Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic has identified and disrupted a widespread campaign by seven China-based AI labs to illegally extract capabilities from its Claude model through a process called industrial-scale distillation. These labs, including Alibaba, Moonshot, DeepSeek, and Zhipu, utilized proxy services and purchased user transcripts to replicate Claude's abilities in their own models, often involving thousands of fraudulent accounts and sophisticated techniques to bypass restrictions. Anthropic has taken measures to counter this activity, including banning reseller accounts and implementing technical safeguards like encrypted reasoning to hinder the usefulness of stolen data. The company also noted that U.S. intelligence agencies have previously accused China-based AI companies of similar activities.
Anthropic announced on Thursday that it has been actively combating a significant campaign of illicit distillation attacks targeting its Claude AI model, originating from seven China-based AI labs. This campaign, dubbed ‘industrial-scale distillation,’ involves replicating Claude’s capabilities in other models without authorization. The attacks are facilitated by proxy services and the purchase of user transcripts, effectively creating a secondary market for stolen AI knowledge.
These labs, including Alibaba, Moonshot, DeepSeek, Zhipu (aka Z.ai), and MiniMax, employ a range of techniques to circumvent Anthropic’s access restrictions. They utilize thousands of fraudulent accounts, often obtained through stolen credit cards and API keys, to route requests through proxy services and purchase conversations directly from third-party resellers. The activity has been ongoing since February 2026, with six distinct campaigns identified, including the ‘GTG-16005’ campaign, which involved 3 million exchanges per day from over 3,500 fraudulent accounts targeting agentic tasks.
Anthropic has responded by banning reseller accounts and accounts operating from unsupported regions like China, Iran, and Russia, and by implementing technical defenses. Notably, the company has updated Claude to summarize its internal reasoning before responding, making stolen transcripts less valuable for training. Furthermore, the introduction of ‘preserved thinking’ in Fable 5.1 prevents new API accounts from altering the system prompt, tools, or messages preceding Claude’s reasoning, encrypting the reasoning process and making it harder to extract useful information.
This development follows earlier accusations from U.S. cybersecurity and intelligence agencies, who allege that China-based AI companies are systematically extracting proprietary functionalities from American frontier models. The scale of the illicit activity highlights a growing concern about the potential for AI capabilities to be misappropriated and used in ways that could undermine innovation and national security.
