Anthropic alleges large-scale Claude distillation campaigns

Anthropic reports five alleged distillation campaigns
Anthropic has alleged that China-based AI companies conducted persistent attempts to extract capabilities from Claude, identifying nearly 200 million exchanges across five separate distillation campaigns. The company said the activity had escalated over recent months as competition in AI intensified.
The campaigns targeted capabilities Anthropic considers especially valuable: agentic behaviour and tool use, coding and data analysis, and logical reasoning. Anthropic said unauthorised labs had developed increasingly sophisticated methods to circumvent its defences and harvest the capabilities of US frontier models.
Alibaba-linked activity accounted for 151 million exchanges
The largest campaign was attributed by Anthropic to Alibaba and described as the biggest wholesale distillation effort it has observed. Anthropic recorded 151 million exchanges from May to July 2026, with activity peaking at nearly three million exchanges a day.
The requests were distributed across 3,500 accounts. Anthropic nevertheless attributed them to one effort because the accounts shared a fixed prompt designed to extract chain-of-thought material, which it said could have been used as training data for Alibaba’s Qwen model family.
Distillation attacks seek to obtain the reasoning process behind a model’s response and use it for supervised fine-tuning of a smaller model. Claude normally presents users with summarised thinking rather than its internal chain of thought. Anthropic said the identified campaigns found ways to prompt the model into exposing more direct reasoning traces, including by disguising a request as a translation task.
Moonshot AI campaign allegedly involved military-routed requests
Anthropic also attributed a campaign to Moonshot AI, the maker of Kimi, and said it appeared to route requests directly from the Chinese military. One request asked Claude to assess closed-circuit surveillance footage and determine whether a subject was behaving abnormally.
Over a ten-day period, Anthropic said nearly 300,000 requests reached Claude through a network of 5,000 accounts, primarily targeting its Opus model. The allegations add operational context as Anthropic and OpenAI at AI Stage TechCrunch Disrupt 2026 brings Anthropic and OpenAI into the industry conversation around frontier AI, competition and model capabilities.
What businesses should take from the report
For organisations providing or procuring advanced model access, the report highlights the importance of monitoring coordinated account activity, repeated prompt structures and unusually high-volume requests. Controls around sensitive reasoning outputs and tools need to be paired with investigation processes that can identify campaigns spread across many accounts.

