Illustration for: Anthropic Ties Claude Distillation to the Dark Web

Anthropic Ties Claude Distillation to the Dark Web

Anthropic disclosed an organized dark-web market that helps Chinese AI labs bypass its access controls to distill Claude's capabilities into rival models.

By the Numbers

24,000+
Fraudulent accounts (3 labs)
16M+
Claude exchanges extracted
28.8M+
Alibaba campaign exchanges
Apr 22-Jun 5, 2026
Alibaba campaign window
4
Labs named
TC
By the AI Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
3 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Anthropic disclosed that the distillation campaigns it first flagged against DeepSeek, Moonshot AI and MiniMax in February have evolved into an organized dark-web and proxy-service market that helps foreign labs bypass Anthropic's access controls entirely.

2

A separate, larger campaign attributed to Alibaba and Alibaba Qwen ran from April 22 to June 5, 2026, generating more than 28.8 million exchanges with Claude aimed at agentic reasoning, software engineering and long-horizon task capabilities.

3

Anthropic's head of threat intelligence, Jacob Klein, says the company detects these campaigns through IP correlation, request metadata and infrastructure fingerprints that diverge sharply from normal customer traffic -- not voluntary disclosure by the labs involved.

4

The disclosure lands the same week Moonshot AI confidentially filed for a Hong Kong IPO targeting a $50 billion valuation, adding a live financial stake to accusations that could trigger US sanctions before the listing prices.

TC

The VC Read · Trace's Take

Trace Cohen

The dark-web/proxy-service angle is the real escalation here, not the account count -- Anthropic is describing a commercial market for evading its own controls, which means blocking fraudulent sign-ups one at a time won't work anymore. Diligence item for anyone with China AI fund exposure: check whether your portfolio's Chinese AI holdings are among the four labs named, because that's now live sanctions and IPO-disclosure risk, not background noise. Watch whether Moonshot's HKEX prospectus has to address this directly.

Analysis

Anthropic disclosed Thursday that the distillation campaigns it first flagged in February against three Chinese AI labs have evolved into an organized market that uses dark-web forums and commercial proxy services to help foreign labs bypass its access controls entirely, CNBC reported. "There's an entire illicit ecosystem to try to gain access to Claude and other models," said Jacob Klein, Anthropic's head of threat intelligence.

Anthropic, founded in 2021 by former OpenAI researchers Dario and Daniela Amodei, builds the Claude family of models and has positioned itself as the frontier lab most willing to publicly name and quantify misuse of its own product -- a stance that doubles as a national-security argument for why Washington should restrict rival labs' access to US-made models. Distillation is a standard, often legal AI training technique in which a smaller model learns by studying a stronger one's outputs; Anthropic's argument is that what it's tracking isn't legitimate research use but industrial-scale extraction run through fraudulent accounts and access markets built specifically to evade its terms of service and export restrictions.

Four Labs, Two Disclosed Campaigns

  • DeepSeek, Moonshot AI, MiniMax -- accused in February of running roughly 24,000 fraudulent accounts that generated more than 16 million exchanges with Claude, extracting outputs to train and improve their own models, per Anthropic's own writeup.
  • Alibaba and Alibaba Qwen -- accused separately of a larger campaign running April 22 through June 5, 2026, generating more than 28.8 million exchanges targeting agentic reasoning, software engineering and long-horizon task capabilities specifically, Mobile World Live reported.

The scale gap between the two disclosed campaigns is itself notable -- Alibaba's alone, at 28.8 million exchanges, is nearly double the combined 16 million Anthropic attributed to DeepSeek, Moonshot and MiniMax together. All four labs compete directly with Anthropic and OpenAI for both Chinese domestic AI leadership and international enterprise customers who might otherwise buy API access to Claude or GPT models -- a cheaper, distilled model with comparable benchmark performance directly undercuts the pricing power frontier labs depend on to justify tens of billions of dollars in compute spending.

The Trump administration's April memo called distillation that undermines American research and proprietary information "unacceptable" and committed to sharing threat intelligence with US AI companies. Thursday's disclosure is Anthropic operationalizing that commitment publicly rather than waiting for government action -- naming specific companies, specific numbers and a specific evasion mechanism.

For VCs with China AI exposure, the practical read is that access to a frontier US model, even indirectly through a proxy service, is now something regulators are actively hunting rather than a gray-area workaround -- and any Chinese AI lab racing toward a public listing, like Moonshot's confidential Hong Kong IPO filing this week, carries fresh disclosure risk if it's one of the labs named in an active US distillation dispute.

What Anthropic's disclosure doesn't establish is causation between distillation and any specific downstream harm -- the company argues distilled models are unlikely to retain frontier safety guardrails, but that's a stated risk, not a documented instance of harm. Anthropic is also not a neutral party: it has commercial interest in both the White House restricting rival labs' access to its technology and in a public narrative that positions Claude as too valuable to let China copy cheaply, alongside its own multi-billion-dollar compute commitments the disclosure indirectly helps justify.

The dark-web and proxy-service angle is the new detail worth tracking -- if evading Anthropic's access controls has become a commercial service with its own market, the response required is different and harder than blocking fraudulent sign-ups one account at a time.

ShareXLinkedInEmail

Key Sources

2 sources
SourceCNBC

Reported by CNBC · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.