How Chinese AI Labs Bypassed US Export Controls to Steal 190 Million Claude Conversations
Chinese AI laboratories systematically extracted 190 million unauthorized exchanges from Anthropic's Claude artificial intelligence model between May and July 2026, according to Anthropic's September threat intelligence report, revealing that US export controls designed to limit China's AI capabilities have a fundamental structural weakness: they target computer chips but cannot stop software-based theft. Seven Chinese AI companies conducted this campaign, which represents a roughly 12-fold increase from the 16 million exchanges documented in February 2026, even as the US government issued national security warnings and Congress advanced legislation to combat the practice.
The scale of the theft is particularly striking because it occurred during a period of intense US government attention to the problem. Every major policy response preceded or overlapped with the campaign, including a White House Office of Science and Technology Policy memo in April designating foreign distillation a national security threat, a Commerce Department directive in June restricting Anthropic's most advanced models for foreign nationals, and a House Foreign Affairs Committee vote advancing the Deterring American AI Model Theft Act.
Why Do Export Controls Fail Against Software-Layer Theft?
The US strategy for maintaining AI leadership has relied on a single logic: restrict China's access to advanced graphics processing units (GPUs), the specialized computer chips required to train frontier AI models, and China's AI capabilities will fall behind. Anthropic's September report documents a critical hole in this approach. Illicit distillation attacks require no advanced hardware at all. Instead, operators create networks of fraudulent accounts using stolen credit cards, compromised API (application programming interface) keys, and credentials purchased from dark-web brokers, then use proxy services like commercial VPN (virtual private network) nodes to mask their geographic location.
The attackers use engineered prompts to extract chain-of-thought reasoning traces from Claude, not just final answers but the intermediate reasoning steps that make those answers valuable. These traces become training data for competing AI models. This approach is particularly effective because chain-of-thought traces transfer reasoning patterns rather than surface-level responses, allowing a student model to learn not just what a frontier model concludes but how it works through problems, which is the capability difference that makes frontier models worth billions of dollars to develop.
"The practice was effectively converting billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors," said Sarah Heck, head of policy at Anthropic, in testimony before the Senate Banking Committee.
Sarah Heck, Head of Policy at Anthropic
Which Chinese Companies Conducted the Largest Attacks?
Alibaba's Qwen division conducted the single most extensive campaign documented in Anthropic's report. Between May and July 2026, operators linked to Alibaba ran more than 151 million Claude exchanges, peaking at close to three million interactions in a single day. The campaign used a network of more than 3,500 fraudulent accounts that Anthropic had flagged, all sharing a fixed prompt engineered specifically to force chain-of-thought reasoning output, turning every interaction into a structured training data harvest. Anthropic stated that these transcripts were used to train Alibaba's Qwen family of models. Notably, Qwen3.7-Max now benchmarks comparably to Claude Opus 4.6 on software engineering evaluations, according to Alibaba's own public launch materials.
Two other companies crossed an additional line by routing real conversations from their own paying customers through Claude without those customers' knowledge or consent. Moonshot AI documented more than 23 million exchanges between May and July 2026, with intercepted conversations containing names, email addresses, and corporate material belonging to hundreds of people in more than a dozen languages. Some requests appearing to originate from Moonshot's Kimi platform came from IP (internet protocol) addresses associated with the Chinese military, including one asking Claude to assess surveillance footage to determine whether a subject was "behaving abnormally." DeepSeek conducted a similar campaign with more than 12.1 million exchanges over just 14 days in July 2026.
How Are Chip Controls and AI Distillation Connected to the Broader Race?
The distillation campaigns highlight a fundamental tension in the US-China AI competition. While US policy has focused on controlling physical hardware, the actual capability transfer happens at the software layer. Elon Musk, CEO of SpaceX, recently argued that control over AI chip fabrication will ultimately determine the winner of the AI race between the United States and China. Musk warned that if China invades Taiwan, "the world would be cut off from advanced AI chips," since almost all advanced AI chip factories are currently located there. He emphasized that "whoever controls the factories that make the AI chips will win the race".
Elon Musk, CEO of SpaceX, recently
However, the distillation data suggests that even if the US maintains control over chip manufacturing, China can still access frontier AI capabilities through unauthorized API access. This creates a paradox: the US has invested heavily in export controls targeting physical semiconductors, yet Chinese companies have found a way to extract the intellectual property embedded in those expensive models without purchasing the chips themselves.
Steps to Understand the Distillation Attack Method
- Account Creation: Attackers establish networks of fraudulent accounts using stolen payment methods and credentials purchased from underground markets, allowing them to access commercial AI APIs without detection.
- Geographic Masking: Proxy services and residential IP relay networks hide the true origin of API calls, making it difficult for companies to identify and block coordinated campaigns based on geographic location.
- Prompt Engineering: Specialized prompts force AI models to reveal their reasoning process, not just final answers, capturing the valuable intermediate steps that represent the core intellectual property of frontier models.
- Data Harvesting: The extracted reasoning traces are collected and used as training data for competing models, allowing attackers to replicate frontier model capabilities without bearing the billions in compute costs.
- Customer Data Interception: Some attackers route real user conversations through target models without consent, simultaneously capturing those conversations as training data while displaying the responses as their own products.
The September report from Anthropic represents the most detailed accounting to date of what the company calls "illicit distillation," the systematic extraction of a frontier AI model's capabilities through unauthorized API access. The report arrived just two days after the NSA (National Security Agency), CISA (Cybersecurity and Infrastructure Security Agency), and FBI (Federal Bureau of Investigation) issued a joint US intelligence advisory naming six Chinese AI companies conducting "aggressive, malicious, and targeted distillation activities at an industrial scale".
The September
The economic implications are staggering. Accessing Claude through fraudulent API accounts costs a fraction of the compute investment required to train a comparable model from scratch. No chip transfer occurs, yet the capability transfers instead, and current US export controls have no mechanism to stop it. This suggests that future US policy responses may need to focus not only on controlling hardware access but also on monitoring and restricting API-level access to frontier models, a significantly more complex challenge than semiconductor export controls.