When a user handed the internal code to Kimi, the security case system data to DeepSeek, or the complete programming session left on Xiaomi MiMo, he saw the product interface of the Chinese company.Anthropic’s latest threat intelligence report, however, raised a more impactful allegation: some of these requests may have been forwarded to Claude without the user knowing; Claude’s response and reasoning tracks were then preserved, cleaned up, and re-transformed into training materials for the big Chinese model.

Anthropic describes it as a set of industrialized “illegal evaporation” systems: multiple Chinese AI laboratories by means of agency services, fake accounts, residential agents, one-time mailboxes, virtual payments and stolen API keys bypass the area and account restrictions, massively call Claude, and then extract Claude’s reasoning capabilities back to their model training pipeline.

Anthropic said it has identified and blocked related activities from seven Chinese AI laboratories with “high credibility” since February 2026, naming companies such as Alibaba Qwen, Moonshot AI, DeepSeek, Intelligence/Z.ai and Xiaomi, saying these actions targeted Claude’s most valuable capabilities, including complex reasoning, programming, use of agency tools and long-term task handling.

原始来源 · techcrunch.comTechCrunch:Anthropic披露中国AI实验室大规模蒸馏Claude报道梳理Moonshot、DeepSeek、阿里等被指通过代理账户大规模提取Claude能力的行动。techcrunch.com ↗

What really pushed the matter from intellectual property disputes to privacy and national data security issues is the real user case that Anthropic disclosed.

原始来源 · anthropic.comAnthropic:2026年9月威胁情报报告Anthropic披露中国AI实验室蒸馏、用户请求转发、代理网络及敏感数据案例。anthropic.com ↗

Moonshot AI is said to not only design a test topic for Claude, but directly silently forward Kimi customer requests to Claude.Anthropic said that within a 10-day window, Moonshot sent 300,000 real customer requests to Anthropic through a proxy network of 5,380 fraudulent accounts, the vast majority of which were redirected to Claude Opus; what Kimi users then saw was actually a Claude-generated response.

Anthropic also says that Moonshot saved at least part of these exchanges and established a dedicated "think chain" extraction pipeline.Claude usually doesn't directly return the full internal reasoning, but instead gives a thinking signature.Moonshot is said to save the signature and then open a new session, allowing Claude to restore the signature to the complete reasoning track, thus bypassing Anthropic's original anti-damping design.

Kimi品牌标识。Anthropic称Moonshot AI曾将部分Kimi用户请求转发至Claude,并将相关交换用于模型蒸馏。|来源:SearchYour.AI / Kimi
Kimi品牌标识。Anthropic称Moonshot AI曾将部分Kimi用户请求转发至Claude,并将相关交换用于模型蒸馏。|来源:SearchYour.AI / Kimi

The user data listed in the report is far more sensitive than the normal chat record.Anthropic judged that a user who may be associated with the Liberation Army, thought he was using Kimi, submitted hundreds of surveillance data from cameras to the model, asking for an analysis of whether a target person had “abnormal behavior.”

Another major Chinese state-owned engineer was alleged to have submitted internal code and access credentials that several large Chinese companies still valid when using Kimi to develop internal systems.Anthropic concluded that the user had no way to know that his Kimi request was actually forwarded to Claude.

Between May and July 2026, Anthropic said it observed more than 23 million exchanges of evaporative activity that belonged to Moonshot.This figure is not equivalent to 23 million real user privacy breaches, but it shows a scaled model capability to access channels that far exceed the scale test.

DeepSeek is alleged to have used a similar and more selective mechanism.Anthropic says DeepSeek checks the string of requests that enter the system to identify users who are using DeepSeek through third-party programming tools such as Claude Code, Claude Agent SDK, OpenCode, and labels those high-value users and then delivers some of the requests to Claude Opus.

One of the Chinese tech company employees thought he was analyzing internal documents using DeepSeek, and Anthropic said the request was actually sent to Claude, which includes the complete technical specifications, organizational architecture and strategic goals of a flagship AI project.

DeepSeek标识。Anthropic指控DeepSeek曾将部分用户请求转发至Claude,并进行大规模模型蒸馏。|来源:Wikimedia Commons
DeepSeek标识。Anthropic指控DeepSeek曾将部分用户请求转发至Claude,并进行大规模模型蒸馏。|来源:Wikimedia Commons

Another case involves the Chinese public security system.Anthropic said that an engineer working for a city's public security administration case management system used DeepSeek to develop tools to match personal activity tracks with police records and use citizenship ID numbers as identification fields; some of these requests were subsequently forwarded to Claude.

Anthropic also revealed that DeepSeek had forwarded a request from an IT employee dealing with a government database related to the Russian defense sector to Claude, resulting in a valid credential of a Russian government database being exposed in the content of the request.

Within 14 days of July 2026, Anthropic said it had observed more than 1.2 million exchanges of evaporative activity belonging to DeepSeek. Like Moonshot, DeepSeek was also alleged to use cross-session reproduction to extract Claude’s complete trajectory.

Xiaomi’s approach is described by Anthropic as another pattern. The report says that Xiaomi did not return Claude’s answers directly as MiMo answers to users, but instead saved the complete requests and answers of MiMo users and then sent those sessions back to Claude to generate supervised subtleties and enhanced learning data.

Anthropic said it observed more than 400,000 Claude requests related to Xiaomi across more than 1,500 agency accounts over about 20 days from March to April 2026.Claude was used to rebuild the development environment, clean up multiple sessions into a more training-friendly format, generate new “user request-model response” pairs, and score the quality of the answers.

The report even suggested that Xiaomi could use the MiMo-V2-Pro free trial to attract international developers to generate real session data and then use those sessions to evaporate Claude.Anthropic said mass evaporation activity increased significantly just before the end of the free trial period; the data transmitted included names, contacts, company profiles and other sensitive information, involving at least a dozen languages.

If this judgment is correct, “free trial” is no longer just a market tool, but can also be a gateway to accessing high-quality real training materials. This changes the user’s role in the product fundamentally: he thinks he is a customer and can actually be a provider of training materials at the same time.

The scale of Alibaba’s Qwen-related operations is greater, according to Anthropic, with more than 1.5 billion exchanges attributed to Ali’s evaporation activity between May and July 2026, a peak of 3 million per day, and access to Claude through thousands of fraudulent accounts.

According to the report, Ali-related pipes injected fixed clues into each request, forcing Claude to write the reasoning process into a specific text tag, and then saved these reasoning tracks to oversee fine-tuning data for training Qwen 3.5, 3.6 and 3.7.

But 1.5 billion exchanges can’t be written as “1.5 billion user data breaches.”Anthropic’s core accusation against Ali is that it massively extracts Claude’s reasoning capabilities; it really clearly involves real user requests to be forwarded, such as Moonshot, DeepSeek, and Xiaomi. Mixing these two concepts together will instead mask the most data risks worth tracking.

More notably, these companies are not building completely separate channels behind each other. Anthropic says that after blocking Ali’s first 5,000 fraudulent accounts, the other side quickly switched to the second set of accounts, some of which are still forwarding requests for DeepSeek and Xiaomi at the same time.

Anthropic calls such agency services “transfer stations” – model transfer stations. They massively create fake identity accounts, use fake or stolen credit cards, steal API keys, residential agencies and one-time mailboxes, and disguise requests from unsupported areas such as China as normal overseas users.

The grey supply chain has another business.Anthropic says that some agency service providers will keep their full chat records with the leading U.S. model without users knowing it, and then sell those records to the labs that want to train their own model.So, in the age of big models, a new data black market emerged: it is not a password database that is sold, but the most complete and valuable real workflow between the user and the most advanced AI model.

Intelligence/Z.ai’s case showed that the distortion target was not limited to general reasoning. Anthropic said Intelligence ran Claude’s mind chain cleaning machine through 273 fraudulent accounts in 10 days, accumulated more than 3.4 million exchanges in 17 days, and used Claude to improve the GLM model training process.

The report also said that researchers used open vulnerability datasets to create CTF cybersecurity issues to specialize in testing and extracting cybersecurity capabilities from the leading U.S. model. When attempts to target stronger models failed, researchers turned to protecting the relatively weaker Opus and another U.S. lab model. The model evaporation extended from “enhancing chat capabilities” to obtaining cyber defense capabilities.

Anthropic itself clearly acknowledges that model evaporation is a normal and common training method. The controversy is not about the “teacher model teaches student model” technology itself, but whether it is possible to massively extract competitor capabilities through fraudulent accounts, agency networks and technology evasion controls, and whether it is possible to engage real sessions, corporate secrets and sensitive government data in a training chain without the user knowing it.

原始来源 · anthropic.comAnthropic:如何识别和阻止模型蒸馏攻击Anthropic解释模型蒸馏与其所称隐蔽大规模能力提取之间的区别。anthropic.com ↗

This is in sharp contrast to the data security system established in recent years in China. The Personal Information Protection Law stipulates that the provision of personal information abroad usually requires the corresponding data exit conditions and informs individuals about the receivers abroad, the purposes of processing and the types of information. For personal information processed by state agencies, the law also requires that it be stored in principle in China, and the security assessment and other procedures should be performed.

原始来源 · gov.cn中华人民共和国个人信息保护法中国个人信息跨境提供、敏感个人信息及国家机关处理个人信息的法律规定。gov.cn ↗

If a public security system engineer handed a request containing ID numbers, trajectories and case management data to DeepSeek and eventually entered Claude without the user knowing, then the question is not just how a company trains the model, but whether China's own "data not exit" system is technically bypassed in the AI model call chain.

The same contradiction appears in China's long-held "technology self-reliance" and "autonomous control" narrative. The domestic large model is used as an important sign of China's breakthrough of the U.S. technological blockade, but Anthropic disclosed is a completely different technological ecology: users open Kimi, DeepSeek or MiMo, some high-value requests are sent to Claude in the background; Claude generates reasoning and answers, these results are extracted, cleaned, scored, and flowed back to Chinese model training.

This does not prove that all the capabilities of Chinese big models come from American models.DeepSeek, Qwen, Kimi and others have their own model architecture, engineering optimization and training innovation, and summarize China's AI progress simply as "copying" as lack of technical seriousness.

But Anthropic’s report raises a more specific, and even more difficult to avoid question: When a company sells out its own AI services, is it entitled to pass user data to another model without the user knowing; when these sessions show corporate code, valid credentials, surveillance data, and public security data, is the business interest of pursuing the model capability at the forefront overtaken the user’s data rights.

Anthropic has also said it has blocked related accounts, strengthened authentication, and changed Claude’s reasoning output mechanisms, making it harder to extract a complete trail of thought.

It is truly warning that it has generated a complete set of industrial chains: the front end is the real user, the middle is the domestic model and model transfer station, the other end is the U.S. front-end model, and the final product returns to Chinese laboratories, becoming the data for a new round of model training.

What users see is just a chat box.

Behind the chat box, however, there may be simultaneously agent accounts, cross-border forwarding, thought chain extraction, data storage and training backflow.Anthropic this time disclosure really torn, not only a few Chinese AI companies "divergence" dispute, but a data supply chain that the average user is almost invisible.

In this chain, the weakest link is precisely the user himself: the enterprise knows where the request goes, the agent knows how the request is forwarded, the model company knows how this data is trained to be used, only the person who initially pressed "send" may not know from the beginning to the end to whom their data was really delivered.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.