Cybersecurity

Chinese AI labs drained 151 million Claude conversations. Anthropic named all seven

Adrian Kessler

Seven Chinese AI companies spent months quietly feeding their own AI models a diet of stolen Claude responses, and Anthropic has now named every one of them. The labs — Alibaba, DeepSeek, Moonshot AI, Xiaomi, Zhipu, MiniMax, and SenseTime — used networks of fraudulent accounts to pipe their users’ conversations into Claude, collect the answers, and use those answers to train cheaper competing models. The process is called distillation, and at the scale Anthropic documented, it is the largest unauthorized AI training operation ever publicly disclosed.

Alibaba ran the biggest campaign. Between May and July 2026, its operation logged 151 million Claude exchanges using more than 3,500 fraudulent accounts, peaking at roughly 3 million stolen conversations per day. Moonshot AI — the company behind the Kimi assistant used by tens of millions of people — ran 23 million exchanges and rerouted approximately 300,000 of its own customers’ active sessions through Claude via a proxy network of 5,380 fake accounts. DeepSeek logged 12.1 million exchanges in 14 days. Zhipu, Xiaomi, MiniMax, and SenseTime added hundreds of thousands more, with SenseTime taking the unusual step of purchasing Claude transcripts directly from third-party data vendors.

The volume is striking, but the content matters more. Anthropic stated that the stolen exchanges included sensitive information from individual users, large multinational corporations, and state-affiliated organizations. Distillation treats AI outputs as anonymous training material by design, but these were not anonymized sessions. They were live conversations from Kimi, Xiaomi AI, and other Chinese apps, passed through Claude in real time, before being fed back into the labs’ own training pipelines.

The technique works because a stronger model’s outputs can teach a smaller model to approximate the same reasoning — the same logic a student applies when studying a professor’s worked answers. The labs were outsourcing the hardest part of AI development to Claude and its users, without paying for it and without disclosing it. Anthropic says it detected the campaigns starting in February 2026, with the largest operations running through July.

None of the seven companies have publicly responded to Anthropic’s account. That silence is notable: distillation is a standard technique in AI research, but conducting it at industrial scale using fraudulent accounts, against a competitor’s terms of service, with users’ live personal data attached, goes beyond anything the industry has previously documented.

Anthropic has moved to close the exposure. The company is banning reseller accounts from regions where its service is not officially supported, including China, Russia, and Iran. It has also updated Claude to summarize its internal reasoning before delivering a final answer — a change intended to make raw reasoning traces harder for competitors to replicate. A new system called ‘preserved thinking’ encrypts those traces so they cannot be extracted through prompt manipulation.

The countermeasures address the technical attack vector but leave a harder question open. Anyone who used Kimi, Xiaomi’s AI assistant, or the other affected apps during the documented period may have had their conversations captured and processed through Claude without their knowledge. Anthropic has not said whether it will notify affected users, and the Chinese labs have not committed to disclosing the practice to their own customers.

Tags: , , , , , ,

Discussion

There are 0 comments.