence Report, September 2026; The Hacker News; TechCrunch; Business Insider.
Share: X