Anthropic identified seven China-based labs that allegedly attempted such distillation over the past seven months|Anthropic|CC BY 2.0

Anthropic reported that Chinese AI companies allegedly found a backdoor of sorts into its Claude chatbot by routing user requests through overseas intermediaries.

The acts allowed the Chinese firms to copy Claude’s answers and study its capabilities.

Anthropic said that seven China-based labs, including Moonshot AI and DeepSeek, funneled thousands of requests to Claude through these middlemen and used the responses for “distillation”—a technique that trains a less powerful model using a more advanced one.

Anthropic identified seven China-based labs that allegedly attempted such distillation over the past seven months|Anthropic|CC BY 2.0Anthropic said it blocked multiple accounts and flagged about 35 concerning research efforts in one month involving bird flu, viruses, toxins and gain-of-function studies. It also said that some requests contained sensitive information, including locations, passwords and corporate login credentials.

Moonshot reportedly generated more than 23 million exchanges with Claude through thousands of fake accounts between May and July.

The report offers new details on how Chinese firms allegedly carried out the practice, which US officials increasingly describe as a threat to America’s AI advantage.