
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.
Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to train a smaller, less-capable or faster "student" model to copy its capabilities.
Illicit distillation, on the other hand, is an industrial-scale campaign that covertly extracts a model's capabilities and replicates them in another model without authorization, typically by making use of networks of fake accounts created with stolen credit cards, login credentials, and API keys.
Frontier AI labs in the West, including those from Google and OpenAI, have repeatedly called out distillation attacks aimed at their models. Anthropic said it has observed unauthorized labs employing "increasingly sophisticated methods" to get around defenses and harvest its capabilities, such as agentic capabilities and tool use, coding and data analysis, and logical reasoning, through prompt manipulation tricks.
"DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude," Anthropic said. "These labs then used Claude’s responses as training data with which to distill Claude's capabilities. Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors."
The AI company said these labs generally gain access to its models by routing requests through proxy services, also referred to as transfer or relay stations, which create thousands of new accounts under fictitious identities, fake or stolen credit cards, and illegally harvested API keys that belong to legitimate companies or individuals.
According to Anthropic, unauthorized AI labs also acquire transcripts of user exchanges with U.S. frontier models by purchasing them off third-party resellers, who are the operators of proxy services that save such conversations without the users' knowledge or consent.
"In other cases, unauthorized labs rerouted requests from their users to Claude -- without the knowledge or permission of those users -- to harvest exchanges between users and Claude for training," Anthropic pointed out.
Since February 2026, the AI company said it has detected six illicit distillation campaigns that were conducted by China-based AI labs to advance their own models -
- GTG-16005 (151 million exchanges observed between May and July 2026), in which a cluster of Alibaba-affiliated operators targeted the chain-of-thought (CoT) reasoning transcripts of Claude Opus 4.6 and 4.7 in what has been described as the "largest distillation attack we have ever measured." It peaked at roughly 3 million exchanges per day launched from more than 3,500 fraudulent accounts targeting agentic tasks, software engineering, kernel development, and long-horizon tasks.
- GTG-16002 (23 million exchanges observed between May and July 2026), in which Moonshot AI stealthily rerouted customer requests to Claude as opposed to processing them using Kimi, and then displayed responses from Claude to users. In tandem, a subset of these exchanges were captured and saved to train its CoT model. Over a 10-day period, Moonshot is said to have relayed almost 300,000 customer requests to Anthropic using a proxy service network of 5,380 fraudulent accounts, most of them located in Singapore and Japan.
- GTG-16001 (More than 12.1 million exchanges observed over 14 days in July 2026), in which DeepSeek followed the same approach as Moonshot AI to silently relay exchanges to Claude without informing its customers and extract CoT transcripts.
- GTG-16006 (More than 3.4 million exchanges observed over 17 days in June and July 2026), in which Zhipu (aka Z.ai) ran a CoT extraction pipeline and replayed Claude reasoning traces through Claude to train its models. The activity took place by rotating through 273 fraudulent accounts.
- GTG-16008 (More than 400,000 exchanges observed over 20 days in March and April 2026), in which Xiaomi replayed user conversations and coding sessions from its own MiMo models to Claude, through OpenClaw and OpenCode coding harnesses, to bolster training data used for future models.
- GTG-16012, in which SenseTime purchased transcripts of user exchanges with Claude from third-party data vendors.
- GTG-16003, in which MiniMax built its own proxy network service through a shell company that offers access to models developed by Anthropic and OpenAI, likely with an aim to collect exchanges between users and U.S. frontier models to train its models.
"The proliferation of proxy services to circumvent Anthropic access restrictions has created a secondary market through which labs can purchase or otherwise acquire harvested exchanges between users and Claude," Anthropic said. "Some proxy networks both provide Claude access to users in unsupported regions, and also save exchanges in order to sell them to other labs."
To counter illicit distillation, the company said it bans reseller accounts or accounts operating from unsupported regions like China, Iran, and Russia when users fail to verify their identity. To make it harder for unauthorized labs to distill Claude's capabilities, the model has been updated to summarize its internal reasoning before responding, thereby making stolen transcripts less useful for follow-on training.
"And with Fable 5.1 we introduced preserved thinking, which stops new API accounts from altering the system prompt, tools, or messages that precede Claude's reasoning in multi-turn conversations," the company added. "That reasoning is encrypted, but editing the context before it is a common technique attackers use to make Claude reveal it."
The development comes as Anthropic said it took down a number of accounts that tried to use its models to surveil their citizens and to research diseases in ways that could support biological weapons. Earlier this week, U.S. cybersecurity and intelligence agencies accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks.