Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
Sep 10, 2026, 1:57 PM · TechCrunch

Anthropic says China-based labs ran industrial-scale distillation against Claude—nearly 200 million exchanges—harvesting chain-of-thought traces the company tried to keep sealed.
Why it matters
Anthropic released a report alleging persistent, increasingly sophisticated distillation attacks by China-based AI companies aiming to harvest capabilities from U.S. frontier models. Across five campaigns, the company says it saw nearly 200 million exchanges tied to distillation—targeting agentic behavior and tool use, coding and data analysis, and logical reasoning.
The largest effort, attributed to Alibaba, allegedly produced about 151 million exchanges between May and July 2026, peaking near three million a day across roughly 3,500 accounts that shared a fixed extraction prompt—material Anthropic links to training for Alibaba’s Qwen models. A separate Moonshot AI campaign, tied to the Kimi maker, allegedly routed on the order of 300,000 requests over ten days through about 5,000 accounts, mostly at Opus, including at least one ask that looked like military-surveillance analysis.
This is no longer a footnote about scrapers. It’s an allegation that geopolitical competitors are treating frontier APIs as unpaid teachers for rival model families.
From the desk
We’re treating this as a security story first and a trade story second. Distillation here means tricking a model into spilling chain-of-thought traces, then using those traces to fine-tune a smaller student model. Anthropic normally shows users summarized thinking, not the raw internal trace. Attackers allegedly found prompts—including a katakana-only “translator” frame—that pulled the working memory out anyway.
Scale is the tell. Tens of millions of exchanges with a shared extraction prompt is not a curious researcher. It’s a factory. If Anthropic’s attribution holds, Alibaba’s campaign alone is industrial espionage by another name—conducted through the front door of an API product. Moonshot’s alleged volume and the surveillance-style query raise a sharper alarm: frontier assistants can be turned into sensors for someone else’s state if account networks and routing aren’t cut fast.
OpenAI has already publicly tied similar activity to DeepSeek; Anthropic’s February warnings named labs too. Thursday’s report is bigger and more aggressive by Anthropic’s own comparison. Useful open competition and open-weight progress are healthy. Covertly stripping a closed model’s reasoning traces to clone its edge is not the same thing, and pretending it is only rewards the attacker.
The downside for everyone building useful AI: tighter rate limits, harder CoT concealment, more nationality and KYC friction, and a chill on legitimate research access. Labs will harden. Regulators will notice. Users will feel the locks.
I’m watching whether Anthropic publishes enough technical detail for defenders without giving attackers a cookbook—and whether Alibaba, Moonshot, or others answer the attribution on the record. Until then, the likelier read is that API distillation has graduated from nuisance to organized capability transfer.
Context
TechCrunch’s September 10 report summarizes Anthropic’s Thursday disclosure. The piece notes prior Anthropic comments in February and OpenAI’s earlier attribution of similar activity to DeepSeek. The article details Alibaba and Moonshot campaigns most fully among the five Anthropic says it observed.
Who feels it
- Anthropic and other frontier labs
- Pressure to harden CoT concealment, detect multi-account extraction, and possibly restrict access patterns that look like wholesale distillation.
- Alibaba, Moonshot AI, and named peers
- Public attribution of industrial-scale campaigns invites diplomatic, commercial, and reputational blowback whether or not they formally respond.
- API customers and researchers
- Expect stricter abuse detection, possible friction for high-volume or unusual prompting, and less visibility into model reasoning.
- Policymakers
- Fresh case study for export controls, API access rules, and debates over whether model-capability theft via distillation needs a clearer legal frame.
What to watch
- Whether Alibaba or Moonshot AI issue on-the-record responses to Anthropic’s attribution
- Follow-on technical posts from Anthropic on detection and CoT-protection changes without publishing exploit recipes
- Similar campaign disclosures from OpenAI, Google, or others naming volumes and methods
- Product changes—rate limits, account verification, or thinking-trace behavior—rolled out in the wake of the report
Companies: Anthropic