"DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude," Anthropic said.
Anthropic names seven China-based labs and describes the threat
Anthropic reported that it identified and disrupted "industrial-scale illicit distillation attacks" against its Claude models carried out by seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. The company drew a strict line between legitimate knowledge distillation — a teacher-student training technique — and the illicit variety it says it observed: covert, large-scale extraction and replication of a model's capabilities without authorization.
How the illicit distillation campaigns worked: proxies, fake accounts, and harvested transcripts
According to Anthropic, unauthorized labs accessed Claude by routing requests through proxy services — also described as transfer or relay stations — that create thousands of accounts under fictitious identities and use fake or stolen credit cards and illegally harvested API keys. The company said some proxy operators both provided Claude access to users in unsupported regions and saved exchanges to sell them on a secondary market.
Anthropic added that unauthorized labs also acquired transcripts of user exchanges by purchasing them from third-party resellers — the operators of proxy services who save conversations "without the users' knowledge or consent." In other cases, labs allegedly rerouted requests from their users to Claude "— without the knowledge or permission of those users — to harvest exchanges between users and Claude for training." Some harvested conversations, Anthropic said, included sensitive information from individual users, major multinational companies, and state-affiliated actors.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSeven tracked campaigns and their scale
- GTG-16005: Anthropic described this cluster—linked to Alibaba-affiliated operators—as "the largest distillation attack we have ever measured." Between May and July 2026, Anthropic observed 151 million exchanges targeting chain-of-thought (CoT) reasoning transcripts from Claude Opus 4.6 and 4.7. It peaked at roughly 3 million exchanges per day launched from more than 3,500 fraudulent accounts and focused on agentic tasks, software engineering, kernel development, and long-horizon tasks.
- GTG-16002: Between May and July 2026 Anthropic observed 23 million exchanges in which Moonshot AI allegedly rerouted customer requests to Claude rather than processing them using its Kimi model, displayed Claude's responses to users, and saved a subset of those responses to train a CoT model. Over a 10-day period Moonshot is said to have relayed almost 300,000 customer requests to Anthropic using a proxy service network of 5,380 fraudulent accounts, most located in Singapore and Japan.
- GTG-16001: DeepSeek is accused of the same silent-relay approach, with more than 12.1 million exchanges observed over 14 days in July 2026 to extract CoT transcripts.
- GTG-16006: Zhipu (aka Z.ai) ran a CoT extraction pipeline and replayed Claude reasoning traces through Claude to train its models, Anthropic says, with more than 3.4 million exchanges observed over 17 days in June and July 2026 using 273 fraudulent accounts.
- GTG-16008: Xiaomi reportedly replayed user conversations and coding sessions from its MiMo models to Claude through OpenClaw and OpenCode coding harnesses; Anthropic observed more than 400,000 exchanges over 20 days in March and April 2026.
- GTG-16012: Anthropic says SenseTime purchased transcripts of user exchanges with Claude from third-party data vendors.
- GTG-16003: MiniMax allegedly built its own proxy network service through a shell company that offers access to models developed by Anthropic and OpenAI, likely to collect exchanges between users and U.S. frontier models to train its models, Anthropic stated.
Defensive steps Anthropic has deployed
Anthropic described a mix of account controls and model-level changes to blunt illicit distillation. The company said it bans reseller accounts or accounts operating from unsupported regions like China, Iran, and Russia when users fail to verify their identity. To reduce the value of stolen transcripts, Anthropic updated Claude to summarize its internal reasoning before responding, "thereby making stolen transcripts less useful for follow-on training."
Anthropic also highlighted a change introduced with Fable 5.1 called "preserved thinking," which "stops new API accounts from altering the system prompt, tools, or messages that precede Claude's reasoning in multi-turn conversations." Anthropic added that the reasoning is encrypted and noted that "editing the context before it is a common technique attackers use to make Claude reveal it."
What this means for technologists, U.S. cybersecurity agencies, and affected enterprises
- Technologists and security teams: Watch for large-scale proxy networks, fraud-based account creation, stolen API keys, and prompt-manipulation tricks that aim to capture chain-of-thought and tool-use transcripts — the precise capabilities Anthropic says attackers targeted.
- U.S. cybersecurity and intelligence agencies: Anthropic noted that earlier this week these agencies accused China-based AI companies of conducting "systematic extraction" of proprietary functionalities; Anthropic also said it took down accounts that attempted surveillance of citizens and research that could support biological-weapons development.
- Affected enterprises and users: Anthropic reports that some captured exchanges contained sensitive information from major multinational companies and state-affiliated actors, and that a secondary market has emerged in which harvested conversations are bought and sold.
Anthropic's disclosure lays out a technical playbook and a market for harvested model interactions: proxy services that create fraudulent identities, secondary resellers that sell transcripts, and large-scale replay and distillation campaigns measured in the tens — and in one case hundreds — of millions of exchanges. The company has deployed account-level bans, encrypted internal reasoning, and the Fable 5.1 "preserved thinking" control, but the report itself emphasizes attackers are using "increasingly sophisticated methods" to evade defenses. Will the combination of account controls, encrypted reasoning, and architectural safeguards be enough to keep pace with distillation campaigns run at industrial scale? That, Anthropic's findings imply, is the next hard question for defenders and regulators alike.




