Claude AI
Anthropic said Chinese AI labs including Alibaba, DeepSeek and Moonshot used millions of exchanges with its Claude models to help train and improve their own AI systems. Unsplash

Chinese artificial intelligence companies including Alibaba, DeepSeek and Moonshot AI used millions of exchanges with Anthropic's Claude to help train and improve their own models, Anthropic said. The company claims they sought to extract capabilities from its most advanced systems to advance their own.

Anthropic went on to describe "distillation" campaigns by seven China-based AI labs. The findings were included in the company's latest threat intelligence report, which covers misuse detected between December 2025 and August 2026.

Distillation is a widely used AI training technique in which outputs from a more capable model are used to train another model. Anthropic has previously described the technique itself as legitimate, including when companies use their own larger models to develop smaller ones, but said competitors violated its terms by using fraudulent accounts and other methods to extract Claude's capabilities without authorization.

Alibaba was responsible for the largest distillation operation Anthropic said it has measured, with more than 151 million Claude exchanges detected between May and July. Activity peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, with the requests targeting software engineering, agentic tasks, kernel development and other complex work.

Operators affiliated with Alibaba targeted reasoning transcripts from Anthropic's Opus 4.6 and 4.7 models and converted them into data that could be used for supervised fine-tuning, Anthropic said. The company linked the resulting data to the training of Alibaba's Qwen 3.5, 3.6 and 3.7 models.

Anthropic said Alibaba also used Claude for other AI research, including work on reinforcement-learning environments, model architecture and internal infrastructure used for model development.

The operation initially relied on nearly 5,000 fraudulent accounts using residential proxies, disposable email addresses and virtual-card payments to obscure their access, according to the report. Anthropic said the traffic shifted to a second pool of accounts after it blocked the first group.

DeepSeek was linked to more than 12.1 million exchanges over a 14-day period in July. Anthropic said the Chinese AI developer targeted Claude Opus reasoning traces and developed a system to extract transcripts that Anthropic's technical controls were designed to prevent users from obtaining.

Some DeepSeek customer requests were also silently routed to Claude, Anthropic said. The company said users believed they were interacting with DeepSeek models and were likely unaware that information they submitted was being sent to Anthropic.

The data included internal documents from a Chinese technology company and requests from an IT operator working with information from a Russian government agency associated with the country's Defense Ministry, according to Anthropic. The latter included active credentials for a Russian government database. Engineers developing a case-management system for a Chinese municipal Public Security Bureau also had requests relayed through Claude, the report said.

Moonshot AI, the Beijing-based developer of the Kimi models, was linked to more than 23 million Claude exchanges between May and July. Anthropic said Moonshot sometimes forwarded customer requests to Claude instead of processing them with Kimi and then showed Claude's responses to users as if they had come from Moonshot's model.

Nearly 300,000 customer requests were relayed to Anthropic during one 10-day period, mostly to Claude Opus models, through a network of 5,380 accounts that Anthropic identified as fraudulent. The company said Moonshot saved at least some of the exchanges and extracted Claude reasoning transcripts to use as training data.

Some of those requests contained sensitive information. Anthropic said one user it assessed as likely affiliated with China's People's Liberation Army submitted surveillance information from hundreds of cameras in Chengdu while believing it was being processed by Kimi. Another user at a major Chinese state-owned enterprise submitted internal code and active credentials belonging to several companies.

Anthropic said it did not know whether Moonshot informed customers that their requests were being sent to a third party.

The report also detailed activity attributed to other Chinese developers, including Xiaomi and Zhipu, which operates internationally as Z.ai. Anthropic linked Xiaomi to more than 400,000 exchanges during a 20-day period in March and April and said some of the traffic included names, contact information and corporate data belonging to users of third-party model-routing services.

The latest findings expand on distillation campaigns Anthropic disclosed in February, when it said DeepSeek, Moonshot and MiniMax generated more than 16 million Claude exchanges through approximately 24,000 fraudulent accounts. Those operations also targeted Claude's reasoning and coding capabilities, the company said.

DeepSeek on Thursday released its V4.1-Flash model, which the company said offers faster inference and higher throughput, while Moonshot released its Kimi K3 model in July.

U.S. officials this week separately accused six Chinese AI companies, including DeepSeek, Moonshot and Alibaba, of conducting large-scale distillation campaigns targeting American models. The officials said the companies had targeted systems developed by Anthropic, OpenAI, Google and SpaceX, Reuters reported.

China has rejected the U.S. allegations, with its Commerce Ministry calling distillation a widely used and neutral technical method. The ministry accused Washington of interfering with normal commercial activity and said some U.S. companies had also distilled Chinese models.

Anthropic said it has responded to the activity by shutting down accounts associated with the operations and strengthening systems designed to detect attempts to extract Claude's capabilities. The company has also introduced additional verification requirements for accounts linked to regions where Claude is not directly available.