Claude attacks: Anthropic fingers seven China AI labs

Anthropic has accused seven China-based AI companies of running industrial-scale illicit distillation campaigns against its Claude frontier models, naming Alibaba, Moonshot AI, DeepSeek, Zhipu AI, Xiaomi, SenseTime and MiniMax as sources of the traffic.[2][3][7]

In a threat-intelligence report released on Thursday, the U.S. AI lab said it had identified and disrupted months-long efforts to extract Claude’s reasoning and cybersecurity capabilities at scale via tens of millions of API interactions routed through fraudulent accounts.[1][2][7]

Knowledge distillation is a standard machine-learning technique in which a powerful teacher model trains a smaller student by exposing it to curated question–answer pairs and reasoning traces.[1][10]

Anthropic argues that when rival labs systematically harvest a proprietary model’s outputs without consent to improve competing systems, the practice crosses the line into misuse and violates its terms of service and regional access restrictions.[1][11]

Previous disclosures in February detailed campaigns by DeepSeek, Moonshot and MiniMax that generated more than 16 million exchanges with Claude using roughly 24,000 fake accounts, activity the company characterized as unauthorized distillation.[1][5][11]

The latest report paints Alibaba’s Qwen division as the most aggressive actor, with Anthropic attributing more than 151 million Claude exchanges between May and July to a single coordinated distillation effort, peaking at nearly 3 million requests per day and targeting Opus 4.6 and 4.7 reasoning outputs to train Qwen 3.5, 3.6 and 3.7.[4][7][9]

In a separate letter to U.S. lawmakers earlier this summer, Anthropic described a six‑week campaign linked to Alibaba that used about 25,000 shell accounts to harvest 28.8 million interactions focused on software engineering, agentic reasoning and cybersecurity capabilities.[4][10][13]

Analysts estimate that across multiple Chinese labs, more than 45 million Claude exchanges have been siphoned through roughly 49,000 fraudulent accounts in recent months, underscoring how quickly model‑distillation can scale when abuse goes unchecked.[12][13][15]

Some labs are accused of quietly proxying user traffic from consumer chatbots to Claude, effectively serving Anthropic’s outputs under their own brand without disclosure, including alleged rerouting of hundreds of thousands of Kimi and DeepSeek requests via thousands of fake accounts.[2][3][9]

Technical write‑ups describe cross‑session replay attacks in which attackers save Claude’s intermediate “thinking” traces from one session and reconstruct them in another, allowing systematic extraction of chain‑of‑thought reasoning that can then be fed into their own training pipelines.[1][9][12]

Zhipu AI is said to have run dedicated pipelines to strip and clean Claude’s reasoning output and to target its cyber‑defense capabilities ahead of releasing GLM‑5.3, with millions of exchanges focused on security‑relevant prompts.[7][9]

Anthropic says it has now blocked the offending accounts, strengthened geographic access controls and deployed new behavioral detection systems tuned to spot high‑volume, low‑variance prompting patterns indicative of distillation rather than normal user traffic.[1][2][6]

The company also reports escalating the matter to regulators and industry partners, framing illicit distillation as an emerging form of AI industrial espionage that sits uncomfortably between traditional cybersecurity incidents and intellectual‑property disputes.[4][10][11]

For organizations operating large language model APIs, the case highlights the need to treat model outputs—especially chain‑of‑thought and cybersecurity content—as sensitive assets and to enforce rate limits, identity verification and anomaly detection on account creation and usage patterns.[1][12][15]

As policymakers debate new guardrails on frontier AI, Anthropic’s accusations against major Chinese labs are likely to fuel pressure for cross‑border access controls and clearer rules around what constitutes acceptable data collection from commercial models.[10][11][14]

References

  1. Detecting and preventing distillation attacks
  2. Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
  3. Anthropic accuses Chinese AI labs of illicit distillation attacks – Yahoo
  4. Anthropic says Alibaba illicitly extracted Claude AI model capabilities
  5. Anthropic accuses DeepSeek, Moonshot and MiniMax …
  6. Adversarial Attacks: Anthropic Says Chinese Labs Distilled …
  7. Anthropic Accuses Seven Chinese AI Companies of Using …
  8. Moonshot, DeepSeek Secretly Served Claude, Not Their Model …
  9. Distillation: The New U.S.–China AI Fight
  10. Anthropic’s distilling charges against Chinese firms expose …
  11. The Attack That Looked Like Nothing at All: Anthropic’s …
  12. The Distillation Game
  13. Anthropic Claims Alibaba Ran ‘Brazen’ Campaign to …
  14. China’s AI Labs Built a Purchasing Department for …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply