Chinese AI Labs Hit Anthropic with 190M Distillation Attacks
DeepSeek, Moonshot, Alibaba, and others allegedly used Claude outputs to train competing models, exposing sensitive government data in the process.

Major Chinese AI Companies Targeted Claude
Anthropic disclosed Thursday that five leading Chinese AI laboratories conducted nearly 190 million distillation attacks against its Claude model during a three-month period this summer. The campaign involved Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi systematically extracting outputs from Claude to improve their own competing AI systems.
Distillation attacks exploit advanced AI models by feeding them queries and using the responses as training data for less capable models. The practice allows competitors to capture the knowledge and reasoning capabilities of frontier systems without investing in the underlying research and compute resources.
According to Anthropic's report, DeepSeek and Moonshot AI redirected their own users' requests to Claude rather than processing them through their native models. Moonshot rerouted 23 million queries between May and July, while DeepSeek redirected 12.1 million requests during a two-week span in July alone.
Sensitive Government Data Exposed
The redirection scheme inadvertently exposed classified information from Chinese and Russian government sources. Anthropic documented instances where requests meant for Chinese AI assistants instead flowed through Claude, including CCTV surveillance footage uploaded by a user affiliated with the People's Liberation Army through Moonshot's Kimi interface. A Russian military contractor also submitted details about a Russian government database that ended up processed by Claude.
Alibaba conducted what Anthropic characterized as the largest distillation attack the company has ever measured. Over 151 million exchanges occurred between May and July, orchestrated through 3,500 fraudulent accounts. These accounts specifically prompted Claude to articulate its reasoning processes, which Alibaba then used to train its Qwen model family.
Xiaomi took a different approach, recording actual user conversations with its MiMo models and feeding those dialogues into Claude to generate training datasets. Anthropic also flagged Z.ai—recently notable for its Ox Alpha model—for conducting attacks similar to Alibaba's operation.
Why It Matters
The scale of these attacks highlights a fundamental tension in AI development: frontier labs invest billions in compute and research, while competitors can potentially shortcut that investment by systematically harvesting outputs. For enterprise leaders evaluating AI vendors, this episode underscores questions about model provenance and the security implications of data routing through undisclosed third-party systems. The inadvertent exposure of government and military data also demonstrates how AI supply chains can create unexpected intelligence risks.
New Safeguards Implemented
In response, Anthropic has deployed multiple countermeasures. The company now bans suspicious activity patterns, reduced the detail level in Claude's reasoning transcripts to make them less useful for training purposes, and implemented identity verification requirements for users appearing to operate from China, Russia, or Iran—jurisdictions where Claude is not officially available.
None of the named Chinese companies responded to requests for comment from Business Insider. Anthropic also did not provide additional comment beyond its published report.
This marks Anthropic's second public disclosure about Chinese distillation campaigns. In June, the company's head of policy Sarah Heck told lawmakers that Alibaba had conducted 28.8 million illicit exchanges with Claude between late April and early June, urging legislation to address such attacks.
These details were first reported by Business Insider.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call