Anthropic Disrupts China-Based Claude Distillation Attacks — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic identified seven China-based AI labs—Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu), Xiaomi, SenseTime, and MiniMax—running illicit distillation attacks on Claude, detecting six campaigns since February 2026 and harvesting capabilities through prompt manipulation tricks aimed at coding, agentic tasks, and logical reasoning.
- The Alibaba-affiliated GTG-16005 campaign was 'the largest distillation attack we have ever measured,' generating roughly 151 million exchanges between May and July 2026 and peaking at about 3 million exchanges per day from more than 3,500 fraudulent accounts targeting chain-of-thought reasoning of Claude Opus 4.6 and 4.7.
- Moonshot AI (GTG-16002) stealthily rerouted nearly 300,000 customer requests to Claude over a 10-day period through 5,380 fraudulent accounts mostly in Singapore and Japan, then displayed Claude's responses to users of its Kimi model while capturing exchanges to train its own chain-of-thought model.
- DeepSeek (GTG-16001) silently relayed over 12.1 million exchanges to Claude across 14 days in July 2026 using the same rerouting tactic; Zhipu/Z.ai (GTG-16006) ran 3.4M+ exchanges through 273 rotating fraudulent accounts.
- Xiaomi replayed MiMo coding sessions to Claude via OpenClaw and OpenCode coding harnesses; SenseTime purchased Claude transcripts from third-party vendors; MiniMax built its own proxy network through a shell company that also resold access to Anthropic and OpenAI models.
- Some captured exchanges contained 'sensitive information, including from individual users, major multinational companies, and state-affiliated actors'—a user-data exposure angle largely buried beneath the headline-grabbing IP-theft framing.
- Anthropic is fighting back by updating Claude to summarize its internal reasoning before responding and, in Fable 5.1, introducing 'preserved thinking' that encrypts reasoning and blocks new API accounts from editing the system prompt, tools, or preceding messages.
Why it matters: With U.S. cybersecurity and intelligence agencies already accusing China-based AI firms of 'systematic extraction' of American frontier models, Anthropic's disclosure of roughly 151 million illicit exchanges from a single Alibaba-linked campaign quantifies how aggressively Chinese labs are mining U.S. AI capabilities—and explains why Anthropic now bars accounts from China, Iran, and Russia and is hardening Claude's reasoning traces against extraction.
Ask SkimNews



