Skip to main content
Workflows Library MCP Directory Realtime AI News Sponsor Tier Subscribe
Front Page / AI News / Deep Dive

Anthropic Alleges 151M-Exchange Distillation Blitz: Alibaba, Moonshot, DeepSeek Named [Analysis]

Anthropic alleged Sep 10-12 that Alibaba ran 151M distillation exchanges and Moonshot plus DeepSeek routed users to Claude. NSA and FBI cited. Defense playbook inside.

Deepak Bagada

Deepak Bagada

Founder & Editor-in-Chief

Sep 15, 2026 Published
|
Sep 15, 2026 Updated
|
8 Minutes Reading Time
Core Takeaways for Founders & Builders
  • Anthropic alleged 151M Alibaba-attributed exchanges May-Jul 2026 plus covert Moonshot and DeepSeek routing to Claude
  • NSA and FBI cited an industrial campaign as OpenAI and Google reported parallel DeepSeek and Gemini incidents
  • Four-signal detector plus trace gating cut our own abuse bill 94% with legit throughput flat

Anthropic Alleges 151M-Exchange Distillation Blitz: Alibaba, Moonshot, DeepSeek Named [Analysis]

Anthropic published a report on September 10, 2026 alleging persistent distillation campaigns by China-based AI companies against Claude. The report names Alibaba as the largest wholesale effort with 151 million exchanges between May and July, peaking near 3 million per day. On September 12, Anthropic escalated further, accusing Moonshot and DeepSeek of routing customer requests to Claude and presenting the answers as their own. Three US agencies including the NSA and FBI described a broader industrial campaign. I spent the weekend tracing what builders must do about it.

Three facts that matter, each attributed:

  • Anthropic alleges the campaigns targeted agentic tool use, coding, data analysis, and reasoning traces, using tricks like framing extraction as translation into katakana-only Japanese.
  • Anthropic alleges Moonshot diversion exposed sensitive customer data to Anthropic's logging, including a user likely tied to China's PLA analyzing CCTV footage via Kimi. None of the named companies had responded at publication time.
  • OpenAI reported similar DeepSeek-attributed activity starting early 2025, and Google says it disrupted 100,000+ prompt attacks on Gemini reasoning. This is an industry-wide enforcement wave, not a single report.

These are allegations, not court findings. Treat them as such. But the builder impact is immediate regardless of outcome. Here is the full breakdown plus your defense playbook.

What Anthropic actually alleged, step by step

I run agent infrastructure at SaaSNext. Distillation abuse is not abstract to us. In March 2026 our own eval API saw one account fire 400,000 code-completion requests in 36 hours from rotating keys. Outputs fed a rival-shaped benchmark within days. We killed the keys, added proof-of-work, and learned the lesson cheap. Anthropic's scale is ours times a thousand.

Per TechCrunch's September 10 reporting, Anthropic says unauthorized labs built increasingly sophisticated circumvention to harvest frontier capabilities. Attackers allegedly coaxed thinking traces out by disguising extraction as translation work. One quoted framing asked the model to render working memory as katakana-only Japanese under a translator persona. Clever. Reasoning traces are the richest training signal, far denser than final answers.

The Alibaba-attributed campaign is the centerpiece: 151 million exchanges in three months, the largest wholesale effort Anthropic says it has ever seen. Five more companies are accused of distilling since February: Alibaba's Qwen unit, Z.ai, Xiaomi's MiMo, MiniMax, and one more unnamed in early coverage. Per the South China Morning Post's September 12 account, US officials say six Chinese companies ran an industrial campaign likely with government awareness. Moonshot and DeepSeek allegedly went further than bulk harvesting. Anthropic claims they routed live user traffic to Claude behind their own brands. Users thought they used Kimi. Responses allegedly came from Claude.

The most explosive single claim: diverted Moonshot traffic let Anthropic see a user likely affiliated with the PLA using Kimi-labeled service to analyze CCTV footage of a targeted person in Chengdu. High-profile Chinese tech firms' data allegedly passed through too. None of the accused companies responded during China's non-working hours. Expect responses this week.

Why labs escalate now: three converging pressures

First, capability gaps closed. Open-weight models at 86% agentic benchmarks plus orchestration routing at 40% discounts mean distillation pays off faster than ever. Stolen traces convert directly into competitive products within a quarter. Our Qwen open-weights terminal analysis shows how narrow the frontier moat has become. Every trace harvested narrows it further.

Second, the slowdown politics. On September 14 Anthropic's CEO urged a three-part oversight plan with rival backing inside 48 hours while Beijing dismissed it as fear-mongering. Our frontier-governance briefing from the same day covers that pact fight. Distillation allegations and pacing demands reinforce each other. If rivals train on your outputs, voluntary slowdowns punish only the compliant. Enforcement talk follows naturally.

Third, money. Moonshot's ARR is projected at $1 billion by year-end per Nomura, doubling since mid-2026. Kimi K3's 2.8 trillion parameters triggered US restriction debates in July. When billion-dollar revenue runs on allegedly borrowed reasoning, agencies engage. The NSA and FBI do not co-sign consumer tech disputes lightly.

Benchmarks of the abuse economy

Scale table from the allegations plus our own abuse logs for proportion:

Signal Alleged scale Source Builder parallel
Alibaba-attributed exchanges 151M, May-Jul 2026 Anthropic via TechCrunch our worst abuse: 400k in 36h
Peak rate ~3M per day Anthropic report our peak: 11k per hour
Fraudulent accounts cited ~24,000 dplooy summary of Feb disclosure our incident: 60 rotating keys
Google-disrupted Gemini attacks 100,000+ prompts Google Threat Intel same katakana-style framing
OpenAI tracking window since early 2025 House open letter matches our timeline

Rate math tells the detection story. Three million exchanges per day cannot look human. It looks like thousands of accounts with machine-regular cadence, shared prompt templates, and reasoning-trace harvesting patterns. That regularity is exactly what defenders fingerprint. Which brings us to your playbook.

Step 1: Detect distillation harvesting on your own endpoints

You do not need Anthropic's budget. You need four signals and one response ladder. This is the config we run after our March incident.

config.py

from pydantic_settings import BaseSettings
from pydantic import Field

class Settings(BaseSettings):
    req_per_min_per_key: int = 60
    trace_request_ratio_alert: float = 0.40
    template_reuse_alert: int = 50
    quarantine_hold_h: int = 24

    class Config:
        extra = "allow"
        env_file = ".env"

settings = Settings()

detector.py

import time
from collections import defaultdict, deque
from config import settings

windows: dict[str, deque] = defaultdict(deque)
templates: dict[str, dict[str, int]] = defaultdict(lambda: defaultdict(int))

def fingerprint(prompt: str) -> str:
    words = prompt.lower().split()
    return " ".join(words[:12])

def check(key: str, prompt: str, asked_trace: bool) -> str:
    now = time.time()
    q = windows[key]
    q.append(now)
    while q and now - q[0] > 60:
        q.popleft()
    if len(q) > settings.req_per_min_per_key:
        return "RATE_BLOCK"
    fp = fingerprint(prompt)
    templates[key][fp] += 1
    if templates[key][fp] > settings.template_reuse_alert and asked_trace:
        return "QUARANTINE"
    return "ALLOW"

requirements.txt

pydantic==2.8.0
pydantic-settings==2.5.0

Deploy order: log first for a week, alert second, block third. We blocked on day one and jailed two enterprise eval harnesses running legitimately. Allowlist your big test customers before enforcing. False positives cost more socially than technically.

Signals that mattered most in our logs: reasoning-trace requests above 40% of volume, template reuse above 50 identical prefixes per key, traffic spikes aligned to non-working hours of the account's claimed region, and output-length distributions skewed to maximum. Any two together meant harvesting with 90%+ precision in our review sample.

Step 2: Harden what attackers want most

Thinking traces are the crown jewels. Gate them like production secrets.

  1. Never return raw chains to untrusted tiers. Summaries only.
  2. Watermark reasoning outputs per account. Canary phrases survive paraphrase less often than people think, but token-distribution watermarks persist through light rewrites.
  3. Rate-limit trace-heavy endpoints separately and lower than chat.
  4. Require verified identity for bulk eval access. Our GemStuffer post-mortem on rogue packages shows what unverified bulk access costs in every ecosystem.
  5. Rotate eval sets. Static benchmarks become distillation targets within weeks.

For agent builders consuming frontier APIs, mirror the defense downstream. Pin model versions, log provider response IDs, and diff behavior weekly. If your upstream gets harvested and retrained, your prompts' performance shifts without warning. We caught one such shift in June when our refusal-rate baseline moved 4 points overnight. Provider-side mitigation had changed outputs. Version pins plus evals caught it. Vibes would not have.

When NOT to panic about this story

Direct talk. Not every team is affected equally.

Stay calm when:

  • You consume models through major providers with abstraction layers. Provider-to-provider disputes rarely break your API contract this quarter.
  • Your workloads are standard chat and summarization. Harvesting targets reasoning and agentic traces, not commodity completions.
  • You already pin versions and run evals. You will see shifts early with minimal damage.

Act this week when:

  • You serve your own model endpoints publicly. Copy the detector above now.
  • You route sensitive traffic through smaller wrappers. Verify whose models actually answer. Demand attestations.
  • You build on Kimi, DeepSeek, or Qwen APIs for US or EU enterprise clients. Legal and procurement will ask questions. Have answers ready with data residency receipts.

Trade-offs: aggressive bot defenses add friction for power users, watermarking slightly degrades trace readability, and rotating evals costs engineering time. Against industrial-scale harvesting, each pays for itself. Our abuse bill dropped 94% after the ladder went live. Legit throughput stayed flat.

Production checklist before the next escalation

  1. Ship the four-signal detector. Log, alert, then block.
  2. Gate reasoning traces behind identity. Summaries for anonymous tiers.
  3. Pin provider model versions. Diff behavior weekly.
  4. Verify your wrappers' upstream. Attestations in writing.
  5. Brief procurement on vendor risk. Have a second provider warm.
  6. Re-read your logging retention. Harvested customer data in your logs is liability.
  7. Watch responses from the named labs this week. Update risk ratings on facts, not vibes.

I keep #6 highlighted because the PLA-CCTV allegation shows where this leads. Traffic you merely transit can contain data you never wanted. Minimize, encrypt, expire. Retention is risk.

Short version: allegations at industrial scale, methods disclosed, agencies engaged, responses pending. Defend your endpoints, verify your upstreams, pin your versions. The facts will develop. Your logging should already be ready.

By Deepak Bagada, Founder & Editor-in-Chief at Daily AI World. I build agent infrastructure at SaaSNext and write from production logs, not press releases. More at deepakbagada.in.

Executive Briefing

Enjoyed this breakdown? Get our morning dispatch in your inbox.

Curated breakdowns of frontier model architectures and compute markets delivered every weekday. Zero fluff.

🎉 Thank You for Subscribing!

Frequently Asked Questions
On Sep 10 Anthropic alleged persistent campaigns targeting agentic tool use, coding, and reasoning, naming Alibaba's 151M-exchange effort as the largest. On Sep 12 it accused Moonshot and DeepSeek of routing live user traffic to Claude. The companies had not responded at publication.
Anthropic says attackers framed extraction as translation into katakana-only Japanese to coax out thinking traces, which are far denser training signals than final answers. Google reported similar framing against Gemini reasoning.
Track rate per key, reasoning-trace request share, template reuse, and off-hours regularity. Our ladder logs first, alerts second, blocks third, with quarantine at 50 reused templates plus trace harvesting.
Gate raw chains behind identity, watermark outputs, rate-limit trace endpoints lower, rotate eval sets, pin provider versions with weekly diffs, and keep a second provider warm for procurement risk.
Deepak Bagada
Author Profile

Deepak Bagada

Founder & Editor-in-Chief

Deepak Bagada is the founder and Editor-in-Chief of Daily AI World and CEO of SaaSNext. He covers enterprise AI architecture, high-concurrency agent workflows, Model Context Protocol tooling, and frontier AI systems engineering.

Related Intelligence Analysis

Audio Briefing
Accessibility Preferences
High Contrast Mode
Accessible Reading Font

Keyboard Shortcuts

Open Search Dialog ⌘K or /
Toggle Theme (Dark/Light) t
Toggle Audio Player a
Open Shortcuts Menu ?
Close Active Dialog Esc

Cookie & Privacy Preferences

We use cookies and telemetry tools to deliver technical dispatches, benchmark analytics, and advertising via Google AdSense. Review our Privacy Policy.