Security1 publisher2 min readPublished
Anthropic traced 151 million Claude exchanges to a 3,500-account fraud network it links to Alibaba
Anthropic says six campaigns since February 2026 pulled reasoning transcripts out of Claude through proxy relays built on fictitious identities, stolen credit cards, and API keys harvested from legitimate companies and individuals.
The Watch · Security desk

What happened
- Anthropic said on Thursday it identified and disrupted industrial-scale illicit distillation against Claude by seven China-based labs, including Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax.
- The largest campaign, GTG-16005, ran 151 million exchanges between May and July 2026 against the chain-of-thought reasoning transcripts of Claude Opus 4.6 and 4.7.
- Xiaomi replayed user conversations and coding sessions from its MiMo models into Claude through the OpenClaw and OpenCode harnesses over 20 days in March and April 2026, Anthropic said.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Companies that never bought Claude are inside this incident through their own stolen API keys, and the enforcement action that stops the relay is what burns the key.
- constraint Volume alarms and per-account rate limits do not see a network that spreads its traffic thinly across thousands of identities, so anyone selling metered API access needs payment and identity analytics to find it.
- decision Any organisation that allowed Kimi or DeepSeek internally now has to decide whether prompts sent during those windows count as disclosure to a vendor it never contracted with.
- contradiction The campaign labels, the volumes and the account counts rest on one vendor's telemetry, and none of the seven named labs has put its own account of the same traffic on the record.
Divide the peak volumes by the account counts and two different operations appear. GTG-16005 ran roughly 3 million exchanges a day across more than 3,500 fraudulent accounts [5], about 857 per account per day [1]. Moonshot's network moved almost 300,000 customer requests in ten days through 5,380 accounts [7], about six per account per day [2]. The first figure shows up in rate limiting. The second looks like ordinary paying customers, and catching it means looking at how the accounts were opened and paid for [12].
Five of the six campaigns carry volumes: 151 million [3], 23 million [6], more than 12.1 million [8], more than 3.4 million from Zhipu's 273 rotating accounts [9], and more than 400,000 from Xiaomi [10]. That is at least 189.9 million exchanges [3]. The sixth, GTG-16012, has no exchange count, because Anthropic says SenseTime bought the transcripts from third-party data vendors instead of generating them [11].
The access path is the part that reaches outside the AI industry. Anthropic said the relays were built on accounts created under fictitious identities, with fake or stolen credit cards and illegally harvested API keys belonging to legitimate companies or individuals [12]. A harvested key does not stop belonging to its owner. Requests made with it arrive at Anthropic under the owner's identity [4].
Traffic also moved the other way, into Claude, carrying other people's prompts. "DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude," Anthropic said [14]. Moonshot, on Anthropic's account, rerouted its own customers' requests away from Kimi and displayed Claude's responses back to them [6]. Anthropic said "Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors." [15]
Seven labs are named [1] and six campaigns described [2]. The campaign detail covers Alibaba, Moonshot, DeepSeek, Zhipu, Xiaomi and SenseTime; MiniMax is in the list of seven without an attributed campaign [5]. Every volume, date range and account count here comes from Anthropic's own telemetry, and no response from any named lab appears in the reporting [6]. Google and OpenAI have made the same accusation about their own models before [17].
What to watch
- A response on the record from Alibaba, Moonshot, DeepSeek, Zhipu, Xiaomi, SenseTime or MiniMax to the campaign attributions.
- Whether Anthropic tells the companies whose harvested API keys were pooled into the relay networks, and publishes anything they can check against.
- Whether Google or OpenAI publish per-campaign exchange volumes and account counts for their own models.