Operators tied to Alibaba pushed nearly 3 million requests a day at Claude at the campaign's peak, part of a covert effort Anthropic says seven China-based labs mounted to strip the reasoning out of its frontier models and rebuild it in their own.
"Distillation attacks generally target US frontier models' most valuable capabilities, including agentic capabilities and tool use, coding and data analysis, and logical reasoning," Anthropic wrote in its September 2026 threat intelligence report, published Sept. 10. Jacob Klein, the company's head of threat intelligence, said in an interview that model capability has moved faster than the defenses around it. "A year ago, let's say you wanted to optimize a drone or optimize the software on a missile, the models just wouldn't be as good at that task as they are now," he said.
The disclosure names Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. The mechanics differ by lab. Alibaba's pipeline injected a fixed prompt forcing Claude to write its reasoning traces inside inline tags, then converted those transcripts into supervised fine-tuning data used to train Qwen 3.5, 3.6 and 3.7 — more than 151 million exchanges observed between May and July 2026, launched from over 3,500 fraudulent accounts. Moonshot relayed almost 300,000 customer requests to Claude over ten days through 5,380 fraudulent accounts while displaying Claude's answers to users who believed they were querying Kimi. DeepSeek logged more than 12.1 million exchanges in 14 days in July 2026 using the same cross-session replay technique. Zhipu ran 770,609 exchanges through a chain-of-thought cleaner in ten days ahead of its GLM 5.3 release. Xiaomi routed more than 400,000 requests across more than 1,500 accounts. SenseTime's pipeline included Claude transcripts bought from third-party data vendors, and MiniMax built a proxy network through a shell company that offers only Anthropic and OpenAI models.
The economics explain the motive. Distillation lets a lab extract frontier reasoning at a fraction of the compute, time and cost of independent development — the same logic that makes legitimate distillation a standard training method. Anthropic said its own research shows a model distilled from a frontier system can reach dangerous capabilities in biological or cyber domains even when the harvested exchanges contain little on those subjects, because general reasoning transfers across tasks. The safeguards that block misuse of Claude do not transfer with it.
The relay problem is a data problem
The more consequential finding may be what traveled alongside the prompts. Anthropic said Moonshot, DeepSeek and Xiaomi fed conversations between their own models and their users into Claude without those users' knowledge. The relayed traffic included names, email addresses, corporate data and live credentials — Anthropic cited a Russian government database credential and a PRC police case-management system exposed in DeepSeek's relay, and CCTV surveillance data from hundreds of cameras in Chengdu, including cameras outside PLA facilities, in Moonshot's. Anthropic said the practices are likely inconsistent with privacy laws and the labs' own terms of service.
That reframes the story from IP theft to third-party data exposure. Any enterprise routing prompts through a Chinese model API now has a disclosure question it did not have last week, and the affected parties — multinationals, state-affiliated users, US and European developers on third-party routers — were never told their sessions were being forwarded.
Anthropic's countermeasures are layered rather than absolute. It attributes proxy networks by metadata, runs extraction classifiers strengthened alongside the Fable 5 launch, summarizes internal reasoning so stolen transcripts are less useful for training, and with Fable 5.1 introduced preserved thinking that stops new API accounts from altering the system prompt or prior messages. Accounts showing abuse signals can be forced through identity verification and banned on failure. The company said it has not observed distillation attempts against Mythos 5 or Mythos Preview, which are not generally accessible.
The regulatory read-through is where the money sits. Anthropic's report lands in an election-season Washington already primed to treat frontier-model access as a national-security question, and it supplies the evidentiary spine for tighter API access rules, stricter know-your-customer requirements on model providers, and expanded export controls covering model weights and inference access rather than just chips. Nvidia, whose data center revenue depends on Chinese demand at the margin, and US labs selling into global developer markets both face a narrower addressable funnel if access controls tighten. The counterweight is commercial: Anthropic, OpenAI and Google all monetize API access, and verification friction raises their own cost of serving legitimate overseas developers.
For investors, the near-term signal is less about Chinese model quality than about the durability of the US frontier moat. If a competitor can harvest 151 million exchanges in a quarter, the moat is a function of enforcement, not architecture — which argues for pricing AI security, identity verification and provenance tooling as a growth line rather than a compliance cost. Anthropic did not disclose revenue impact or the number of accounts banned beyond the campaign figures. Alibaba did not immediately respond to a request for comment.
This article is for informational purposes only and does not constitute investment advice.