Chinese AI labs harvested US models, exposed state secrets: Anthropic report
Anthropic’s report reveals that major Chinese AI developers operated illicit proxy networks to harvest Claude’s reasoning capabilities, unintentionally leaking sensitive military, government, and corporate secrets in the process.
Chinese AI developers have been conducting covert, industrial-scale distillation campaigns to harvest advanced reasoning capabilities from American frontier models, according to an Anthropic report.
Distillation is a standard machine learning practice where a smaller student model is trained on outputs generated by a larger teacher model to replicate its performance at a fraction of the cost.
Anthropic’s September 2026 Threat Intelligence Report reveals how major Chinese technology firms used fraudulent account networks, proxy relays, and technical exploits to secretly extract Chain-of-Thought reasoning from Claude Opus.
The report details illicit distillation operations across seven Chinese AI laboratories.
Alibaba operated the largest campaign ever measured, launching over 151 million exchanges between May and July 2026 to fine-tune its Qwen models, peaking at nearly three million requests per day.
Zhipu AI processed millions of prompts to train its GLM models, switching its target to Claude Opus 4.6 after Anthropic’s enhanced cyber safeguards on newer models disrupted its initial attempts.
Meanwhile, technology developers such as Xiaomi, SenseTime, and MiniMax acquired harvested user transcripts through third-party reseller markets or shell proxy networks.
In one of the most surprising developments, Moonshot AI and DeepSeek went beyond standard distillation by silently re-routing their own customers’ live queries to Claude.
Anthropic report reveals AI weapons, surveillance outlive their digital bans
Moonshot operated 5,380 fraudulent accounts across Singapore and Japan, relaying 23 million exchanges and serving Claude’s answers directly back to users who believed they were interacting with domestic models. DeepSeek deployed a similar pipeline, intercepting over 12.1 million user requests in two weeks through coding harnesses.
To extract Claude’s encrypted reasoning traces, both companies engineered cross-session replay attacks, saving Claude’s encrypted thinking signatures and prompting fresh API sessions to convert them back into unredacted reasoning transcripts for model training.
This covert proxying created massive, unintended data leaks, sending sensitive domestic government, corporate, and military intelligence directly onto American servers without user knowledge.
Moonshot inadvertently forwarded video surveillance data from hundreds of CCTV cameras in Chengdu, including footage outside Chinese military facilities and state-owned enterprises, submitted by a user conducting abnormal behaviour analysis.
DeepSeek relayed live database credentials for a Russian Ministry of Defence agency, internal tracking tools for a Chinese municipal Public Security Bureau, and confidential software specifications from major technology firms.
The disclosures highlight the growing challenge of protecting frontier intellectual property against unauthorised distillation.
In response, Western AI vendors are deploying encrypted reasoning signatures, preserved thinking protocols, and real-time behavioural monitoring to prevent model extraction.
Anthropic emphasised that when general reasoning is distilled into local models, safety alignment is stripped away, transferring dual-use capabilities across cyber and biological domains.


