Anthropic Reports Massive Distillation Attacks from Alibaba, Moonshot AI, DeepSeek

Original: Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek

Why This Matters

These campaigns highlight escalating IP extraction risks threatening US frontier AI developers' competitive advantages.

Anthropic released a report on September 10, 2026, alleging large-scale distillation attacks by China-based AI companies including Alibaba, Moonshot AI, and DeepSeek, totaling nearly 200 million exchanges across five separate campaigns in recent months.

Anthropic's new report alleges that China-based AI companies have conducted escalating distillation attacks against its Claude models. In total, the company observed nearly 200 million exchanges linked to five separate campaigns. Distillation attacks involve extracting a model's internal chain of thought to train smaller models via supervised fine-tuning. While Anthropic only displays 'summarized thinking' blocks to users, attackers found techniques to reveal full thinking traces — including one tactic that framed queries as translation requests into katakana-only Japanese.

The largest campaign was attributed to Alibaba, comprising 151 million exchanges between May and July 2026, peaking at nearly 3 million exchanges per day across 3,500 accounts. Anthropic believes the data was used to train Alibaba's Qwen model family. A separate campaign attributed to Moonshot AI — maker of Kimi — appeared to route requests from the Chinese military, including one request to analyze surveillance footage for abnormal behavior. Over 10 days, nearly 300,000 requests were sent through 5,000 accounts, targeting Anthropic's Opus model. Anthropic previously identified distillation attacks in February 2026; OpenAI has reported similar activity attributed to DeepSeek.

Source

techcrunch.com — Read original →