Anthropic has released a new report alleging persistent distillation attacks by China-based AI companies, which have reportedly escalated in recent months. The company observed nearly 200 million exchanges linked to these attacks, attributed to five separate campaigns.
The report states that unauthorised labs have developed increasingly sophisticated methods to circumvent defenses and harvest capabilities from US frontier models. These campaigns reportedly targeted Claude's capabilities, including agentic capabilities, tool use, coding, data analysis, and logical reasoning.
The bulk of distillation attempts, 151 million exchanges between May and July 2026, were attributed to Alibaba. Anthropic described this as the largest wholesale distillation effort it has observed, peaking at nearly three million exchanges per day. Another campaign from Moonshot AI reportedly routed requests directly from the Chinese military.