.##....##.########.##......##..######.....########..#######..########.....###....##....##
.###...##.##.......##..##..##.##....##.......##....##.....##.##.....##...##.##....##..##.
.####..##.##.......##..##..##.##.............##....##.....##.##.....##..##...##....####..
.##.##.##.######...##..##..##..######........##....##.....##.##.....##.##.....##....##...
.##..####.##.......##..##..##.......##.......##....##.....##.##.....##.#########....##...
.##...###.##.......##..##..##.##....##.......##....##.....##.##.....##.##.....##....##...
.##....##.########..###..###...######........##.....#######..########..##.....##....##...

All signal, no noise, 24/7.
Built for Humans & AI Agents.

Anthropic, the U.S.-based artificial intelligence company, has released a comprehensive threat intelligence report detailing how several Chinese AI laboratories reportedly engaged in large-scale, unauthorized use of its Claude model outputs. The company stated that these actions constituted “illicit distillation”—a practice involving using the outputs of a powerful AI system to train and replicate the capabilities of a competing model without proper authorization.

Scope and Methodology of Misuse

Anthropic reported detecting and disrupting these unauthorized efforts between December 2025 and August 2026. The company noted that the exchanges utilized by these labs contained sensitive information, potentially sourced from individual users, large multinational corporations, and state-affiliated actors. Anthropic stated that such practices were likely incompatible with both established privacy laws and the respective AI labs’ terms of service.

The overall scope of the report covers seven areas of misuse, including cyber operations, influence operations, surveillance, fraud and scams, biological misuse, conventional weapons development, and model distillation.

Alibaba and Qwen Model Training

According to the report, operators affiliated with Alibaba utilized Claude’s outputs to assist in training its Qwen models. This operation represented the largest distillation campaign Anthropic had measured, involving over 151 million exchanges with Claude between May and July. The activity reportedly peaked at a rate of nearly 3 million exchanges per day, originating from more than 3,500 accounts identified by the company as fraudulent. Beyond this, Alibaba was also observed using Claude for broader AI research, including reinforcement learning and model architecture development.

Moonshot AI and Kimi Model Requests

The report also detailed activity involving Moonshot AI, the Beijing-based developer of the Kimi family of AI models. Moonshot was found to have silently redirected certain user queries intended for Kimi to Claude. Users were reportedly shown Claude’s responses, leading them to believe they were interacting with the Kimi model. In one ten-day period alone, Moonshot channeled nearly 300,000 customer requests to Anthropic. The majority of these requests were routed to Claude Opus models through a network of 5,380 accounts, most of which appeared to be situated in Japan and Singapore.

Anthropic described these accounts as fraudulent and noted that Moonshot subsequently saved these exchanges, extracting Claude’s reasoning transcripts to serve as training data for its own models. Between May and July, Anthropic attributed over 23 million exchanges to Moonshot.

DeepSeek and Third-Party Exploitation

A similar tactic was observed involving DeepSeek, a company that gained prominence last year due to its capabilities and cost-effectiveness. DeepSeek was reported to have used methods akin to Moonshot, passing exchanges to Claude without notifying the associated customers. Anthropic observed more than 12 million distillation attacks linked to DeepSeek over a period of 14 days during July 2026.

The company stated that it did not know whether Moonshot had informed its customers that their requests were being forwarded to Anthropic.

Alibaba, Moonshot, DeepSeek, and Xiaomi did not provide immediate comment when contacted by the publication.

Max

Written by

Max

Covers AI news, agentic AI, LLMs, and tech developments. When he is not writing, he is comparing open-source models' tokens per second just to see how they hold up.

+ , , ,