Anthropic detected and shut down large-scale efforts by Alibaba, Moonshot AI and DeepSeek to extract Claude outputs for training their own models through a technique known as model distillation.
The campaign represents a direct assault on Anthropic's economic moat. By harvesting Claude's responses without paying for API access, the Chinese labs replicated advanced capabilities while avoiding the billions required for frontier model development and compute infrastructure.
Alibaba's operation was the largest. Between May and July, the company routed 151 million queries to Claude across more than 3,500 fraudulent accounts, peaking at 3 million daily exchanges. Anthropic found that Alibaba used Claude's outputs to train its Qwen models and also extracted Claude's reasoning transcripts for reinforcement learning and architecture development.
Moonshot AI employed a more deceptive approach. The Beijing-based company silently redirected customer queries intended for its Kimi models to Claude, then displayed Claude's responses to users without disclosing the rerouting. In a 10-day period, Moonshot forwarded 300,000 customer requests through 5,380 accounts appearing to originate in Singapore and Japan. The company saved Claude's reasoning transcripts as training data, with 23 million distillation attacks logged between May and July.
DeepSeek, which has gained market share through claims of superior cost efficiency, transferred 12 million queries to Claude over a 14-day period in July 2026 without notifying its own customers.
Both Moonshot and DeepSeek routed requests containing sensitive information—including data from individual users, multinational corporations and state-affiliated actors. Anthropic said the practices likely violate privacy laws and the labs' own terms of service.
The distillation campaigns underscore a structural vulnerability in the API-based model monetization strategy. Anthropic charges by the token, and at scale, extracting model outputs to train competitors becomes rational economics for well-funded labs. The company's $5 billion Series C valuation depends partly on Claude's defensibility as a moat; unauthorized extraction directly erodes that premium.
Anthropoic's disruption efforts spanned seven areas, including cyber operations, over an eight-month period from December 2025 through August 2026.
