Fetching from the wire…
Public story · 2026-09-12 · high
A second Chinese group pulled 151 million more exchanges from Claude using 3,500 fake accounts to train Alibaba's Qwen models.
Why now: Anthropic's account of both operations surfaced in coverage dated September 12.
A Chinese state-sponsored group ran 12.1 million exchanges through Claude Opus in 14 days, analyzing CCTV feeds covering PLA facilities in Chengdu, Anthropic says.
In one case Anthropic describes, a PRC technology company employee believed they were feeding internal documents into DeepSeek. The query reached Claude instead, handing over the full specifications, org structure and strategic objectives of a flagship AI program.
The same operation, GTG-16001, also pulled Russian Ministry of Defense database credentials and Chinese public security case files into its Claude sessions, per The Decoder.
A separate operation, GTG-16005, built more than 3,500 fraudulent accounts to pull over 151 million exchanges out of Claude. Anthropic ties the extraction, which peaked near 3 million exchanges a day, to training Alibaba's Qwen models.
Both cases complicate the usual distillation story, where a rival lab trains on Claude's outputs without permission. Here a DeepSeek-branded product routed a user's proprietary data into Claude, while the Qwen accounts pulled data out for training in the more familiar direction.
Each link below shares sources, entities, or timing with this story.
Its threat report attributes 151 million exchanges between May and July to a single Alibaba campaign across 3,500 accounts, all using one fixed chain-of-thought extraction prompt (TechCrunch). It counts more than 12 million DeepSeek exchanges over 14 days. It also says Moonsho...
Martin Alderson's essay "The upcoming AI margin collapse, part 1: GLM 5.2" hit 675 points and 462 comments on Hacker News, and it's the rare HN chart-topper that's actually about spreadsheet math instead of vibes. The argument is simple. Z.ai's GLM 5.2 delivers frontier-adjace...
25,000 fake accounts. 28.8 million Claude conversations. Six weeks. And the thing they were harvesting wasn't trivia, it was software engineering and agentic reasoning. In a June 24 letter to US senators and the White House, Anthropic alleged that operators tied to Alibaba's Q...
Anthropic published technical details of distillation attacks by DeepSeek, MiniMax, and Moonshot AI — 24,000 fraudulent accounts generating 16M+ exchanges targeting Claude's most differentiated capabilities: agentic reasoning, tool use, and coding. MiniMax led with 13M exchang...
DeepSeek, Moonshot AI, and MiniMax created 24,000 fraudulent accounts generating 16 million exchanges to extract Claude's outputs. 33.5 million views, 55,000 likes. First time Anthropic publicly named competitors and quantified IP extraction scope. Source
Anthropic identified industrial-scale capability theft: 24K fake accounts generating 16M+ exchanges from DeepSeek, Moonshot, and MiniMax. MiniMax pivoted to new models within 24 hours of each Claude release — suggesting automated distillation pipelines. ---
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.