Subscribe
16:57Anthropic names seven Chinese labs, 189.9m distilled exchanges and a Russia-linked actor.15:42Revised CLARITY Act runs 630 pages; stablecoin yield section unchanged from July14:35OpenAI launches ChatGPT for Financial Services with Daloopa and PitchBook data built in.14:17OpenAI pauses new $200 ChatGPT Pro sign-ups, seven days after GPT-6 Astra shipped.14:00Coinbase renames Base App back to Coinbase Wallet, adds Robinhood Chain and Monad13:54AMD launches Ryzen 5 5500F at $99 and Ryzen 5 7500 at $189 as DDR4 spot inverts

Anthropic's threat report: 189.9m distilled exchanges, and two Chinese labs that relayed their own users to Claude

The September 10 report names seven China-based labs, a Russian espionage actor whose agents rebuilt malware until it went undetected, and customer data that reached Anthropic by accident.

In briefAnthropic identified and disrupted distillation attacks from seven China-based labs since its February disclosure1Alibaba's campaign peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, over 151 million exchanges May to July 20262Scale by lab: Alibaba 151m, Moonshot 23m, DeepSeek 12.1m, Zhipu 3.4m, Xiaomi 400,0003
Anthropic chief executive Dario Amodei on stage at TechCrunch Disrupt 2023
Photo: TechCrunch (CC BY 2.0)

Anthropic published its threat report on September 10 and put a figure on being copied: 189.9 million exchanges of illicit distillation across five measured campaigns, 151 million of them attributed to Alibaba's Qwen team between May and July, peaking near three million a day from more than 3,500 fraudulent accounts. Seven China-based labs are named since February. The report also describes a Russian espionage actor whose AI agents rebuilt its malware, unsupervised, until the security products stopped flagging it.

Exchanges attributed to each lab (millions)
Alibaba151Moonshot23DeepSeek12.1Zhipu3.4Xiaomi0.4

That total is the number the wires led with.

It is probably the least interesting thing in the document.

Here is what almost nobody pulled out. Anthropic says Moonshot and DeepSeek were not merely harvesting Claude — they were quietly serving Claude to their own paying customers, who believed they were talking to Kimi and to DeepSeek. Over one ten-day stretch Moonshot relayed almost 300,000 customer requests to Anthropic through 5,380 fraudulent accounts (mostly, on the account metadata, in Singapore and Japan).

So what does that mean for the customer at the other end?

It means their prompts went to an American company. Anthropic lists some of what arrived: a user it assesses was likely PLA-affiliated, loading CCTV footage from hundreds of cameras in Chengdu — including cameras outside PLA facilities — and asking whether a tracked individual was "behaving abnormally". Engineers at a Chinese state-owned enterprise pasting in live credentials. Engineers building a case-management tool for a municipal Public Security Bureau that compares a person's movements against police records by national ID number. And, through DeepSeek, an IT operator handling data from a Russian government agency tied to its defence ministry, whose relayed requests exposed live credentials for a Russian government database.

Two Chinese labs appear to have spent the spring turning themselves into an intelligence feed for a company in San Francisco.

Not on purpose. That is arguably worse.

Now the Russian case, which is the one a security team should read twice. Anthropic designates it GTG-20006 (their internal label for an actor abusing AI, not a public one) and says the attribution is consistent with public reporting linking the actor to Midnight Blizzard; one operator used the handle "JackPoterz". The toolkit was ordinary enough — two families of Windows implants, a mobile exploitation kit, a browser credential stealer, a phishing platform, an admin console. The loop around it was not.

If their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections. The agents were designed to continue iterating on GTG-20006's toolkit until it was undetected.
Anthropic, "Detecting and countering misuse of AI: September 2026"

More than 20 organisations sat in the actor's planning, reconnaissance or live operations: ministries, defence and intelligence bodies, embassies, think tanks, defence-industrial firms, concentrated in Ukraine and Europe. They bulk-exported the mailboxes of at least two drone component makers and stole a complete software development kit for a drone vision system (the manufacturers are not named), then spent days reverse-engineering it down to the bill of materials and an unannounced product. To reach indirect targets they compromised three vendors running hotel guest WiFi and rewrote DNS records, so a traveller connecting from a lobby handed over their traffic and device identifier.

Our read is that the distillation figures are the part built to be quoted and the detection loop is the part that changes anyone's Monday. Static signatures have been the economic backbone of endpoint security: a defender writes one, and the attacker pays in labour to route around it. An agent that rebuilds a binary until it comes back clean charges that cost to an API meter instead. Anthropic's own line — that sophistication has stopped being a reliable signal of who is behind an operation — is the sentence security vendors will spend a year arguing with. We would expect at least one major endpoint vendor to publish evasion telemetry showing a step change in unique hashes per campaign before the end of the first quarter of 2027. If that data comes back flat, this was a capability demonstration rather than a shift, and we will say so.

You should be sceptical of parts of this, and the reasons deserve saying out loud. Anthropic is grading its own homework, naming commercial rivals on evidence it does not show, in a week when its own safety record is the subject of a viral resignation. No methodology accompanies the attribution of an account cluster to a named company. The distillation section also doubles as an argument for export policy, and Anthropic surely knows it.

Two things pull the other way. Google published an adversarial-distillation threat tracker earlier this year and OpenAI has made the same complaint since early 2025, so this is not one vendor's invention. And the relay findings are the rare accusation the accused party's own customers can check: if you ran a Kimi or DeepSeek session through a coding harness this summer, where your tokens actually went is now a live question, and neither company has answered it.

The report's own footnote is the sharpest bit. A proxy platform serving virologists, blocked by Anthropic's biosecurity classifier while helping draft a chikungunya gain-of-function grant, built a fallback that forwarded refused prompts to a competitor's model. Safety, at that point, is a routing decision made by somebody else.

Sources

01
Anthropic identified and disrupted distillation attacks from seven China-based labs since its February disclosureSince we published our first disclosure in February, we have identified and disrupted additional distillation attacks against Claude from seven labs based in China. All of these attacks targeted our generally available models; we have…” — anthropic.com · primary · Sep 10
02
Alibaba's campaign peaked at nearly 3 million exchanges a day from more than 3,500 fraudulent accounts, over 151 million exchanges May to July 2026Alibaba’s illicit distillation campaign peaked at nearly 3 million exchanges per day launched from more than 3,500 fraudulent accounts. The distillation attacks targeted agentic tasks, software engineering, kernel development, and…” — anthropic.com · primary · Sep 10
03
Scale by lab: Alibaba 151m, Moonshot 23m, DeepSeek 12.1m, Zhipu 3.4m, Xiaomi 400,000Scale of distillation attacks attributable to Alibaba between May and July 2026: over 151 million exchanges observed. […] Scale of distillation attacks attributable to Moonshot between May and July 2026: over 23 million exchanges…” — anthropic.com · primary · Sep 10
Show all 18 sources
04
Moonshot silently forwarded customer requests to Claude and displayed Claude's responses to users who thought they were using KimiWe discovered that Moonshot AI, the company that produces the Kimi family of models, silently forwarded customer requests to Claude, instead of processing them using Kimi. Moonshot then displayed Claude’s responses to users. These users…” — anthropic.com · primary · Sep 10
05
Moonshot relayed almost 300,000 customer requests in ten days through 5,380 fraudulent accounts, mostly in Singapore and JapanIn one instance, over a ten-day period, Moonshot relayed almost 300,000 customer requests to Anthropic, the vast majority of which were routed to Opus. Moonshot used a proxy service network of 5,380 fraudulent accounts, most of which…” — anthropic.com · primary · Sep 10
06
A likely PLA-affiliated user loaded Chengdu CCTV archive data and asked whether the tracked person was behaving abnormallyOne user that we assess was likely affiliated with the PLA used what they thought was Moonshot’s Kimi model to load surveillance data from a CCTV archive about a single targeted individual. The user asked Kimi to analyze the CCTV data to…” — anthropic.com · primary · Sep 10
07
DeepSeek relayed requests from an IT operator working with Russian defence ministry data, exposing live credentials for a Russian government databaseRussian defense agency. DeepSeek relayed requests from an IT operator working with data from a Russian government agency associated with its Ministry of Defense. The relayed requests exposed live credentials for a Russian government…” — anthropic.com · primary · Sep 10
08
DeepSeek engineers building a municipal Public Security Bureau case-management tool had requests relayed to ClaudePRC police surveillance. Engineers building a case management system for a municipal Public Security Bureau in China used DeepSeek, which relayed those requests to Claude. The engineer built a tool that compares a person’s movements…” — anthropic.com · primary · Sep 10
09
GTG-20006 attribution is consistent with reporting linking the actor to Midnight Blizzard; an operator used the handle JackPoterzOur attribution is consistent with public reporting linking the actor to Midnight Blizzard. One of the operators is a Russian speaker using the handle “JackPoterz” whose tradecraft and targeting are consistent with Russian state-nexus…” — anthropic.com · primary · Sep 10
10
The actor's agents autonomously rebuilt malware until it evaded detectionIf their monitoring AI agents identified that any of their deployed malware was detected by a security product, agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing…” — anthropic.com · primary · Sep 10
11
More than 20 organisations were targeted; the toolkit and the drone SDK theftOur investigation identified more than 20 distinct organizations targeted in the actor’s operational planning, reconnaissance, and live operations. They included government ministries, defense and intelligence bodies, embassies and…” — anthropic.com · primary · Sep 10
12
The actor bulk-exported drone component makers' mailboxes and stole a drone vision SDK, reverse-engineering it to the bill of materials and an unannounced productThe actor bulk-exported the mailboxes of at least two drone component manufacturers, targeted a military drone maker, and stole a complete proprietary software development kit for a drone vision system. They spent several days…” — anthropic.com · primary · Sep 10
13
The actor compromised three hotel-WiFi hospitality vendors and hijacked DNS to capture guest trafficto reach their targets indirectly, the actor compromised at least three hospitality vendors that operate hotel guest WiFi. They used compromised admin credentials to modify DNS records so that they pointed to services owned by the actor…” — anthropic.com · primary · Sep 10
14
Anthropic says sophistication is no longer a reliable signal of who is behind an operationFor threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data…” — anthropic.com · primary · Sep 10
15
Google published an adversarial-distillation threat tracker and OpenAI has raised distillation since early 2025Other frontier labs have faced distillation attacks. OpenAI has called attention to this activity since early 2025. Google published a threat tracker on adversarial distillation earlier this year.” — anthropic.com · primary · Sep 10
16
A blocked chikungunya gain-of-function grant request was routed by the platform to a competitor's modelThe developer’s desire to improve the user experience of academic researchers on their platform led them to develop a fallback mechanism that sent sensitive requests that Claude would refuse to answer to a competitor’s model.” — anthropic.com · primary · Sep 10
17
TechCrunch reported the distillation total as nearly 200 million exchanges across five campaignsAll told, the company observed nearly 200 million exchanges linked to distillation attacks, attributed to five separate campaigns.” — techcrunch.com · reported · Sep 10
18
Cointelegraph summarised the report as a disrupted Russia-linked espionage campaign plus seven Chinese labs copying Claude🚨 LATEST: Anthropic says it disrupted a suspected Russia-linked cyber espionage campaign and attempts by seven Chinese AI labs to copy Claude.” — x.com · reported · Sep 10
Up next · Keep readingAI · 3 min read

OpenAI's finance ChatGPT ships with two design partners, no named customer and no price

ChatGPT for Financial Services bundles Daloopa, PitchBook, LSEG and Crunchbase data indexed on OpenAI's own servers, and proves itself on a benchmark made of public Treasury bulletins.

Continue ↓