Anthropic catches China's AI labs in 190M-attack Claude training scheme
Anthropic says Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi used Claude's outputs to train their models, exposing sensitive data and forcing new safeguards.

Anthropic accused China's top AI labs, including Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi, of launching nearly 190 million distillation attacks on Claude between May and July. The attacks, which routed user requests to Claude to train rival models, have prompted Anthropic to tighten guardrails and require identity verification for users in China, Russia, and Iran.
Anthropic has accused China's top AI labs of launching nearly 190 million distillation attacks against its Claude model between May and July, according to a Thursday report. The attacks, which used Claude's outputs to train rival models, involved Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi - a who's who of Chinese AI that collectively represents billions in valuation and some of the most advanced models outside the US.
The most striking detail: Moonshot and DeepSeek routed their own users' requests to Claude instead of their own models. Moonshot recorded 23 million such reroutings between May and July, while DeepSeek logged 12.1 million in just 14 days in July. That's 35 million times that user queries meant for Chinese AI were secretly processed by Claude - a number that underscores the scale of the operation.
Distillation attacks are a known tactic in AI: using a frontier model's outputs to train a cheaper, less advanced model. Anthropic says Alibaba ran the largest attack it has ever measured, with over 151 million exchanges from 3,500 fraudulent accounts, forcing Claude to reveal its reasoning processes to train its Qwen models. Z.ai, the mysterious lab behind the Ox Alpha model, launched a similar attack, and Xiaomi fed its own MiMo user chats into Claude to create training data.
The stakes go beyond corporate espionage. Some of the rerouted requests exposed sensitive data from Chinese and Russian governments and militaries, including CCTV footage from a PLA-affiliated Kimi user and information on a Russian government database from a Russian military contractor. That raises national security concerns and underscores how AI models can become vectors for data leakage - a risk that extends to any enterprise using AI APIs.
Anthropic is responding with new safeguards: banning suspicious activity, making Claude produce less detailed reasoning transcripts, and requiring identity verification for users in China, Russia, and Iran, where Claude isn't available. This is not the first time Anthropic has called out Chinese labs - in June, its head of policy Sarah Heck told lawmakers that Alibaba had engaged in 28.8 million exchanges with Claude and called for legislation to address such attacks. Representatives for Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi did not respond to queries from Business Insider, and Anthropic also declined to comment.
For executives, this is a reminder that AI models are both assets and liabilities. Distillation attacks are a form of intellectual property theft that's hard to detect and even harder to stop. Anthropic's move to limit reasoning transparency is a trade-off: it protects the model but may degrade its usefulness for legitimate users who need to understand how it thinks. The company is also requiring identity verification, which could slow down legitimate users in restricted regions.
The broader implication is geopolitical. As the US and China compete on AI, these attacks could accelerate regulatory action, from export controls to new laws targeting model theft. For companies building on frontier models, the lesson is to audit how your data flows and who has access to your API - because the next attack might not come from a rival lab but from a user you never suspected. The fact that Anthropic chose to go public with these allegations suggests it sees this as a systemic threat that demands industry-wide attention.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business
Royal Caribbean just spent $3B to own half of Sandals
The cruise giant is buying a 50% stake in the all-inclusive resort chain for $3 billion, a bet that land-based vacations are the next growth engine.
Paramount's Ellison: Merger Clearance Done, WBD Deal by Oct 1
David Ellison says the Paramount-WBD merger has full clearance after settling with state AGs, clearing the path for an October 1 close.
Paramount settles with 12 states, $110B Warner merger clears final hurdle
David Ellison's studio avoids a March trial and a $7M-a-day ticking fee by settling with state AGs over local job losses.



