Anthropic said in a new report that Chinese artificial intelligence laboratories had carried out increasingly sophisticated campaigns in recent months to extract capabilities from advanced American models, noting that it had detected nearly 200 million interactions linked to five separate campaigns. According to the company, the attempts targeted Claude’s capabilities in operating agents and using tools, as well as programming, data analysis, and logical reasoning.
Anthropic describes these operations as “distillation attacks,” a technique used to collect the outputs of a large model and then employ them to train a smaller model on reasoning tasks. The company says the attackers attempted to bypass its defenses to extract what it calls the model’s hidden chain-of-thought traces, although Claude does not normally show these traces to users and instead provides “summary thinking” blocks that offer a general glimpse into how it reached an answer.
A Method for Circumventing Chain-of-Thought Protection
According to the report, some campaigns managed to get the model to reveal its chain of thought by phrasing requests indirectly. Anthropic cites an example of a request presented as a translation task, asking Claude to translate its “previous working memory” into Japanese written only in katakana. The company says such methods made it possible to obtain details that were not supposed to appear in a normal response.
The Largest Campaign Was Attributed to Alibaba
Anthropic said the campaign attributed to Alibaba was the largest bulk-distillation operation it had detected to date. Between May and July 2026, the company recorded 151 million interactions, with activity peaking at about three million interactions per day. The requests were distributed across 3,500 accounts, but the use of a fixed prompt to extract chain-of-thought traces led Anthropic to consider them a single effort aimed, in its assessment, at producing training material for Alibaba’s Qwen family of models.
Requests Linked to Moonshot AI
As for another campaign attributed to Moonshot AI, the company behind the Kimi model, Anthropic said it appeared to direct requests from the Chinese military. The report mentions a request to analyze a set of closed-circuit surveillance camera recordings to determine whether someone was “behaving abnormally.” Over a period of ten days, Anthropic detected nearly 300,000 requests routed to Claude through a network of 5,000 accounts, most of them targeting the Opus model.
Why Does This Matter?
If Anthropic’s estimates are accurate, the issue goes beyond the misuse of scattered accounts to an organized attempt to collect outputs from advanced models on a large scale, potentially reducing the cost of developing competing models. The figures also show that protecting capabilities involves not only preventing direct access to model weights, but also controlling usage patterns and detecting similar accounts and requests. Nevertheless, the findings remain allegations made by Anthropic; the material provides no independent verification that the campaigns were linked to Alibaba or Moonshot AI, and it offers no details about the other three campaigns beyond the total number of interactions attributed to them.