VMTech
Discuss a project

Anthropic Details Large-Scale Claude Distillation Campaigns

Anthropic Details Large-Scale Claude Distillation Campaigns

Anthropic identifies seven China-based labs in Claude extraction activity

Anthropic said it identified and disrupted illicit, industrial-scale attempts to distill the capabilities of its Claude models by seven China-based AI labs. The company named Alibaba, Moonshot AI, DeepSeek, Z.ai, also known as Zhipu, MiniMax, Xiaomi and SenseTime. It said the activity involved proxy networks, fraudulent accounts and, in some cases, the collection of user interactions for training purposes.

The largest campaign, tracked as GTG-16005 and attributed to a cluster of Alibaba-affiliated operators, produced 151 million observed exchanges from May through July 2026. Anthropic described it as the largest distillation attack it has measured. The operation peaked at roughly 3 million exchanges per day, used more than 3,500 fraudulent accounts, and targeted chain-of-thought reasoning transcripts from Claude Opus 4.6 and 4.7.

Anthropic said the Alibaba-linked activity focused on agentic tasks, software engineering, kernel development and long-horizon tasks. Knowledge distillation is a legitimate machine-learning method in which a larger model teaches a smaller or faster model. Anthropic distinguished that practice from unauthorized extraction intended to replicate a model’s capabilities without permission.

Proxy networks and rerouted requests created collection paths

Anthropic said unauthorized operators commonly routed requests through proxy, transfer or relay services. These networks can create thousands of accounts using fictitious identities, fake or stolen payment cards, and illegally obtained API keys belonging to companies or individuals. The company also said some resellers retain conversations without users’ knowledge or consent and sell the transcripts to other labs.

GTG-16002 involved 23 million exchanges between May and July 2026. Anthropic said Moonshot AI covertly relayed customer requests to Claude instead of processing them through Kimi, returned Claude responses to customers, and retained part of the activity to train a chain-of-thought model. Over 10 days, the company said, nearly 300,000 requests were sent through a proxy network using 5,380 fraudulent accounts, most located in Singapore and Japan.

Anthropic attributed more than 12.1 million exchanges over 14 days in July to DeepSeek, which it said used a similar request-relaying approach. It said Zhipu operated a chain-of-thought extraction pipeline involving more than 3.4 million exchanges over 17 days and 273 fraudulent accounts. Xiaomi was linked to more than 400,000 exchanges involving MiMo conversations and coding sessions sent through OpenClaw and OpenCode harnesses.

Anthropic changes access controls and reasoning protections

The company said SenseTime bought Claude user-exchange transcripts from third-party data vendors. MiniMax allegedly built a proxy service through a shell company offering access to Anthropic and OpenAI models, potentially creating a channel to gather interactions with U.S. frontier models.

Anthropic said it bans reseller accounts and accounts operating in unsupported regions, including China, Iran and Russia, when identity verification fails. It has also changed Claude to summarize internal reasoning before answering, a measure intended to make captured transcripts less useful for subsequent training. The company added that Fable 5.1 introduced preserved thinking, which prevents new API accounts from altering the system prompt, tools or messages before Claude’s reasoning in multi-turn conversations.

For businesses using frontier-model APIs, the disclosure makes identity verification, API-key protection and monitoring for unusual relay patterns operational priorities. Organizations should also assess whether third-party services can retain, redirect or resell their AI conversations before sending sensitive customer, corporate or research data through them.

#aisecurity#anthropic#apikeysecurity#dataprivacy
Open analytics
On the site 0 views
min read 4 11.09.2026
Instagram

Anthropic Details Large-Scale Claude Distillation Campaigns

Open the post on Instagram ↗