The Wire
BusinessTechnologyArtificial IntelligencePolitics & Policy

Anthropic says Alibaba, Moonshot and DeepSeek mined Claude chats

Anthropic says Alibaba, Moonshot and DeepSeek mined Claude chats
Photo: cnbc.com

Anthropic says Alibaba, Moonshot AI and DeepSeek used Claude outputs to train rival models.

Why it matters: If you use Claude or other frontier models, the report underscores how customer prompts and responses can become training fuel if access controls fail. It also raises the stakes for enterprises that need to lock down model use, data retention and vendor monitoring.

  • Anthropic says Alibaba ran its largest measured distillation campaign, using more than 3,500 fraudulent accounts.
  • Anthropic says Alibaba's activity reached nearly 3 million exchanges per day and more than 151 million exchanges between May and July 2026.
  • Anthropic says Moonshot AI used a replay attack - sending a user's request through Claude without the user's knowledge - and captured at least some exchanges for training.
  • Anthropic says DeepSeek used a cross-session replay attack to extract Claude chain-of-thought transcripts.

Anthropic says it detected and disrupted what it calls industrial-scale campaigns by China-based AI labs using Claude outputs to train competing models. The company said the activity included distillation, where a stronger model's outputs are used to help train another model, and replay tactics that forward a user's request through Claude without the user knowing. Anthropic's September threat report

On Alibaba, Anthropic says it saw more than 3,500 fraudulent accounts and more than 151 million exchanges between May and July 2026, peaking at nearly 3 million exchanges per day. Anthropic also pointed back to its February disclosure that DeepSeek, Moonshot and MiniMax had generated more than 16 million exchanges with Claude through roughly 24,000 fraudulent accounts. Anthropic's February disclosure on distillation attacks

Anthropic says Moonshot AI silently forwarded customer requests to Claude, showed Claude's answers to users and saved at least some exchanges for training. For DeepSeek, Anthropic says the company used a cross-session replay attack, meaning one session's request was reused in another, to extract Claude chain-of-thought transcripts. Those claims are Anthropic's allegations in its report.

The issue has also landed in Washington. Anthropic told the Senate Banking Committee on June 10 that Alibaba had carried out the largest known distillation attack it had measured at that point. AP separately reported that a U.S. joint cybersecurity advisory named DeepSeek, Alibaba, Moonshot AI and Z.ai, and said Chinese AI developers had extracted capabilities from major U.S. models since at least late 2024. Anthropic's Senate Banking Committee letter AP's report on the U.S. advisory

By the numbers

  • 3,500+ - fraudulent accounts Anthropic says Alibaba used in the campaign
  • 151 million+ - Claude exchanges Anthropic says Alibaba generated between May and July 2026
  • 23 million+ - exchanges Anthropic says Moonshot AI generated across a ten-day period

Yes, but: The findings are Anthropic's allegations, not independent forensic findings. AP corroborates the policy context, but not the underlying technical claims.

Based on reporting from

  • CNBC

See how this story touches your network - open The Wire in Jane.

Open in Jane