
Anthropic Reports Unauthorized Exploitation by Chinese AI Companies
Anthropic, a US AI startup, has reported that several Chinese AI laboratories, including Alibaba, Moonshot AI, and DeepSeek, have engaged in sophisticated tactics to illegally “distill” and exploit capabilities from their advanced models.
Unauthorized Activities
In a recent report, Anthropic revealed it has detected and prevented large-scale unauthorized attempts from these companies to train their own models using capabilities from Claude, Anthropic’s AI. The report states that these labs have developed increasingly sophisticated methods to bypass Anthropic’s defenses, targeting valuable capabilities such as reasoning, tool usage, programming, and data analysis.
Methodology of Exploitation
The primary focus of these unauthorized activities involves extracting thought processes from Claude’s responses through various queries. These thought processes are then used to train smaller models on general reasoning capabilities via supervised fine-tuning. Anthropic does not provide users with internal thought chains but only offers a summary view. Attackers have employed techniques to trick the model into revealing secrets, such as framing queries as translation requests.
Scale of Distillation Efforts
Anthropic identified Alibaba’s distillation efforts as the largest they have measured, with over 151 million exchanges with Claude from May to July, peaking at nearly 3 million daily exchanges from over 3,500 fraudulent accounts. Moonshot AI has also been implicated in forwarding numerous user requests to Claude while making users believe they were interacting with their own model, Kimi. In just ten days, Moonshot AI extracted nearly 300,000 commands aimed at Claude Opus through a network of 5,380 fraudulent accounts.
DeepSeek’s Activities
DeepSeek has similarly engaged in unauthorized query forwarding to Claude without notifying customers. Anthropic reported over 12 million distillation attempts likely conducted by DeepSeek within a two-week period in July.
Broader Context of Unauthorized Exploitation
The report also highlights other major Chinese AI companies and their activities that Anthropic has thwarted since December 2025 across various sectors, including cyber operations, influence operations, fraud, and misuse of biotechnology. Anthropic previously reported similar distillation attacks in February, specifically naming certain labs, with OpenAI also attributing similar activities to DeepSeek.
Overall Impact
Anthropic’s report indicates nearly 200 million exchanges related to distillation or unauthorized exploitation, underscoring the scale and seriousness of these activities. The concept of distillation in AI refers to transferring knowledge from a larger pre-trained model (teacher) to a smaller model (student), allowing the smaller model to achieve performance comparable to the teacher while reducing inference costs.










