Anthropic Details Distillation Campaigns Linked to Alibaba, Moonshot AI and DeepSeek
Summary
Anthropic says a new report identified five persistent distillation campaigns that together generated nearly 200 million exchanges aimed at harvesting capabilities from its Claude models. The company says the campaigns targeted agentic capabilities and tool use, coding and data analysis, and logical reasoning, and became more sophisticated as competition intensified. Distillation involves using model responses, including reasoning traces, as training material for a smaller model. Anthropic normally shows users summarized thinking rather than internal chain-of-thought, but says attackers found prompts that could induce Claude to reveal more direct traces, including by disguising a request as a katakana-only Japanese translation task. The largest campaign, attributed to Alibaba, produced 151 million exchanges from May through July 2026, peaked at almost three million per day, and used 3,500 accounts with a shared extraction prompt. Anthropic linked the activity to efforts to create training material for Alibaba’s Qwen model family. A separate campaign attributed to Moonshot AI, the maker of Kimi, routed requests through 5,000 accounts, including a surveillance-footage analysis request that Anthropic said appeared to come from the Chinese military; nearly 300,000 requests were sent over 10 days, primarily targeting Claude Opus. The report follows earlier allegations by Anthropic and similar claims from OpenAI involving DeepSeek.