Anthropic published a report detailing ongoing distillation attacks by several China-based AI companies, including Alibaba, Moonshot AI, and DeepSeek. These attacks have intensified recently amid increasing competition in the AI industry. Distillation attacks involve extracting the internal reasoning or "chain of thought" from AI model responses, which can then be used to train smaller models through supervised fine-tuning.

The company noted that attackers have developed sophisticated methods to bypass its defenses and access valuable capabilities of its Claude models, such as agentic functions, tool use, coding, data analysis, and logical reasoning. Unlike typical user interactions that show summarized reasoning, these campaigns tricked the models into revealing detailed internal thought processes.

Anthropic observed nearly 200 million exchanges linked to five distinct distillation campaigns. The largest campaign, attributed to Alibaba, accounted for 151 million exchanges between May and July 2026, involving around 3,500 accounts using a fixed prompt to extract reasoning chains. This effort appears aimed at enhancing Alibaba's Qwen model family.

Another campaign from Moonshot AI, maker of the Kimi model, reportedly routed requests through accounts linked to the Chinese military. One example involved analyzing surveillance footage to detect abnormal behavior. Over a 10-day period, approximately 300,000 requests targeted Anthropic’s Opus model via 5,000 accounts.

Anthropic’s findings underscore the challenges AI developers face in safeguarding proprietary model capabilities from unauthorized extraction. As AI competition grows, protecting intellectual property and model integrity remains a critical concern for the industry.