Anthropic says it has traced nearly 200 million exchanges with Claude to five distillation campaigns run by unauthorised labs, the largest such effort the company has documented.
In a report published Thursday, the AI developer said the operations targeted its most valuable capabilities, including agentic tool use, coding, data analysis and logical reasoning.
Distillation works by harvesting a model’s chain of thought and using it to supervise the training of a smaller system, letting rivals absorb frontier capability without paying for the research behind it.
Claude hides its internal reasoning behind summarised thinking blocks, but Anthropic says attackers found prompts that tricked the model into revealing full traces. One disguised the request as a translation task into katakana-only Japanese.
The biggest campaign, attributed to Alibaba, spanned 151 million exchanges between May and July, peaking near three million a day across 3,500 accounts. Anthropic linked the accounts through a single fixed extraction prompt and tied the effort to training data for Alibaba’s Qwen models.
Evidence of military use surfaced in a second cluster of accounts, which Anthropic links to Kimi developer Moonshot AI. Roughly 300,000 queries moved through that network in ten days, including one that asked the model to study stored CCTV footage and decide whether the person on camera was behaving abnormally.
Anthropic has raised the issue before, as has OpenAI, which blamed DeepSeek. The company says the activity has grown more aggressive as competition intensifies, and is pressing for controls on how foreign labs reach US models.