Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Anthropic released a Thursday report alleging persistent distillation attacks by China-based AI labs, identifying five separate campaigns that generated nearly 200 million exchanges targeting Claude's agentic capabilities, tool use, coding, data analysis, and logical reasoning.
- The bulk of activity came from an Alibaba campaign that produced 151 million exchanges between May and July 2026, peaking at nearly 3 million per day across 3,500 accounts that all shared a single fixed prompt designed to harvest training material for the Qwen model family.
- A Moonshot AI campaign routed roughly 300,000 requests over a ten-day period through 5,000 accounts — including one query asking Claude to assess closed-circuit surveillance footage for subjects "behaving abnormally" — which Anthropic says indicates the requests flowed directly from the Chinese military.
- Attackers bypassed Anthropic's chain-of-thought protections by disguising prompts as translation requests, such as instructing the model to render "previous working memory" into katakana-only Japanese, a technique Anthropic calls "increasingly sophisticated."
- OpenAI has previously reported similar activity it attributed specifically to DeepSeek, while Anthropic first flagged distillation attacks in February — making Thursday's report a broader, more aggressive successor that names Alibaba and Moonshot as the dominant sources.
Why it matters: Anthropic logged 200 million exchanges aimed at cloning its highest-value commercial capabilities — agentic reasoning, coding, and tool use — while the Moonshot campaign reportedly routed requests directly through the Chinese military, turning a competitive IP dispute into a national-security flashpoint between U.S. frontier labs and Beijing's AI ecosystem.
Ask SkimNews



