source: TechCrunch AI: Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
level: technical
anthropic released a report on september 10, 2026, detailing persistent distillation attacks by china-based ai companies. the report says unauthorized labs have developed sophisticated methods to harvest capabilities from us frontier models. the campaigns targeted claude's agentic abilities, tool use, coding, data analysis, and logical reasoning. anthropic observed nearly 200 million exchanges linked to distillation attacks across five separate campaigns. this is a significant escalation from earlier reports in february.
the largest campaign was attributed to alibaba, with 151 million exchanges between may and july 2026, peaking at nearly three million per day. these exchanges came from 3,500 accounts using a single fixed prompt to extract chain of thought, likely for training alibaba's qwen models. another campaign from moonshot ai routed requests from the chinese military, including one asking claude to assess surveillance footage for abnormal behavior. over ten days, nearly 300,000 requests came through 5,000 accounts targeting the opus model.
distillation attacks extract a model's chain of thought by tricking it into revealing reasoning traces. anthropic normally shows summarized thinking, but attackers used prompts like framing a query as a translation request to get direct thinking traces. the extracted chain of thought can train smaller models through supervised fine-tuning. openai has reported similar activity from deepseek. this report shows the scale and sophistication of efforts to copy frontier model capabilities without authorization.
why it matters: distillation attacks let competitors copy expensive model reasoning at low cost, threatening the economic value of frontier ai research.
source: TechCrunch AI: Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek