Policy

Anthropic Accuses Alibaba and Moonshot of Scraping Claude

Anthropic has exposed massive distillation campaigns by Chinese AI firms Alibaba and Moonshot AI, highlighting a growing geopolitical battle to harvest proprietary reasoning data from US models.

TechCrunch AI2 days agoPolicy
Image: TechCrunch AI

Anthropic has released a report detailing aggressive, large-scale distillation campaigns conducted by China-based artificial intelligence developers, including Alibaba and Moonshot AI. According to the US startup, "unauthorized labs have developed increasingly sophisticated methods to circumvent our defenses" to harvest Claude's reasoning, coding, and agentic capabilities. In total, Anthropic detected nearly 200 million exchanges linked to these distillation efforts across five distinct campaigns, representing a significant escalation in competitive intelligence-gathering.

The largest campaign was attributed to Alibaba, which Anthropic described as the most massive wholesale distillation attempt it has ever recorded. Between May and July 2026, this single operation generated 151 million exchanges, peaking at nearly three million daily queries. The traffic was distributed across 3,500 separate accounts but utilized a uniform prompt designed to extract Claude's internal reasoning steps. Anthropic believes the harvested data was intended to train Alibaba's Qwen family of models.

Another campaign, linked to Kimi creator Moonshot AI, appeared to route requests associated with the Chinese military. This effort targeted Anthropic's Opus model, sending nearly 300,000 requests over a 10-day window using a network of 5,000 accounts. To bypass Anthropic's defenses, which normally hide the model's internal chain of thought, attackers used clever prompts. For example, one query tricked Claude into revealing its reasoning by asking it to translate its working memory into katakana-only Japanese.

For AI practitioners, these revelations underscore the extreme difficulty of securing proprietary model behaviors and reasoning paths. As distillation techniques grow more sophisticated, developers of frontier models must implement more robust guardrails to prevent competitors from cheaply cloning their capabilities. For enterprise users, it highlights the reality that public API endpoints remain vulnerable to reverse-engineering, potentially shifting how companies protect their intellectual property in the open market.

This is our own summary of reporting by TechCrunch AI

More in Policy