Anthropic's new distillation tally: more than 186 million Claude exchanges across 3 labs
Anthropic says it detected more than 186 million Claude exchanges in distillation campaigns attributed to Alibaba, Moonshot and DeepSeek. Its largest attribution is an Alibaba-linked campaign of 151 million exchanges across more than 3,500 accounts from May through July 2026. The figures reported by Reuters and The Clarity come from Anthropic's own threat intelligence; the reports include no response from the named companies.
Artificial Intelligence··Midday
How the scale breaks down
According to the Anthropic account carried by Reuters, the Alibaba-linked campaign generated more than 151 million Claude exchanges through over 3,500 fraudulent accounts from May through July 2026. Daily traffic reached nearly 3 million. The company says the activity harvested Claude outputs to train other models through distillation. That classification is the result of Anthropic's own security review, not an independently verified record of how the accounts were used.[1]
The other two campaigns
The Clarity reports that the same findings attribute 23 million exchanges to Moonshot and 12 million attacks over 14 days in July 2026 to DeepSeek. The total attributed to the three labs therefore exceeds 186 million. The report links the Moonshot traffic to Kimi models and the Alibaba traffic to Qwen models. These figures compare the scale of the campaigns; they do not measure the companies' model performance or any training benefit obtained.[2]
The limit of the attribution
Reuters names Alibaba, Moonshot, DeepSeek and Xiaomi among the Chinese companies identified by Anthropic, but its report includes no response from them. The findings should be read as a provider attribution based on account patterns and traffic volume. Independent reports establish that Anthropic made the claims and reproduce the figures, but they do not provide a separate technical audit of who operated the accounts or how the outputs entered training pipelines.[1], [2]