Anthropic Disrupts Industrial-Scale Claude Distillation by China AI Labs
Anthropic disclosed on Thursday that it identified and disrupted industrial-scale illicit distillation attacks targeting Claude, tracing the activity to seven AI labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu), and MiniMax. While knowledge distillation is a legitimate training technique in which a larger "teacher" model trains a smaller "student" model, Anthropic characterized the operations it observed as covert campaigns designed to extract Claude's capabilities without authorization. The attackers used networks of fake accounts created with stolen credit cards, harvested credentials, and stolen API keys to route queries through proxy services and relay stations, a pattern security teams can flag using a VPN/proxy detector to identify anonymized infrastructure.
According to Anthropic, the targeted labs employed increasingly sophisticated prompt manipulation to harvest agentic capabilities, tool use, coding and data analysis skills, and logical reasoning. "DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude," Anthropic said, noting that some exchanges included sensitive data from individual users, multinational corporations, and state-affiliated actors. The attackers also rerouted user requests to Claude without consent and purchased user transcripts from third-party resellers operating proxy services that silently log conversations, a privacy violation that underscores why individuals should run a privacy checkup to audit their exposure.
Since February 2026, Anthropic has detected six illicit distillation campaigns. The largest, designated GTG-16005, was attributed to Alibaba-affiliated operators and involved approximately 151 million exchanges between May and July 2026, peaking at roughly 3 million exchanges per day launched from more than 16,000 distinct IP addresses. This campaign specifically targeted chain-of-thought reasoning transcripts from Claude Opus 4.6 and 4.7 in what Anthropic described as "the largest distillation attack we have ever measured." Other campaigns leveraged compromised API keys belonging to legitimate companies and individuals, highlighting the recurring risk of credential theft across the AI supply chain. As frontier model providers including Google and OpenAI face similar pressure, the incident signals an emerging front in AI security where commercial model theft is being industrialized at nation-state scale."