AI

Anthropic Accuses Chinese AI Labs of Massive Distillation Campaigns Targeting Claude

A new report identifies nearly 200 million queries designed to harvest reasoning traces from frontier models, pointing to efforts from Alibaba, Moonshot AI, and DeepSeek.

  • Chinese artificial intelligence developers are systematically targeting frontier reasoning models through coordinated distillation efforts, according to findings published by Anthropic on Thursday.
  • The activity, reported by TechCrunch, represents a sharp escalation in industrial-scale model distillation.
  • Anthropic does not expose full chain-of-thought outputs to standard users, displaying condensed summaries instead.
Anthropic Accuses Chinese AI Labs of Massive Distillation Campaigns Targeting ClaudeThe Scale Report

Chinese artificial intelligence developers are systematically targeting frontier reasoning models through coordinated distillation efforts, according to findings published by Anthropic on Thursday. The San Francisco-based AI company documented five distinct campaigns comprising nearly 200 million interactions aimed at harvesting Claude's proprietary capabilities.

The activity, reported by TechCrunch, represents a sharp escalation in industrial-scale model distillation. Attackers focused heavily on extracting internal chain-of-thought traces, which reveal the intermediate logical steps a model takes before producing an answer. These traces can be used to fine-tune smaller open-source models, effectively transferring high-level reasoning, coding skills, and tool-use performance without incurring the massive initial training costs.

Anthropic does not expose full chain-of-thought outputs to standard users, displaying condensed summaries instead. However, researchers found that coordinated networks bypassed safeguards using creative prompt engineering. In one highlighted instance, queries instructed Claude to act as a translator and render its hidden working memory into katakana-only Japanese, successfully leaking internal reasoning.

Industrial Scale Extraction

The largest campaign documented by Anthropic was attributed to Alibaba. Between May and July 2026, the operation generated approximately 151 million exchanges across 3,500 accounts, peaking at nearly three million queries per day. Anthropic tied the volume to an effort to produce fine-tuning data for Alibaba's Qwen model family, noting identical prompt structures across the accounts.

A separate operation linked to Moonshot AI, the startup behind the Kimi assistant, deployed roughly 5,000 accounts to send 300,000 queries to Claude Opus over a 10-day window. Anthropic noted that several prompts in that cluster appeared to involve state surveillance tasks, including requests to evaluate closed-circuit camera feeds for suspicious behavior. DeepSeek was also cited in connection with ongoing distillation activity.

The Strategic Stakes

The dispute underscores a growing technical rift in generative AI. As leading American labs invest billions in training large-scale reasoning architectures, the resulting models become prime targets for competitors seeking cost-effective shortcuts. With frontier labs keeping technical architectures and reasoning traces private, automated scraping and adversarial elicitation have become standard tools in the race to catch up.

Reporting based on coverage from AI News & Artificial Intelligence | TechCrunch.

The daily brief

The biggest stories in AI, venture, sports business and culture - once a day.

One short email from The Scale Report. No spam, unsubscribe any time.

Read next