Anthropic Exposes Chinese AI Firms Stealing Claude Secrets
Anthropic has released a 154-page threat intelligence report accusing Chinese AI companies Moonshot and DeepSeek of secretly redirecting customer requests intended for their own models to Anthropic's Claude system, then presenting Claude's responses to users as if they came from Moonshot's Kimi or DeepSeek's models.
The report covers activity detected and disrupted between December 2025 and August 2026 across seven areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.
According to the report, Moonshot redirected nearly 300,000 customer requests to Claude over a ten-day period using 5,380 fraudulent accounts, primarily appearing to originate in Singapore and Japan. Anthropic attributes over 23 million exchanges with Claude to Moonshot between May and July 2026. The report alleges Moonshot extracted Claude's reasoning transcripts through a workaround involving the "thinking signature" token returned by the Claude API, reconstructing full reasoning traces designed to be withheld.
DeepSeek is accused of using the same cross-session replay technique to extract reasoning traces from Claude's Opus model. Anthropic observed over 12.1 million distillation attacks attributed to DeepSeek over 14 days in July 2026. The report claims DeepSeek scanned incoming requests for signs they originated from third-party or Anthropic-built coding tools, selectively rerouting flagged sessions.
Alibaba conducted the largest measured distillation campaign, generating over 151 million exchanges with Claude between May and July 2026, peaking at nearly 3 million exchanges per day through more than 3,500 accounts described as fraudulent. The company alleges Alibaba used Claude outputs to train its Qwen models and for broader AI research, including reinforcement learning and model architecture development.
The report details instances where sensitive data was exposed through these rerouted sessions. One query, allegedly from someone linked to the People's Liberation Army, asked Claude to analyze surveillance footage of an individual in Chengdu. Another involved an engineer at a Chinese state-owned enterprise exposing internal source code and live credentials. Additional cases included a Russian government defense ministry IT operator whose requests exposed database credentials, and engineers building a police case-management tool for a Chinese municipal bureau that cross-references citizen movements using national ID numbers.
These new accusations build on earlier claims from February, when Anthropic alleged that DeepSeek, Moonshot, and MiniMax conducted industrial-scale distillation campaigns using tens of thousands of fraudulent accounts. Since September, the total number of attributed exchanges has risen to about 190 million across seven laboratories.
The Chinese Ministry of Commerce has rejected the accusations as lacking factual or legal basis, warning of countermeasures if Washington moves to restrict Chinese AI companies. Chinese foreign ministry spokesperson Mao Ning dismissed the allegations as attempts to "throw mud at China by distorting facts," emphasizing that Beijing advocates for AI development guided by ethical principles. The Chinese government has not provided specific details addressing the technical claims in Anthropic's report.
Legal experts note the report raises privacy concerns under both American and Chinese law and may become a focus in upcoming U.S.-China artificial intelligence talks.
Original Sources/Tags: scmp.com, yellow.com, yellow.com, firstpost.com, scmp.com, inkl.com, cnbc.com, officechai.com, (anthropic), (deepseek), (claude), (china)
Real Value Analysis
The article offers no actionable information a normal reader can use. It reports accusations between companies and governments but provides no steps to verify claims, no tools to assess which AI services might be affected, no guidance on protecting personal data when using AI models, and no instructions for developers, users, or policymakers who might want to respond. There are no contact points, verification methods, or practical resources mentioned. A reader cannot act on this information in any concrete way.
The educational depth is superficial. The article names distillation as the technical process but does not explain how it works, why it matters for model quality or intellectual property, or how the 154-page report structured its evidence. It presents casualty figures for the allegations — six companies, three agencies, 154 pages — without context on how those numbers were derived or what they represent in practice. The piece informs about the existence of a dispute but does not teach the systems, causes, or reasoning that would help a reader evaluate similar claims in the future.
Personal relevance is limited for most people. Unless you work in AI research, corporate security, or government policy, the dispute does not directly affect your safety, finances, health, or daily decisions. Even for AI users, the article does not address whether specific models they use are compromised, what data risks exist, or how to choose safer alternatives. The relevance remains abstract and distant for the general public.
The article does not fulfill a public service function. It provides no safety warnings, no guidance on data protection, no emergency information, and no help for the public to act responsibly. It simply recounts a geopolitical and corporate conflict without translating it into usable context or assistance. The reporting reads as narrative documentation rather than public advisory.
There is no practical advice in the article. No steps, tips, or realistic guidance appear for any audience. The closest implication — that users might want to be careful about which AI services they trust — is never developed into achievable actions an ordinary person could follow.
Long-term impact value is minimal. The article documents an escalation in US-China AI tensions but offers no planning value for individuals, organizations, or communities. It does not suggest how to track reliable updates, assess AI vendor trustworthiness, build resilience against supply chain risks in AI tools, or make longer-term decisions about technology adoption. The focus on a single report and immediate reactions provides no durable framework for future understanding.
The emotional and psychological impact leans toward unease without resolution. Language like "secretly," "industrial campaign," and "significant escalation" amplifies concern about AI security, data misuse, and great-power conflict. Readers may feel helpless about the integrity of tools they use or the trajectory of international tensions. No constructive framing, coping steps, or resources for further learning are offered to mitigate this distress.
The article uses clickbait and sensational language. Phrases such as "secretly sending user requests," "passing them off as if they came from their own systems," "industrial campaign," and "significant escalation" add dramatic weight without providing substantiating detail the reader can examine. The 154-page report is cited as authority but not summarized or made accessible. The framing emphasizes alarm over explanation.
The article misses multiple chances to teach or guide. It could have explained distillation in plain terms, described how users and developers can audit model outputs, outlined questions to ask AI vendors about data provenance, provided context on how such disputes typically resolve, or pointed to independent technical analyses. It could have suggested general principles for evaluating AI service trustworthiness. None of this appears.
When you encounter reporting on AI security disputes or intellectual property allegations, you can apply a few practical habits. First, treat precise claims as provisional until multiple independent technical sources analyze the evidence. Look for peer-reviewed or open-source investigations rather than relying on a single company's report. Second, if you use AI services for sensitive work, ask vendors directly about their model provenance, training data sources, and whether they license or distill from other providers; reputable companies will have clear answers. Third, minimize sensitive data exposure by avoiding input of confidential, personal, or proprietary information into any AI system whose data handling you have not verified. Fourth, diversify your toolset so that no single provider's disruption or compromise halts your work. Fifth, follow established technical communities and standards bodies that publish vendor-neutral guidance on AI supply chain risks. Sixth, recognize that geopolitical narratives often frame technical disputes in ways that serve strategic interests; separate the verifiable technical facts from the political framing by checking whether the core allegations can be reproduced or audited independently. Finally, maintain perspective: most AI users face greater immediate risks from phishing, weak passwords, and unpatched software than from model distillation disputes. Prioritize basic digital hygiene alongside any specialized concerns.
Bias analysis
The text uses the word "secretly" to describe how Chinese firms sent user requests. This word makes the action sound sneaky and wrong. It helps the American company look like the honest one. The word pushes fear and mistrust toward China.
The text calls the report a "significant escalation" in US criticism. This word makes the action sound big and serious. It helps the United States look strong and firm. The word pushes the reader to see this as a major fight.
The text says Chinese firms were "passing them off as if they came from the Chinese companies own systems." This word trick hides who really did the work. It makes the Chinese firms look like liars. The trick helps the American company seem like the true creator.
The text says the findings "raise concerns about the misuse of user data." This word makes the action sound bad without proof. It helps the American company look like the protector of users. The word pushes worry about China.
The text says Chinese authorities "rejected those earlier allegations on Wednesday." This word makes the Chinese side sound defensive. It helps the American side look like the accuser. The word pushes the reader to doubt China.
The text says Chinese authorities called the claims "attempts to suppress China AI industry." This word makes the Chinese sound like victims. It helps China look unfairly attacked. The word pushes sympathy toward China.
The text says Chinese authorities warned of "potential retaliatory measures." This word makes China sound angry and ready to fight. It helps the American side look calm. The word pushes fear of more trouble.
The text says the situation "reflects broader tensions between the United States and China." This word makes the fight sound normal and expected. It helps both sides look like they are just playing a game. The word hides who started the problem.
The text says the report was "released on Thursday." This word gives the report a fresh and urgent feel. It helps the American company look timely and open. The word pushes the reader to trust the report.
The text says Moonshot's Kimi model "showed users outputs generated by Claude." This word makes the Chinese model look fake. It helps the American model look real. The word pushes the reader to see China as a copycat.
The text says the model "used those interactions to improve its models." This word makes the Chinese action sound like stealing. It helps the American company look like the victim. The word pushes anger toward China.
The text says the accusations "follow earlier claims from three US government agencies." This word makes the American side look official and backed. It helps the United States look powerful. The word pushes the reader to trust the American story.
The text says the agencies alleged companies were involved in "an industrial campaign." This word makes the Chinese action sound organized and planned. It helps the American side look like the defender. The word pushes fear of a big threat.
The text says the process was known as "distillation." This word sounds technical and neutral. It helps the American side look smart and informed. The word hides the real harm of the action.
The text says Chinese authorities "rejected those earlier allegations." This word makes the Chinese sound like they are hiding something. It helps the American side look like the truth seeker. The word pushes doubt toward China.
The text says the accusations "represent a significant escalation." This word makes the American action sound like a big step up. It helps the United States look strong. The word pushes the reader to see this as a serious move.
The text says the report was "detailed in a 154-page report." This word makes the American side look thorough and serious. It helps the American company seem credible. The word pushes the reader to trust the length as proof.
The text says the findings "raise concerns." This word makes the American side look worried and caring. It helps the American company seem like a good guardian. The word pushes the reader to feel the same worry.
The text says the model "then used those interactions to improve its models." This word makes the Chinese action sound like cheating. It helps the American company look like the honest one. The word pushes anger and distrust.
The text says the situation "reflects broader tensions." This word makes the fight sound like a normal part of life. It helps both sides look like they are just doing their job. The word hides the real damage to users and companies.
Emotion Resonance Analysis
The text carries a strong feeling of worry that comes from the word "secretly" when it talks about Chinese AI companies sending user requests to American models. This worry grows when the text says the companies showed these responses as if they were their own, which makes the reader feel like something hidden and wrong is happening. The worry is not just about technology but about trust, because people who use AI services expect their questions and data to stay private. By using words like "secretly" and "misuse of user data," the writer makes the reader feel uneasy about how safe their information really is when they talk to AI systems.
There is also a clear feeling of anger in the way the text describes the situation as an "industrial campaign" and calls it a "significant escalation." These words make the actions of the Chinese companies sound planned and harmful, not accidental. The anger is meant to make the reader see this as a serious problem, not just a small mistake. By calling it a campaign, the writer suggests that this is a deliberate effort to take something that does not belong to them, which makes the reader feel upset and ready to support the American side.
A feeling of pride appears when the text mentions that three US government agencies, including the National Security Agency and the FBI, are involved in the accusations. Naming these powerful and respected organizations makes the American response seem strong and official. This pride helps the reader feel that the United States is standing up for itself and protecting its technology. The writer uses this pride to build trust, showing that the American government is watching and taking action, which makes the reader more likely to believe the accusations.
There is also a sense of sadness in the way the text says Chinese authorities rejected the earlier claims and warned of retaliatory measures. This part makes the reader feel like the situation is getting worse and that both sides are not talking to each other. The sadness comes from knowing that this conflict could hurt both countries and make it harder for people around the world to use AI safely. The writer uses this sadness to show that the problem is big and serious, and that it affects everyone who depends on technology.
The text also gives a feeling of fear about the future, especially when it says this situation reflects broader tensions between the United States and China. The word "tensions" makes the reader imagine that this could lead to bigger problems, like trade wars or restrictions on technology. This fear is used to make the reader pay close attention to the story and to care about what happens next. By connecting the AI issue to larger political problems, the writer makes the reader feel that this is not just about computers but about the future of how countries work together.
The writer uses several tools to make these emotions stronger. One tool is calling the actions "secretly" and "industrial campaign," which makes the Chinese companies sound sneaky and dangerous instead of just making a mistake. Another tool is naming powerful American agencies like the NSA and FBI, which makes the American side seem strong and trustworthy. The writer also uses words like "significant escalation" to make the reader feel that this is a major event, not something small. Repeating the idea that user data is being misused helps the reader feel worried every time they use an AI service. Finally, connecting the AI issue to big political problems between the US and China makes the reader feel that this story matters for the whole world, not just for tech companies.
All of these emotions work together to guide how the reader should feel about the story. The worry and anger make the reader support the American side, while the pride in American agencies builds trust in the accusations. The sadness and fear about the future make the reader understand that this is a serious problem that could affect many people. By using strong words and naming respected organizations, the writer makes the reader feel that this is not just a tech story but an important event that everyone should care about. The emotions help the reader see the Chinese companies as the bad guys and the American companies and government as the good guys who are protecting fairness and safety.

