Drooid Logo
Back to story perspectives

Full Breakdown

Anthropic Accuses Chinese AI Labs of Large-Scale “Illicit Distillation” and Covert Request Routing

By Drooid · · How we work

Core Event

Anthropic PBC released a multi-hundred-page threat-intelligence report alleging that three China-based AI companies—Alibaba, Moonshot AI and DeepSeek—routed user queries intended for their own models to Anthropic’s Claude systems, captured the responses, and used the data to train their own models without permission. Anthropic says the activity exposed Chinese users’ information to the U.S. company and violated privacy laws and Anthropic’s terms of service.

Background & Context

Distillation is a standard AI research technique in which outputs from a more capable model are used to improve a less capable one. U.S. officials have warned that Chinese firms may be using the method at industrial scale to shortcut development. Earlier in the week, the NSA, FBI and CISA issued a joint advisory describing systematic extraction of U.S. model capabilities by Chinese AI companies.

Data & Statistics

  • Alibaba: Over 151 million exchanges with Claude recorded between May and July; activity peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts.
  • Moonshot AI: Approximately 23 million exchanges; a 10-day window saw nearly 300,000 user requests forwarded to Claude Opus, routed through 5,380 accounts.
  • DeepSeek: More than 12 million distillation attacks observed over a 14-day span in July.
  • The fraudulent accounts used by Moonshot and DeepSeek were described as “networked” and “obfuscated,” allowing the firms to bypass geographic restrictions that block U.S. frontier models from China.

Official Statements & Responses

  • Anthropic said it disrupted the identified campaigns and added safeguards to block further abuse.
  • Chinese Commerce Ministry: Rejected the accusations as “without factual or legal basis” and warned of “countermeasures” if the United States attempts to “contain and suppress” Chinese AI firms.
  • U.S. agencies: Recommended that AI companies adopt detection and mitigation measures, including subtle response alterations for suspected malicious queries.

Criticism & Opposition

Chinese officials argue the allegations are part of a broader U.S. effort to stifle China’s AI industry. The Commerce Ministry framed the claims as a “Washington-driven” attempt to suppress competition and signaled readiness to retaliate against any U.S. actions perceived as containment.

Verbatim Quotes

  • “If we were to do that, or if one of our competitors would do that, that would be a large privacy scandal,” — Jacob Klein
  • “If you extrapolate into the future, the level of capabilities of these AIs … they could cause extreme havoc,” — Jacob Coxon
  • “Attackers deploy proxy infrastructure to orchestrate large-scale automated attacks, rotating queries across thousands of compromised credentials and fraudulent accounts across different product channels to obscure their origin and bypass standard security controls,” — Google Threat Intelligence Group (GTIG)

Conflicting Reports & Gaps

Anthropic’s report provides quantitative exchange counts, while the Chinese Commerce Ministry offers no data to refute the numbers, merely denying the factual basis of the claims. No independent third-party verification of the exchange volumes has been presented, leaving a gap in external confirmation of the scale of the alleged campaigns.

What’s Next

U.S. agencies have urged AI developers to strengthen detection mechanisms and consider coordinated responses to large-scale distillation attacks. Anthropic indicated it will continue to incorporate investigative findings into its model safeguards. The Chinese Commerce Ministry warned of “countermeasures” should the United States pursue actions perceived as suppressing Chinese AI firms.