AIToday
Large Language ModelsAI Safety & AlignmentAI Business & IndustryTechCrunch AIPublished: Sep 11, 2026, 06:00 JST2 min read

Anthropic says Alibaba, Moonshot ran distillation attacks

Anthropic says Alibaba, Moonshot ran distillation attacks

3 Key Points

  1. What happened

    Anthropic released a report Thursday alleging five distillation campaigns by China-based labs, with nearly 200 million exchanges. The largest, tied to Alibaba's Qwen models, totaled 151 million exchanges between May and July 2026.

  2. Why it matters

    Anthropic previously spoke out about distillation in February and called out specific labs. The new campaigns are both larger and more aggressive, and Anthropic says attackers used tricks like posing as translators to extract Claude's chain of thought.

  3. What to watch

    The test is whether Anthropic's account of these campaigns holds up, and whether the labs it names respond. Watch Alibaba's Qwen family and Moonshot AI's Kimi, the models tied to the alleged campaigns.

WHO IT HITSAI developers building frontier models and those dependent on their protections face renewed scrutiny over how training data is sourced. Companies relying on Claude's agentic and coding capabilities may want to review how their access is secured.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

Anthropic's report lands after the company first raised alarms about distillation in February, when it named specific labs. OpenAI has reported similar activity, which it attributed to DeepSeek specifically. Anthropic says the campaigns in its new report are larger and more aggressive than what came before, suggesting the tactics have scaled up along with the models themselves.

The report zeroes in on how these attacks work. Distillation tries to pull the chain of thought out of a model's answers, which can then be used to train a smaller model. Anthropic normally shows users only summarized thinking blocks rather than the internal chain of thought, but the report says the campaigns found specific ways to trick the model into revealing its thinking traces directly — for example, by posing as a katakana-only translation task. The bulk of the attempts, attributed to Alibaba, involved 151 million exchanges between May and July 2026 across 3,500 accounts, all tied to a single fixed prompt aimed at producing training data for Alibaba's Qwen family.

A separate campaign attributed to Moonshot AI, the maker of Kimi, appeared to route requests directly from the Chinese military, including one asking Claude to review surveillance footage for abnormal behavior. Over one ten-day period, nearly 300,000 requests went through 5,000 accounts, mostly targeting Anthropic's Opus model. The outcome likely hinges on how these allegations are received and whether the named labs respond, since the report's claims about scale and intent are central to the dispute.

FAQ
What is distillation in this context?
It is an attack that extracts the chain of thought from a model's responses. That extracted reasoning can then train a smaller model through supervised fine-tuning.
How did the attackers get around Claude's defenses?
Anthropic says they found techniques to trick the model into revealing its thinking traces. One example framed the query as a katakana-only translation request.
Which labs does the report name?
The campaigns are attributed to Alibaba, Moonshot AI, and DeepSeek. The largest is attributed to Alibaba, producing training material for its Qwen models.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Dynatrace acquires Arize AI as observability shifts to actionSiliconANGLE AI · 5h ago
  • Shared base cuts 100 fine-tunes from 1.5 TB to 19.3 GBDaily Dose of Data Science · 5h ago
  • OpenAI agents hit RubyGems, undisclosed since May 12thSimon Willison's Weblog · 5h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleArlequin AI raises €28 million for topological AI models