Editorial illustration for Anthropic: Five Campaigns Launched 200 Million AI Distillation Attacks
Anthropic: China Firms Launched 200M Claude Attacks
Anthropic: Five Campaigns Launched 200 Million AI Distillation Attacks
Anthropic published a report Thursday laying out what it says are coordinated efforts by China-based AI companies to strip the reasoning capabilities out of its Claude models. The company names Alibaba, Moonshot AI, and DeepSeek as targets of its investigation, and puts a number on the scale of the problem: nearly 200 million exchanges tied to five distinct campaigns aimed at extracting Claude's underlying capabilities.
This isn't the first time Anthropic has raised the alarm. Back in February, the company called out specific labs over similar behavior. OpenAI has made comparable claims, pointing directly at DeepSeek as the source of unauthorized extraction attempts on its own models. What's new in Thursday's report is the size and sophistication of the operations Anthropic says it uncovered, methods that go well beyond simple prompt scraping.
At the center of the dispute is chain of thought, the step-by-step reasoning a model produces before answering a query. Anthropic doesn't expose that raw reasoning to users, showing only condensed summaries instead. The report details how attackers found ways around that safeguard, coaxing models into revealing their internal thinking through carefully disguised requests.
The bulk of the distillation attempts came from a campaign attributed to Alibaba, which Anthropic describes as the largest wholesale distillation effort the company has ever observed. The company observed 151 million exchanges between May and July 2026 that were attributed to the campaign, peaking at nearly three million exchanges per day.
Why this matters
Anthropic's numbers, five campaigns, nearly 200 million exchanges, describe a scale that's hard to dismiss as isolated scraping. If chain-of-thought outputs are being harvested this systematically, the moat frontier labs claim around reasoning capabilities is thinner than marketing suggests. For developers and founders building on Claude or similar models, the immediate question isn't abstract IP theft, it's whether the defenses these companies tout actually hold up against determined, well-resourced adversaries.
Anthropic names Alibaba, Moonshot AI, and DeepSeek, but naming isn't proving, and the report is self-interested: Anthropic has obvious reasons to frame distillation as theft rather than competition. Still, the operational detail, five distinct campaigns rather than one diffuse pattern, suggests something more organized than opportunistic misuse. Researchers should watch whether Anthropic or others release technical specifics on detection methods, because right now we're taking their word for both the scale and the attribution.
Expect rival labs to push back, and expect this to become a template for how frontier companies justify tighter API restrictions going forward.
Common Questions Answered
Which companies did Anthropic identify as conducting AI distillation attacks on Claude models?
Anthropic named Alibaba, Moonshot AI, and DeepSeek as the companies targeted in its investigation of coordinated distillation efforts. These China-based AI companies were identified as part of five distinct campaigns aimed at extracting Claude's underlying reasoning capabilities.
How many exchanges were attributed to Alibaba's distillation campaign according to Anthropic's report?
Anthropic observed 151 million exchanges between May and July 2026 that were attributed to Alibaba's campaign, which the company describes as the largest wholesale distillation effort it has ever observed. The campaign peaked at nearly three million exchanges per day during this period.
What is the total scale of the distillation attacks Anthropic documented across all five campaigns?
Anthropic documented nearly 200 million exchanges tied to five distinct campaigns aimed at extracting Claude's reasoning capabilities. This scale represents a coordinated effort that Anthropic argues is too large to dismiss as isolated scraping activity.
What specific capabilities were the distillation campaigns attempting to extract from Claude models?
The campaigns were primarily focused on harvesting chain-of-thought outputs and reasoning capabilities from Claude models. According to Anthropic, the systematic extraction of these outputs suggests that the competitive moat frontier labs claim around reasoning capabilities may be thinner than their marketing suggests.
Why does Anthropic's distillation report matter for developers building on Claude?
For developers and founders building on Claude or similar models, the report raises immediate questions about whether the security defenses these companies tout actually hold up against determined distillation attacks. The scale and coordination of these campaigns suggest that the protective measures around advanced AI capabilities may be less robust than publicly claimed.
Further Reading
- Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek - TechCrunch
- Anthropic says Alibaba illicitly extracted Claude AI model capabilities - Reuters
- Anthropic accuses Chinese AI labs of mining Claude as US debates AI chip exports - TechCrunch
- Anthropic accuses Chinese rival Alibaba of illicitly extracting Claude AI model capabilities - BBC News
- Anthropic's Threat Report: Attacks Run on Agent Frameworks and Distillation Campaigns - CellCog