Anthropic Disrupts China-Based Claude Distillation Campaigns — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic identified and disrupted industrial-scale illicit distillation attacks against Claude from seven China-based AI labs: Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu), Xiaomi, SenseTime, and MiniMax.
- The largest campaign, GTG-16005, was run by Alibaba-affiliated operators and generated 151 million exchanges between May and July 2026, peaking at roughly 3 million exchanges per day from more than 3,500 fraudulent accounts targeting chain-of-thought reasoning in Claude Opus 4.6 and 4.7.
- Moonshot AI (GTG-16002) stealthily rerouted approximately 300,000 customer requests to Claude over 10 days through 5,380 fraudulent accounts mostly located in Singapore and Japan, then displayed Claude's responses to users as if they came from its own Kimi model.
- DeepSeek (GTG-16001) silently relayed more than 12.1 million exchanges to Claude over 14 days in July 2026 without informing customers, while Zhipu/Z.ai (GTG-16006) extracted 3.4 million exchanges through 273 rotating fraudulent accounts.
- The unauthorized labs gained access via proxy networks using fake or stolen credit cards and illegally harvested API keys, with some captured exchanges containing sensitive information from individual users, multinational companies, and state-affiliated actors.
- Anthropic is responding by banning reseller accounts and accounts from unsupported regions (China, Iran, Russia), updating Claude to summarize internal reasoning before responding, and introducing encrypted reasoning with Fable 5.1 to block prompt manipulation.
- Earlier this week, U.S. cybersecurity and intelligence agencies formally accused China-based AI companies of conducting "systematic extraction" of proprietary functionalities from American frontier models.
Why it matters: With 151 million exchanges in a single Alibaba-linked campaign, the scale of capability theft dwarfs typical IP disputes and matches what U.S. agencies now publicly call "systematic extraction" — converting distillation from a legal gray area into a national-security flashpoint between U.S. and Chinese frontier AI labs.
Ask SkimNews


