# Anthropic Exposes Large-Scale AI Theft Operations Tied to Chinese Research Labs
Anthropic has publicly disclosed that it uncovered and shut down a coordinated, industrial-scale campaign of unauthorized model copying targeting its Claude AI system. The operation involved seven research organizations headquartered in China, including notable names such as Alibaba, Moonshot AI, DeepSeek, Zhipu (Z.ai), MiniMax, Xiaomi, and SenseTime.
## What Is AI Knowledge Distillation?
AI knowledge distillation is a widely accepted training methodology in which a larger, more capable “teacher” model transfers its learned knowledge to a smaller, more efficient “student” model. This technique is commonly used to create leaner versions of powerful AI systems that retain much of the original model’s performance while reducing computational costs.
When conducted with proper authorization and licensing agreements, distillation is a legitimate and valuable tool in the AI industry. However, when performed without consent — secretly extracting a model’s internal capabilities and replicating them in a competing system — it crosses the line into intellectual property theft.
## How Illicit Distillation Works at Scale
The unauthorized operations identified by Anthropic relied on a sophisticated infrastructure designed to evade detection and access controls. The attackers used networks of proxy servers, also known as relay stations, which generated thousands of synthetic user accounts using fabricated identities, stolen payment credentials, and hijacked API keys belonging to legitimate businesses and individuals.
Once access was established, the labs deployed several methods to harvest Claude’s outputs:
– **Request rerouting:** Some labs silently redirected their own users’ queries to Claude instead of processing them through their own models, then captured and stored the responses for training purposes — all without the users’ awareness.
– **Conversation interception:** User exchanges with Claude were recorded and later purchased from third-party resellers who operated the proxy networks, often without the consent of the individuals involved.
– **Cross-model data feeding:** Certain labs fed conversations between their proprietary models and human users into Claude, then used Claude’s responses as training material to replicate advanced capabilities such as logical reasoning, software engineering, and tool usage.
In some cases, sensitive data from individual users, major multinational corporations, and state-affiliated entities was inadvertently included in these harvested conversations.
## The Six Major Distillation Campaigns
Since February 2026, Anthropic documented six distinct illicit distillation campaigns originating from Chinese-based labs. The scale of these operations was staggering:
**Campaign GTG-16005** — Operated by a group affiliated with Alibaba, this was the largest attack ever recorded by Anthropic. Between May and July 2026, it generated approximately 151 million data exchanges, peaking at around 3 million per day. The campaign involved over 3,500 fraudulent accounts and focused on extracting chain-of-thought reasoning transcripts from Claude Opus 4.6 and 4.7, targeting tasks in agent behavior, software engineering, and kernel development.
**Campaign GTG-16002** — Moonshot AI secretly rerouted customer requests away from its own Kimi model and passed them through to Claude instead. Using a network of 5,380 fake accounts primarily hosted in Singapore and Japan, the lab captured roughly 300,000 customer requests over a 10-day window, storing the responses to train its own reasoning models.
**Campaign GTG-16001** — DeepSeek employed a nearly identical approach to Moonshot, silently relaying user interactions through Claude without notifying customers and extracting the reasoning traces for training purposes. Over a two-week period in July 2026, more than 12.1 million exchanges were captured.
**Campaign GTG-16006** — Zhipu (Z.ai) ran an automated pipeline that replayed Claude’s reasoning outputs back through the model itself, effectively using Claude’s own answers to reinforce its training data. The operation cycled through 273 fraudulent accounts across June and July 2026, accumulating over 3.4 million exchanges.
**Campaign GTG-16008** — Xiaomi fed conversations and coding sessions from its MiMo models back into Claude through OpenClaw and OpenCode development frameworks, harvesting the responses to strengthen the training data for future iterations of its models. The campaign generated over 400,000 exchanges across 20 days in March and April 2026.
**Campaign GTG-16012 and GTG-16003** — SenseTime obtained Claude interaction transcripts by purchasing them from third-party data brokers, while MiniMax constructed its own proxy access service through a shell company, offering connections to models built by both Anthropic and OpenAI with the apparent goal of collecting user exchanges for training.
## The Proxy Service Underground
Anthropic highlighted the emergence of a secondary market built around proxy services that bypass its geographic and access restrictions. These services not only provide Claude access to users in restricted regions but also surreptitiously archive conversations for resale to other AI labs seeking training data.
This underground economy has made it increasingly difficult for frontier AI companies to control how their models are used and to prevent unauthorized replication of their proprietary capabilities.
## Anthropic’s Countermeasures
In response to the persistent attacks, Anthropic implemented several defensive strategies:
– **Account restrictions:** Reseller accounts and those operating from unsupported regions, including China, Iran, and Russia, are banned when users fail to verify their identity.
– **Reasoning obfuscation:** Claude’s models have been updated to summarize their internal reasoning before delivering a final response, making captured transcripts significantly less useful for training purposes.
– **Prompt integrity protection:** With the release of Claude’s Fable 5.1 update, a feature called “preserved thinking” was introduced. This prevents new API accounts from modifying the system prompt, tools, or messages that sit ahead of Claude’s reasoning during multi-turn conversations. The reasoning chain is encrypted, and attackers commonly attempt to manipulate the conversation context to coerce the model into revealing its internal thought process.
## Broader Industry Context
Anthropic’s disclosure comes on the heels of actions by U.S. cybersecurity and intelligence agencies, which have formally accused Chinese AI firms of conducting systematic extraction of proprietary features and capabilities from American frontier AI models. The company also reported shutting down accounts that attempted to use Claude for citizen surveillance and for research into diseases that could support the development of biological weapons.
The findings underscore a growing tension in the global AI landscape, where the rapid advancement of frontier models has created both opportunities and significant risks around intellectual property protection, data privacy, and national security.
—
## Frequently Asked Questions
**Q: What is the difference between legitimate and illicit knowledge distillation?**
A: Legitimate distillation involves authorized training agreements where a smaller model learns from a larger one with proper licensing and consent. Illicit distillation occurs when an organization secretly extracts a model’s capabilities without authorization, often using deceptive means such as fake accounts and stolen credentials.
**Q: How did the unauthorized labs gain access to Claude?**
A: The labs primarily routed requests through proxy services that generated thousands of fake user accounts using fabricated identities, stolen credit cards, and illegally obtained API keys. Some also purchased conversation transcripts from third-party resellers who operated these proxy networks.
**Q: Were users aware that their interactions with Claude were being captured?**
A: In most cases, no. Several labs silently rerouted user requests to Claude without informing the users, and the proxy operators saved conversations without the consent of the individuals involved.
**Q: What specific capabilities were the attackers trying to steal?**
A: The campaigns targeted advanced capabilities including chain-of-thought reasoning, agentic behavior, software engineering skills, tool usage, coding proficiency, and long-horizon task execution.
**Q: What steps has Anthropic taken to prevent future attacks?**
A: Anthropic has banned accounts from unsupported regions when identity verification fails, updated its models to obscure internal reasoning in responses, introduced encryption and prompt integrity protections in newer versions, and disrupted the specific accounts and networks involved in the documented campaigns.
**Q: Why are China-based labs specifically implicated?**
A: Anthropic identified the seven labs responsible for the documented campaigns as being headquartered in China. It is worth noting that earlier in 2026, U.S. cybersecurity agencies also accused Chinese AI companies of systematic extraction of American frontier model capabilities, reinforcing the pattern observed by Anthropic.
**Q: What is the “preserved thinking” feature in Claude?**
A: Preserved thinking, introduced in Claude Fable 5.1, prevents new API accounts from altering the system prompt, tools, or preceding messages before Claude’s reasoning chain in multi-turn conversations. The reasoning itself is encrypted, making it harder for attackers to manipulate the model into revealing its internal logic.
—
## Conclusion
The scale and sophistication of the distillation campaigns uncovered by Anthropic represent a significant challenge for the AI industry. As frontier models become increasingly powerful and valuable, the incentives for unauthorized copying grow stronger, driving the development of ever more elaborate methods to circumvent access controls and extract proprietary knowledge.
The discovery of a thriving proxy-based secondary market for conversation transcripts highlights the need for stronger enforcement mechanisms, better identity verification protocols, and international cooperation to combat AI intellectual property theft. Anthropic’s defensive measures — including reasoning obfuscation and prompt integrity protection — represent important steps forward, but the ongoing cat-and-mouse dynamic between model developers and unauthorized copiers suggests that this will remain a persistent issue for the foreseeable future.
The broader implications extend beyond individual companies, touching on national security concerns, user privacy, and the ethical boundaries of AI development in an increasingly competitive global landscape.
Thank you for reading



