According to Anthropic’s latest threat intelligence report, operators affiliated with Alibaba ran the largest model-distillation campaign the company has ever measured: more than 151 million exchanges with Claude between May and July, peaking at nearly 3 million per day from more than 3,500 fraudulent accounts. The report says those behind it went straight for the reasoning transcripts of Claude Opus 4.6 and 4.7 — injecting a fixed prompt into each request that forced Claude to write out its chain-of-thought inside inline text tags, then harvesting those traces as training data for Qwen 3.5, 3.6 and 3.7.
That is the headline claim, and it is worth being precise about what kind of claim it is. Everything in the report is Anthropic’s own account of activity it says it detected and disrupted between December 2025 and August 2026. Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic did not immediately respond to CNBC’s requests for comment. China’s Ministry of Commerce has responded — to the United States government advisory built on similar findings — by calling the allegations groundless.
What the report actually claims
The numbers are large enough to sit up straight for. Beyond Alibaba’s 151 million exchanges, Anthropic attributes more than 23 million to Moonshot AI between May and July, routed through 5,380 accounts the company describes as fraudulent, most appearing to be located in Singapore and Japan. In one 10-day period, Moonshot relayed nearly 300,000 customer requests to Anthropic — the vast majority to Claude Opus models — while, according to Anthropic, users believed they were talking to Kimi. The report states Anthropic does not know whether Moonshot notified those customers that their queries were being rerouted to a third party. Some of the rerouted queries, the company says, contained sensitive information, including what it assesses was likely PLA-affiliated surveillance activity.
DeepSeek’s attributed count is over 12.1 million exchanges across 14 days in July. Xiaomi logged more than 400,000 over 20 days in March and April. Zhipu, branded internationally as Z.ai, is accused in the report of running a chain-of-thought extraction pipeline against Claude Opus 4.8 through 273 rotating accounts it describes as fraudulent — 770,609 exchanges passing through the cleaner in ten days in June, with over 3 million more exchanges used to clean distilled outputs. Anthropic also says that ahead of GLM 5.3’s release, Zhipu targeted the cyber capabilities of a leading US frontier model, with Claude Opus 4.6 separately used to grade the responses of the other US model. Zhipu did not respond to a request for comment; none of the named companies have publicly contested the specific counts.
There is a secondary market in the report too: Anthropic describes a proliferation of proxy services through which labs can buy harvested exchanges, and it names a reseller ecosystem it says connects Sensetime and MiniMax to that market.
The part that should worry everyone, not just Anthropic
The Moonshot detail is the one with real-world consequences beyond the distillation dispute itself. User queries meant for Kimi were silently forwarded to Claude, and some of those queries contained sensitive information — from individual users, major multinational companies, and state-affiliated actors. If you typed a prompt into Kimi this northern summer, you had no way of knowing it was being answered by a competitor’s frontier model and potentially retained as that competitor’s training data. Anthropic says it cannot confirm whether those users were ever told.
The report’s non-distillation cases read like a catalogue of where AI-enabled operations are heading. An independent consultant working with Mali’s state intelligence service is alleged to have used Claude to build “Lakana 360,” a surveillance platform monitoring roughly 25 million SIM cards across all three of Mali’s national mobile operators, designed to circumvent Malian legal restrictions requiring court orders. An operation Anthropic calls “DronDoc” or “Serafim” used Claude to build the core software for an autonomous kamikaze drone swarm — shared swarm memory, fault-tolerant coordination logic, an onboard small language model governing attack behaviours — with simulation and rented GPU training infrastructure behind it. The report also describes Claude integrated as the sub-editor layer in Russian state-media editorial pipelines, drawing on inputs from Russian newswires, the SVR foreign intelligence agency, and the Defence Ministry, with at least one confirmed instance reaching Russian airwaves.
Anthropic frames the safeguards picture this way: humans retained meaningful involvement in most operations, but a growing subset ran multi-agent frameworks conducting reconnaissance, exploitation and theft in parallel for hours or days at a time, and one collection fleet ran on a pre-set schedule with no human in the loop.
The US government made it official — and Beijing fired back
The same week, CISA and other US agencies jointly issued advisory AA26-251a, which states that, likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted what it calls billions of tokens across millions of exchanges from US frontier AI models. The advisory is American-signed; no New Zealand agency appears among the co-signatories.
China’s Ministry of Commerce responded on Wednesday, according to Global Times: the allegations were groundless and lacked legal basis, distillation is a normal technical and commercial practice, and the advisory is further evidence of Washington’s technological hegemony and its pursuit of a monopoly over computing power. The spokesperson added that if the United States acts to suppress Chinese AI companies under the pretext of countering distillation, China will take resolute countermeasures.
Both things can be true at once, and probably are: distillation of this scale is real, and Beijing has an obvious interest in normalising it as industry practice. What the dispute does settle is that extracted frontier-model capability has graduated from a security-team nuisance to a formal item of US-China trade friction — with an AI capability dispute now carrying retaliation threats usually reserved for tariffs.
New Zealand’s quiet exposure
The 12:15 and 1pm robotics runs will not cover this — it is a software story — but the exposure it describes is not abstract for this country. New Zealand businesses and agencies use both Claude and the Chinese labs’ models, often through third-party routing services. Anthropic’s report notes that many of the relayed exchanges came from users of third-party model routing services commonly used in the United States and Europe. A NZX-listed company typing commercial data into what it believes is its own chatbot has no way of knowing where that prompt actually went — that is the lesson of the Moonshot case, whatever the truth of the attribution dispute.
MBIE’s AI strategy leans on voluntary adoption; none of its guidance contemplates that a chatbot vendor might secretly swap the model underneath. Whether New Zealand’s privacy framework gives any recourse to a user whose query was rerouted to a foreign model without consent is a question nobody in Wellington has answered publicly. It should probably be asked before, not after, the local equivalent lands.
The honest takeaway from the report is unglamorous: accounts get farmed, transcripts get harvested, and the frontier labs’ terms of service turn out to be enforceable only against customers who care about being caught. Anthropic says it has disrupted the campaigns and hardened its safeguards. The 151 million exchanges already happened.
FAQ
What is model distillation? Training a smaller or different model on the outputs of a larger one to transfer its capabilities. Using your own model’s outputs is standard practice; Anthropic’s complaint is that these campaigns extracted them from Claude at scale, against its terms, using fraudulent accounts.
Did Anthropic prove the Chinese labs did this? No. Anthropic published what it says it detected and disrupted. The named companies had not responded to requests for comment at the time of CNBC’s reporting, and China’s Commerce Ministry has rejected the underlying US advisory as groundless. The claims remain the reporting party’s own.
What should a New Zealand business take from this? Know which model is actually answering your prompts, especially on third-party routing services — and be conservative about what you type into chatbots you cannot verify.
Sources:
- Anthropic — Detecting and countering misuse of AI: September 2026
- CNBC — Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says
- CISA — Advisory AA26-251a
- Global Times — China dismisses US AI distillation claims, vows countermeasures
- Anthropic — Moonshot and the model-swap problem, Singularity.Kiwi coverage
— CJ Murden, editor of Singularity.Kiwi. Former digital technologies teacher, author of AI-focused books. Writing with a New Zealand focus.