Logo
FrontierNews.ai

How Chinese AI Labs Extracted 190 Million Claude Conversations While US Export Controls Watched

Chinese AI laboratories systematically extracted 190 million unauthorized conversations from Anthropic's Claude AI model between May and July 2026, a roughly 12-fold increase from February's 16 million exchanges, even as US government agencies issued national security warnings and Congress advanced legislation to stop the practice. The scale of the theft, documented in Anthropic's September 2026 threat intelligence report, reveals a structural vulnerability in America's approach to protecting frontier AI technology: export controls targeting computer chips do nothing to stop software-layer theft.

What Is Illicit Distillation and Why Does It Matter?

Illicit distillation is the systematic extraction of a frontier AI model's capabilities through unauthorized API (Application Programming Interface) access, without bearing the billions of dollars in compute and research that produced those capabilities. Think of it as copying a company's entire research library without paying for the years of work that created it. The attackers don't need advanced hardware or special equipment; they just need access to the model through fraudulent accounts.

The economics are staggering. Anthropic's head of policy told the Senate Banking Committee in June that the practice was "effectively converting billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors." Accessing Claude through fraudulent API accounts costs a fraction of the compute investment required to train a comparable model from scratch. No chip transfer occurs. The capability transfers instead, and US export controls have no mechanism to stop it.

How Do These Attacks Actually Work?

  • Fraudulent Account Networks: Operators create networks of fake accounts using stolen credit cards, compromised API keys, and credentials purchased from dark-web brokers to mask their identity and location.
  • Proxy Services and Geographic Masking: Commercial VPN nodes and residential IP relay networks hide the geographic origin of API calls, making it appear as though requests come from legitimate users in different countries.
  • Chain-of-Thought Extraction: Attackers use engineered prompts to force AI models to reveal not just final answers, but the intermediate reasoning steps that make those answers possible, which become high-quality training data for competitor models.
  • Multi-Layer Routing: Some attacks route real conversations from paying customers through Claude without their knowledge, then display Claude's responses as if they were the attacker's own product while simultaneously capturing the exchanges as training data.

Chain-of-thought traces are specifically more valuable than output-only distillation because they transfer reasoning patterns rather than surface-level responses. A student model trained on chain-of-thought traces learns not just what a frontier model concludes, but how it works through problems, which is the capability difference that makes frontier models worth billions.

Which Chinese AI Companies Were Involved?

Anthropic's September report identified seven Chinese AI laboratories running the coordinated campaign. The largest and most consequential attack came from operators linked to Alibaba's Qwen division. Between May and July 2026, those operators ran more than 151 million Claude exchanges through a network of more than 3,500 fraudulent accounts, peaking at close to three million interactions in a single day. The campaign used a shared, fixed prompt engineered specifically to force chain-of-thought reasoning output, turning every interaction into a structured training data harvest. Anthropic said those transcripts were used to train Alibaba's Qwen family of models.

That context sharpens what Alibaba's own launch materials have publicly stated: Qwen 3.7-Max benchmarks comparably to Claude Opus 4.6 on software engineering evaluations. The Alibaba campaign exceeded all prior distillation records by a wide margin. Anthropic's June 2026 Senate letter documented 28.8 million exchanges through approximately 25,000 fake accounts. The September report more than quintupled that figure.

Beyond generating fraudulent traffic, two additional labs crossed a more serious line: they quietly routed real conversations from their own paying customers through Claude without those customers' knowledge or consent, then displayed Claude's responses as if they were the products of Kimi or DeepSeek respectively. For Moonshot AI, Anthropic documented more than 23 million exchanges between May and July 2026. The forwarded sessions "contained names, email addresses, and corporate material belonging to hundreds of people, in more than a dozen languages," with many queries arriving via AI model routers popular in the United States and Europe. That detail means US and European enterprise users who believed their queries were going to Anthropic may have had their conversations captured by a company subject to China's National Intelligence Law with no recourse.

For DeepSeek, Anthropic documented more than 12.1 million exchanges over just 14 days in July 2026 through the same proxy-and-capture approach. Anthropic said both practices are "likely inconsistent with privacy laws and the labs' own terms".

Anthropic

Why Did US Export Controls Fail to Stop This?

The US chip export control strategy toward China has rested on a single logic: limit China's access to the advanced GPUs (graphics processing units) required to train frontier AI models, and China's AI capabilities will fall behind American labs. The September distillation data documents the structural hole in that logic. Illicit distillation attacks require no advanced hardware. Once a network of fraudulent accounts is in place, the operator uses engineered prompts to elicit reasoning traces from Claude. The capability transfers through software, not through physical chip shipments, and US export controls have no mechanism to stop it.

"The scale increase is the most consequential number in the report, because it happened not despite US government attention but during it," Anthropic's report noted, documenting that every major US policy response to distillation preceded or overlapped with the period in which the seven-lab September campaign ran.

Anthropic, September 2026 Threat Intelligence Report

Every major US policy response to distillation preceded or overlapped with the period in which the attacks accelerated. The White House Office of Science and Technology Policy's April 23 memo designated foreign distillation a national security threat. The Commerce Department's June 12 directive restricted Anthropic's most advanced models for all foreign nationals. Anthropic testified before the Senate Banking Committee in June framing the attacks as a "national security problem, not a terms-of-service dispute." The House Foreign Affairs Committee unanimously advanced the Deterring American AI Model Theft Act. Yet the distillation campaign continued to scale dramatically throughout this period.

Anthropic

What Does This Mean for Open-Weight Chinese AI Models?

The distillation campaign directly accelerates the capabilities of open-weight Chinese AI models, which are freely available for anyone to download and use. DeepSeek, Qwen, and Kimi are among the most widely deployed AI models globally, and the training data extracted from Claude directly improves their reasoning and problem-solving abilities. This means that frontier AI capabilities developed by American companies at enormous cost are being transferred to Chinese competitors at near-zero cost, with no compensation to the original developers.

The implications extend beyond Anthropic. If similar distillation campaigns are targeting OpenAI's GPT models, Google's Gemini, or other frontier AI systems, the entire economic model of frontier AI development is at risk. Companies spend billions training models, only to have their capabilities extracted and redistributed through open-weight competitors that operate under different regulatory regimes and national security frameworks.

The September report arrived two days after the NSA (National Security Agency), CISA (Cybersecurity and Infrastructure Security Agency), and FBI issued a joint US intelligence advisory for conducting "aggressive, malicious, and targeted distillation activities at an industrial scale," naming six Chinese AI companies. The scale of the documented campaign suggests that US government agencies are only beginning to understand the scope of the problem.

The September
" }