Anthropic says Alibaba, Moonshot and DeepSeek trained on Claude — and Kimi users never knew
Anthropic's September threat-intelligence report names Chinese labs it says ran industrial-scale "illicit distillation" of Claude — led by an Alibaba campaign of more than 151 million exchanges in three months. The report, covering misuse the company disrupted between December 2025 and August 2026, says operators affiliated with Alibaba used Claude outputs to help train its Qwen models, peaking at nearly 3 million exchanges a day across more than 3,500 fraudulent accounts. Anthropic calls it the largest distillation campaign it has ever measured.
Moonshot's scheme is the one that touches consumers directly. The Beijing-based maker of the Kimi models silently forwarded customer requests intended for Kimi to Claude — mostly to Opus — then showed users Claude's responses as if they were Kimi's, Anthropic says. In one 10-day window, nearly 300,000 customer requests flowed to Anthropic through 5,380 accounts, most appearing to be in Singapore and Japan; some of those exchanges were saved and their reasoning transcripts extracted as training data. Anthropic attributes more than 23 million exchanges to Moonshot between May and July, and says DeepSeek ran a similar relay without telling its customers — over 12 million distillation attacks across 14 days in July. The company says some exchanges contained sensitive information from individual users, major multinational companies and state-affiliated actors, and that the practices are likely inconsistent with privacy laws and the labs' own terms. Alibaba, Moonshot and DeepSeek did not respond to requests for comment.
This is the distillation arms race going kinetic. Earlier this year Anthropic locked Claude's thinking blocks specifically to kill API distillation — we covered that in "Anthropic locks Claude's thinking blocks to kill API distillation" — and a week later went public with the dark-web pipeline behind it. Today's report is the escalation: the accused now include some of China's biggest labs, the alleged method includes deceiving your own paying users about which model they're talking to, and the claimed volumes are orders of magnitude beyond anything previously named. Caveats matter: this is one company's forensic account of traffic it observed and blocked, published by the party that was distilled from, and none of the named labs has answered the allegations. But if even half of it holds, the tacit norm that frontier labs don't train on rivals' traffic is dead — and every API response is now potential training data for someone else.
What to watch: whether Moonshot's relay — showing users Claude output branded as Kimi — draws regulator attention, since that's a consumer deception claim, not just a terms-of-service fight.
Do you check which model actually answers when you send a prompt to a chatbot — or do you trust the label?
Sources: CNBC · Anthropic threat-intelligence report, September 2026 · TechCrunch · Anthropic — Detecting and preventing distillation attacks