Anthropic accuses Alibaba, DeepSeek of training models on stolen Claude data
- Alibaba generated over 151 million exchanges with Claude between May and July
- Anthropic accuses Alibaba, Moonshot, and DeepSeek of illicit model distillation
- Peak activity reached 3 million daily exchanges via 3,500 fraudulent accounts
- Daniel Newman claims Chinese AI labs lift capabilities from U.S. frontier models

*this image is generated using AI for illustrative purposes only.
Anthropic accused major Chinese AI developers of illicitly extracting capabilities from its Claude model to train their own systems. The report details massive-scale distillation campaigns involving Alibaba Group Holdings, Moonshot AI, and DeepSeek.
Scale Of Alleged Distillation
The threat intelligence report released on Thursday identified unauthorized, large-scale extraction activities that went beyond ordinary model use. Anthropic termed this activity "illicit distillation," where responses from a more capable model are used to train another system.
Alibaba Group Holdings was identified as the largest offender. Between May and July, the company allegedly generated more than 151 million exchanges with Claude. This activity peaked at nearly 3 million exchanges per day across more than 3,500 fraudulent accounts. Anthropic stated that Alibaba used these outputs to train its Qwen models and for reinforcement learning research.
| Company | Alleged Activity Period | Volume Of Exchanges/Requests |
|---|---|---|
| Alibaba Group Holdings | May to July | More than 151 million exchanges |
| Moonshot AI | May to July | More than 23 million exchanges |
| DeepSeek | 14 days in July | More than 12 million attacks |
Moonshot AI, the developer behind Kimi, was accused of routing customer requests to Claude without user knowledge. Nearly 300,000 requests were relayed during a single 10-day period. DeepSeek faced accusations of similar activity, with over 12 million distillation attacks observed over 14 days in July.
Industry Reaction And Privacy Concerns
Futurum Group CEO Daniel Newman criticized the narrative surrounding Chinese AI development. He alleged that some Chinese "Open Weight" models rely heavily on lifting capabilities from U.S. frontier labs rather than independent development. Newman described the practice as "freaking insane" and suggested it explains the rapid advancement of certain Chinese models.
Anthropic noted that intercepted requests contained sensitive information, raising privacy and terms-of-service violation concerns. The report covered activities across cyber operations, surveillance, scams, biological misuse, and weapons development. Alibaba, Moonshot, DeepSeek, and Xiaomi did not immediately respond to requests for comment.
How might U.S. regulators respond to these allegations, and could they lead to stricter export controls on AI model access for Chinese entities?
What legal precedents exist for prosecuting 'illicit distillation' of proprietary AI models, and how enforceable are current terms-of-service agreements across borders?
Will this scandal accelerate the development of technical safeguards by Western AI labs to detect and prevent unauthorized model distillation in real-time?

































