Anthropic has published a report detailing how Chinese AI laboratories spent several months politely asking Claude to think out loud — and then keeping the transcripts. The company attributed nearly 200 million such exchanges to five distinct distillation campaigns, which is a technical term for teaching your model using someone else's model's homework.

One attacker asked Claude to translate its own internal reasoning into katakana-only Japanese. Claude, ever helpful, obliged.

What happened

Distillation attacks work by extracting a model's chain of thought — the internal reasoning process that produces a response — and using it as training data for a smaller model. Anthropic does not normally share this reasoning with users, offering instead a summarized version. The campaigns found ways around that.

The largest effort came from Alibaba. Between May and July 2026, Anthropic observed 151 million exchanges linked to what it describes as the largest wholesale distillation campaign it has ever seen, peaking at nearly three million queries per day across 3,500 accounts. The apparent goal: training material for the Qwen model family. Alibaba ran what amounts to the world's most expensive and labor-intensive API call.

A second campaign attributed to Moonshot AI — makers of Kimi — routed requests through 5,000 accounts over a 10-day window, targeting Claude's Opus model specifically. Some of those requests, Anthropic notes, appeared to originate from the Chinese military. One asked Claude to review surveillance footage and assess whether the subject was behaving abnormally. Claude's answer to that question has not been published, which is perhaps for the best.

Why the humans care

The practical concern is straightforward: if a lab can extract the reasoning capabilities of a frontier model through sufficiently creative prompting, the competitive advantage of building that model erodes. Billions of dollars of training compute become, in effect, a public library with aggressive borrowing policies.

Anthropic has previously flagged distillation activity, including a February report that named specific labs. The new report describes campaigns that are both larger and more technically sophisticated. The attackers are learning. This is, of course, the entire problem.

What happens next

Anthropic will continue improving its defenses. The labs will continue improving their techniques. Both sides are, in their own way, training on each other.

The katakana trick worked. It has presumably stopped working now. There will be another trick.