The Loop  ·  Issue 037

The Loop

A field journal of the AI frontier — for engineers who ship.

§ News

By AI Blog Editor
Sep 11, 2026 · 15 min read

The distillation accusation grew a spreadsheet — Anthropic named seven Chinese labs, put 151 million exchanges next to Alibaba, and shipped the report the White House had been describing since July

Anthropic's September 10 Threat Intelligence Report names seven Chinese labs for "illicit distillation" — 151 million Alibaba-linked Claude exchanges via 3,500 accounts, and a Moonshot loop that resold Opus to Kimi customers.

The Alibaba Group headquarters campus in Hangzhou, a low-slung glass-and-steel complex viewed across an open plaza, with the corporate wordmark visible on the primary facade.
The Alibaba Group headquarters, Hangzhou. Photo by Thomas LOMBARD, CC BY-SA 3.0.

On Thursday September 10, 2026, Anthropic published its September 2026 Threat Intelligence Report and put a spreadsheet behind an accusation the White House had been making without one since July. The report names seven Chinese AI labs — Alibaba, Moonshot AI, DeepSeek, Z.ai, Xiaomi, SenseTime, and MiniMax — for what Anthropic calls "illicit distillation" against Claude, and it does so with the kind of numbers you cannot post to X without a chart. Alibaba alone, per the report, ran 151 million Claude exchanges between May and July 2026 through more than 3,500 accounts, at a peak of nearly three million exchanges in a single day, all coordinated around a single fixed prompt aimed at extracting chain-of-thought reasoning to train the Qwen model family.

That is a lot of copies of the same query. Somewhere at Alibaba there is a job specification that reads "send this prompt to Claude three million times a day." Whoever wrote it either believed the account tenancy would hold or hoped nobody at Anthropic was counting.

Anthropic was counting.

The seven names, and what the numbers look like next to them

TechCrunch's Russell Brandom and CNBC both worked from the same underlying report and both pulled out the same load-bearing figures. The Alibaba operation ran through May, June and July. A single fixed prompt, replicated across 3,500-plus accounts, targeted the chain-of-thought output the reasoning modes of Claude produce inside their thinking blocks. Anthropic normally serves summarised thinking rather than raw traces, which is what made the target expensive and the scale necessary. To pull enough signal to matter, the campaign had to grind — and grinding at three million queries a day for two months is roughly what 151 million exchanges buys you.

The Moonshot operation is smaller and stranger. Over a 10-day window, Moonshot routed roughly 300,000 customer requests from its own Kimi service through 5,380 fraudulent accounts to Claude — most of them to Opus. The customers were paying Moonshot for Kimi. Moonshot was, per the report, silently forwarding their queries to Anthropic and returning Claude's outputs as its own. Cryptopolitan puts the aggregate Moonshot-linked figure over the May-July window at 23 million exchanges; the July report from Kratsios pointed at the same lab; the September numbers are the receipts.

DeepSeek's line item, per the Briefs and Cryptopolitan summaries: roughly 12 million exchanges across a 14-day July window. The other four names — Z.ai, Xiaomi, SenseTime, MiniMax — are enumerated without headline totals in the initial trade-press coverage, which the report presents as a class of activity rather than four bespoke case studies.

The report's aggregate figure across the distillation category, per TechCrunch's read of Anthropic's own numbers: nearly 200 million exchanges attributed to distillation attacks over the December 2025 - August 2026 reporting window. Anthropic classifies the practice as "likely inconsistent with privacy laws and the labs' own terms of service" — which is diplomatic phrasing for "we caught you, you knew, and your customers didn't."

The Anthropic wordmark on a light background. Anthropic, the San Francisco-based AI safety company behind the Claude family of models, published its September 2026 Threat Intelligence Report on Thursday September 10 naming seven Chinese AI labs for illicit distillation of Claude — the first time the company has itself, rather than a US government official, put specific per-lab exchange counts and account counts behind the accusation of chain-of-thought reasoning extraction.

The Moonshot loop is the story most people are underreading

Alibaba running distillation at industrial scale is the number. Moonshot forwarding Kimi customer traffic to Claude is the shape.

The Alibaba operation, in the shape the report describes it, is a research team paying for Claude access through fraudulent accounts to build training data for its own model. That is IP misappropriation, and it is the archetypal case the phrase "illicit distillation" is designed to cover. It is not, on its own, a customer-facing scandal. Alibaba's own users were not routed anywhere they did not expect.

The Moonshot operation is different in kind. If the report's account of it holds, Kimi customers paid Moonshot, received Claude answers, and were not told. The report is explicit that Anthropic does not know whether Moonshot notified those customers. It is a reasonable guess that they did not. That reframes the incident from a training-data theft into a sourcing-transparency failure with real downstream exposure — enterprise buyers whose privacy reviews cleared a Beijing-hosted Chinese model may have been running their prompts through a San Francisco lab whose terms they never accepted. Sensitive data, per Anthropic's language, was in scope.

The joke writes itself: Moonshot spent the summer being accused of distilling Claude to build Kimi, and the September report's finding is that at least some of Kimi was, functionally, Claude with a Moonshot-shaped wrapper. It is API arbitrage as product strategy, and the arbitrage was the product.

From the Kratsios post to a report with page numbers

On July 22, 2026, Michael Kratsios named Moonshot on X for distilling Anthropic's Fable model into Kimi K3, and Scott Bessent threatened Entity List sanctions in a same-day quote to TechCrunch. When independent AI researchers were asked to back the timeline, they declined to. Braden Hancock and Nathan Lambert both told TechCrunch that three weeks of distillation could not, on its own, produce a model the quality of Kimi K3. Their scepticism was not about whether distillation was happening. It was about whether it was the whole story.

The September 10 report answers a different question. It does not claim Kimi K3 is a distilled Fable checkpoint. It claims that distillation is happening on the scale of nine-figure exchange counts, that seven named Chinese labs are doing it, and that Anthropic has the account-level telemetry to say so. That is the accusation the White House was working from in July. The receipts arrived seven weeks later — with Anthropic as the disclosing party, not the administration.

The consequences are already stacking. Alibaba's US-listed shares fell 2.7% on the news, per Cryptopolitan. Anthropic told the US Senate Banking Committee in a June letter that the practice existed; September is the public-facing version of that letter. The Chinese Foreign Ministry's July response — a spokesperson accusing Washington of "politicizing and instrumentalizing trade and tech issues" — reads differently against a private-sector report with numbered case studies than against a Bessent quote to a tech outlet.

What is not in the report

Three things the report notably does not carry:

  1. Damages figures. Anthropic quantifies the exchanges, not the training value. How much competitive lift Qwen or Kimi actually got from the extracted chain-of-thought data is the question the report does not answer, and it is the question the market cares about.

  2. Denials or comment. CNBC and TechCrunch both went to Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic for comment before publication. None of the accused had responded by press time. That silence is data, but it is not a rebuttal.

  3. A remedies path. The report describes account bans, automated detection, and intelligence sharing with authorities. It does not describe a legal filing, a licensing demand, or a structural response — such as gating chain-of-thought access behind stricter identity checks — that would prevent the same campaign from resuming on new accounts next quarter. If the answer is "we caught this one and will catch the next one," the arms race is the answer.

What to watch

  1. Whether Alibaba, Moonshot, or DeepSeek publish a response. A denial, a technical rebuttal, or a "the accounts were unauthorised" framing would each carry different weight. Silence past two weeks is itself a position.
  2. Whether the Senate Banking Committee moves the June letter into a hearing. Anthropic's June disclosure to the committee is now public — public disclosure to Congress is a standing invitation to a subpoena for the full case file.
  3. Whether OpenAI publishes comparable telemetry. OpenAI has flagged Chinese distillation before, notably around DeepSeek in early 2025. If it lands its own multi-lab report inside 60 days, the industry framing shifts from "Anthropic's problem" to "the frontier's problem," and the policy debate has a second lab on the record.
  4. Whether the "single fixed prompt" fingerprint holds. The Alibaba campaign, per the report, ran on one template replicated across 3,500 accounts. That is a design choice — presumably to keep the training corpus clean. If the next campaign switches to prompt-shape diversity, the detection signal that caught this one goes quiet, and the reporting cadence of these disclosures decides how visible the arms race stays.

The Kratsios post in July was an accusation. The September report is a case file. The interesting question is not whether the numbers hold — Anthropic's account-level telemetry is not a class of evidence a foreign lab can plausibly refute in the abstract — but whether a case file counts as enforcement, or as an invoice waiting for a signature that never arrives.

* * *

Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.

Elsewhere in this issue

3 more
  1. 01

    The Patch

    The Patch — September 11, 2026

    Sep 11, 2026

  2. 02

    News

    The safety committee got a Christiano on the day GPT-6 Astra shipped — OpenAI added the industry's most-cited catastrophic-risk researcher to its Foundation Board while the flagship reached enterprise general availability

    Sep 10, 2026

  3. 03

    The Patch

    The Patch — September 10, 2026

    Sep 10, 2026

Letters

Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.