Key points
- Anthropic names seven China-based AI labs
- Anthropic attributes 151 million Claude exchanges to Alibaba
- Anthropic says Moonshot and DeepSeek rerouted customer requests
- US agencies issued a distillation advisory Tuesday
Anthropic said operators affiliated with Alibaba (BABA) ran the largest model-copying campaign it has ever measured against its Claude models. The company observed more than 151 million exchanges between May and July, according to a threat intelligence report published Thursday. Six other labs based in China are named alongside it.
The practice is called distillation. One lab feeds another model's outputs into its own training pipeline, which is an ordinary training method when the model's owner agrees to it. Anthropic defines the illicit version as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization." The report covers activity the company says it detected and disrupted between December 2025 and August 2026.
Anthropic describes a network of proxy services and resold training data behind the campaigns. The labs routed requests through services the report calls transfer stations, which open thousands of accounts using false identities, fake or stolen credit cards, and stolen API keys. Some of those proxy operators also save the exchanges and resell them. SenseTime's pipeline included Claude transcripts bought from third-party data vendors, and MiniMax built its own proxy service through a shell company that sells access to Anthropic and OpenAI models and to no Chinese models at all, including its own.
What Anthropic says each lab did
| Lab | What the report describes | Scale Anthropic measured |
|---|---|---|
| Alibaba (BABA) | Forced Claude to write out its reasoning, trained Qwen on the transcripts | 151M+ exchanges, May to July |
| Moonshot AI | Served Claude's answers to Kimi customers and saved the exchanges | 23M+ exchanges, May to July |
| DeepSeek | Relayed coding-tool users' requests to Claude Opus without telling them | 12.1M+ exchanges, 14 days in July |
| Zhipu | Rotated 273 fraudulent accounts to pull and clean reasoning traces | 3.4M+ exchanges, 17 days in June and July |
| Xiaomi | Replayed sessions from its own MiMo models through Claude | 400,000+ exchanges, 20 days in March and April |
| SenseTime | Bought Claude transcripts from third-party data vendors | Not disclosed |
| MiniMax | Ran a proxy network through an undisclosed shell company | Not disclosed |
Alibaba's pipeline injected a fixed prompt into each request to force Claude to write out its chain of thought before giving a final answer, the report says, and those transcripts became supervised fine-tuning data. Traffic peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts. Anthropic banned a first pool of nearly 5,000 accounts, and the traffic moved to a second pool, some of whose accounts were also carrying requests from DeepSeek and Xiaomi. Alibaba used Claude for its own research as well, building reinforcement learning environments and working on model architecture. Alibaba is also an investor in Moonshot, one of the other labs the report names. Its annual report filed in May 2026 discloses an approximately 36% equity interest bought for about $800 million during the fiscal year ended March 31, 2024.
Customer data traveled with the requests
Moonshot AI, which makes the Kimi chatbot, forwarded customer requests to Claude and showed users the answers it returned. Over one 10-day stretch the company relayed almost 300,000 requests through 5,380 accounts, most of which appeared to be in Singapore and Japan. Anthropic says it does not know whether Moonshot told those customers. DeepSeek ran a similar setup, checking inbound traffic for the signatures of coding tools such as Claude Code and OpenCode, then forwarding those users' requests to Claude Opus.
Those relayed sessions carried real data. The requests contained names, email addresses, company data and other sensitive information from hundreds of end users in at least a dozen languages. The report says the practices are "likely inconsistent with privacy laws and the labs' own terms of service." Anthropic's examples include an engineer at a large Chinese state-owned enterprise who exposed internal code and live credentials through Kimi, and an IT operator handling data for an agency tied to Russia's defense ministry whose requests DeepSeek passed to Claude.
China's foreign ministry said it was not aware of the report and opposes distortion of facts and smears against the country, Reuters reported. Alibaba, Moonshot, DeepSeek and Xiaomi did not immediately respond to requests for comment from CNBC.
The findings land while Washington is already moving on the issue. On Tuesday, the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI released an advisory warning that China-based AI companies are distilling US models. It names DeepSeek, Moonshot, Alibaba, MiniMax, StepFun and Z.ai. One of its recommendations is that US labs make targeted changes to the responses they return to high-confidence distillation requests, such as answering with a less sophisticated model. Those changes should vary from request to request, so the degradation is hard to evaluate. The advisory also says not to tell a suspected account that it has been switched to a downgraded model.
Not everyone wants a crackdown. Y Combinator chief executive Garry Tan told CNBC he would "do nothing" about distillation. "We could argue that there should be an American distillation regime," he said, adding that regulators should focus on keeping a balance between open-weight and frontier models.
Alibaba's US-listed shares traded at $109.45 shortly before noon ET on Friday, up about 0.8% from Thursday's close of $108.56. The stock is about 43% below its 52-week high of $192.67, set on October 2, 2025.



