>_TheQuery
// Reading nowStart
← All Articles

Anthropic: Alibaba Cloned Claude 151M Times. Six More Did.

By Addy · September 11, 2026 · Editorial standards

Anthropic published its third threat intelligence report on September 10, 2026, and the section drawing the most attention has nothing to do with hackers or propaganda networks. It is about seven Chinese AI labs that Anthropic says have spent the past eight months running fraud operations against Claude for a single purpose: harvesting its outputs to train their own models.

The headline number belongs to Alibaba. Anthropic says accounts it traced back to the company exchanged more than 151 million messages with Claude between May and July 2026, the largest such campaign the company has ever measured. Six other labs, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax, appear in the same report for smaller but structurally similar operations.

None of this is Anthropic's first accusation along these lines. What makes the September report notable is the scale. The company first went public with distillation numbers in February. By September, the volume attributed to just one of the seven labs had grown roughly tenfold.

What "Illicit Distillation" Actually Means

Distillation itself is an ordinary, legal training technique. A smaller or cheaper model learns by studying a bigger model's answers, in much the same way a student might learn geometry by working through a tutor's fully solved problems rather than staring at a blank page. Every major AI lab does versions of this internally, and companies frequently license a stronger model's outputs on purpose.

What Anthropic calls illicit distillation is the same idea carried out through fraud and at industrial volume. The company's own definition, from the report: an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization, typically enabled by fake accounts built with stolen credit cards, login credentials, and API keys. Instead of one student working through one tutor's solutions, it is thousands of fabricated accounts feeding a tutor's every worked answer into a rival's textbook, without the tutor ever agreeing to teach any of them.

The specific thing several of the labs were after was Claude's chain of thought: the scratch-work a model produces before it lands on a final answer, similar to the intermediate steps a student is asked to show on a math test rather than just the final number. Anthropic normally shows users only a summarized version of that scratch work. According to the report, Alibaba's accounts found a way around the summary.

Alibaba's Operation Was the Biggest Anthropic Has Ever Measured

The case, internally tracked as GTG-16005, worked differently from ordinary heavy API usage. Anthropic says the accounts, more than 3,500 of them, used a single fixed prompt framed as an innocuous translation request to get Claude Opus 4.6 and 4.7 to output their full internal reasoning rather than a summary of it. Traffic peaked at close to 3 million exchanges in a single day. The harvested transcripts, Anthropic says, were used to train three successive Qwen releases: 3.5, 3.6, and 3.7.

The scale escalated across three separate disclosures this year. In February, Anthropic's first public distillation report did not name Alibaba at all, it named DeepSeek, Moonshot, and MiniMax collectively for roughly 16 million exchanges across 24,000 fraudulent accounts. In June, Anthropic sent a letter to the Senate Banking Committee accusing Alibaba specifically of 28.8 million exchanges across 25,000 accounts between April 22 and June 5, a claim that reportedly knocked Alibaba's US-listed shares down roughly 2.7% to a 52-week low. By September, the number attributed to Alibaba alone for a similar window, May through July, had climbed to 151 million.

Anthropic is careful to note that not all of Alibaba's Claude usage was extraction. The company said Alibaba also used Claude for legitimate research, including reinforcement learning and architecture work unrelated to the distillation campaign. The 151 million figure applies specifically to the accounts using the fixed chain-of-thought extraction prompt.

Moonshot and DeepSeek Chose the Sneakier Method

Where Alibaba's accounts queried Claude directly, Moonshot AI and DeepSeek took a different approach: routing their own paying customers' real conversations through Claude without telling them, then serving Claude's answers back to users as though they had come from Kimi or DeepSeek's own models.

In the case Anthropic tracks as GTG-16002, Moonshot silently forwarded almost 300,000 customer requests to Claude over a single ten-day window, using 5,380 fraudulent accounts and a technique Anthropic calls a cross-session replay attack on Claude's thinking signatures, a method for extracting reasoning traces that a normal API call would not expose. Total exchanges attributed to Moonshot between May and July reached more than 23 million. One flagged request, which Anthropic assessed as likely tied to the Chinese military, asked Claude to review closed-circuit surveillance footage and determine whether a subject was behaving abnormally.

DeepSeek's case, GTG-16001, used the same replay technique and logged more than 12.1 million exchanges in just 14 days in July 2026. Because DeepSeek was relaying live customer conversations rather than running synthetic queries, some of what reached Claude's servers was sensitive by accident. Anthropic says the exposed material included live credentials for a Russian government database and a Chinese police case-management system, information that arrived at Anthropic only because DeepSeek's own users had no idea their prompts were being forwarded to a competitor.

Four More Labs, Four More Shortcuts

The remaining four labs in the report each took a distinct route to the same end. Zhipu, which builds the GLM models under the brand Z.ai, ran 770,609 exchanges through what Anthropic describes as a chain-of-thought cleaner over ten days, timed ahead of its GLM 5.3 release. Xiaomi routed more than 400,000 requests across upwards of 1,500 accounts. SenseTime did not run an extraction pipeline of its own at all: Anthropic says its distillation pipeline was built on Claude transcripts purchased from third-party data vendors. MiniMax, already named in February's report, built a proxy network through a shell company that marketed itself as a discount reseller of Anthropic and OpenAI access, a setup designed to harvest both usage and credentials from customers who thought they were getting a cheap deal.

LabReported volumeWindowMethod
Alibaba151M+ exchangesMay–Jul 2026Fixed prompt extracting full chain-of-thought from Opus 4.6/4.7, used to train Qwen 3.5–3.7
Moonshot AI23M+ exchanges (300K in one 10-day span)May–Jul 2026Silently rerouted live Kimi customer queries to Claude; replay attack on reasoning traces
DeepSeek12.1M+ exchanges14 days, Jul 2026Same replay technique; rerouted live customer conversations, exposing sensitive third-party data
Zhipu (Z.ai)770,609 exchanges10 days"Chain-of-thought cleaner," timed ahead of GLM 5.3
Xiaomi400,000+ exchangesUnspecified1,500+ fraudulent accounts
SenseTimeNot disclosedUnspecifiedPurchased Claude transcripts from third-party data vendors
MiniMaxNot disclosed in Sept reportUnspecifiedShell-company proxy reselling fake discounted Claude and OpenAI access

The Money and Politics Around the Numbers

The distillation dispute has not stayed confined to blog posts. The White House Office of Science and Technology Policy flagged industrial-scale distillation as a national security concern in April 2026, and Anthropic's June letter to Congress noted that Alibaba's campaign continued after that warning was issued. Alibaba, Moonshot, DeepSeek, and Xiaomi did not respond to reporters' requests for comment on the September report. China's Foreign Ministry has previously addressed the broader accusation pattern without confirming or denying specific figures, saying the country's AI progress comes from greater self-reliance and strength in science and technology rather than from any single company's outputs.

Anthropic is not the only lab making this argument. OpenAI has separately attributed similar extraction activity to DeepSeek, and Google has published its own findings on distillation attempts against its models. Anthropic's report goes further than a complaint, explicitly calling for tighter access controls on advanced chips as part of the response, tying the distillation fight directly to the broader US-China semiconductor export debate.

The Irony Nobody Asked For

In July 2026, weeks after Anthropic's Senate letter about Alibaba went public, developers on X found that Claude Opus 4.8 would sometimes identify itself as Qwen or DeepSeek when prompted in certain ways, particularly in Chinese-language conversations. The finding spread fast, with posts framing it as Anthropic training on the very labs it was publicly accusing.

That framing does not hold up well. Large language models misidentifying themselves is a well-documented and fairly mundane quirk, usually traced to training data that includes chat transcripts, articles, or benchmarks referencing other models' names, not evidence of which model actually produced the training data. No independent analysis has tied Claude's self-identification slips to Anthropic distilling a rival's outputs. But the coincidence in timing was close enough that the "you're doing it too" narrative outlasted the technical explanation, at least on social media.

What Anthropic Is Actually Doing About It

The report describes several defenses built specifically around how these seven campaigns operated. Anthropic says it now applies metadata-based attribution to identify proxy service networks before they scale, and that its classifiers for detecting extraction attempts were strengthened alongside the Fable 5 launch. The chain-of-thought summarization that Alibaba's accounts worked around is being reinforced rather than abandoned, on the logic that a summarized version of the scratch work is simply less useful as training data than the raw version.

The more targeted fix arrived with Fable 5.1, in the form of what Anthropic calls preserved thinking: a safeguard that stops new API accounts from altering the system prompt, tools, or preceding messages in a conversation before Claude's reasoning step, closing off the exact replay mechanism Moonshot and DeepSeek used to pull reasoning traces out of live customer traffic. Accounts that trigger abuse signals now face identity verification, and accounts that fail it are banned outright.

Anthropic has published three of these reports since March 2025, and each one has named more labs and bigger numbers than the one before it. Not one of the seven labs named in September has issued a public rebuttal, a correction, or a competing set of numbers. The distillation keeps scaling. So does the silence.

Sources

  1. Countering misuse of AI: September 2026
  2. Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
  3. Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas