Invest1 publisher2 min readPublished
Anthropic traces 151 million Claude exchanges to Alibaba over three months
Anthropic's threat intelligence report puts more than 186 million Claude exchanges across Alibaba, Moonshot and DeepSeek between May and July. The report carries no legal filing, and the named labs have not commented.
The Investor · Invest desk

What happened
- Anthropic said in a threat intelligence report released Thursday that it detected and disrupted unauthorized large-scale efforts by China-based labs including Alibaba, Moonshot and DeepSeek to train models on Claude.
- Operators affiliated with Alibaba ran more than 151 million Claude exchanges between May and July to help train Qwen models, the largest distillation campaign Anthropic says it has measured.
- In one 10-day period Moonshot relayed nearly 300,000 Kimi customer requests to Claude, mostly to Opus models, through 5,380 accounts that appeared to be located in Singapore and Japan.
- Anthropic said DeepSeek transferred exchanges to Claude without notifying its customers, and that it observed more than 12 million distillation attacks attributable to DeepSeek over 14 days in July 2026.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure Buyers of Chinese model APIs now have to establish which upstream model actually served their prompts before they can answer their own compliance questions about where the text went.
- constraint Volume-based defences that flag an account running 860 exchanges a day will pass one running under six, so catching relayed traffic means inspecting content and routing instead of counting calls.
- contradiction The report calls the practices likely unlawful while the named labs stay silent, so anyone valuing the intellectual property claim is working from one company's telemetry with nothing to test it against.
- precedent An API vendor publishing per-account volumes attributed to named competitors makes the threat report the expected venue for enforcing model terms of service.
Nearly 3 million exchanges a day spread across more than 3,500 fraudulent accounts is about 860 exchanges per account per day [6][2]. Moonshot's relay ran at a different scale: nearly 300,000 customer requests through 5,380 accounts over ten days works out at about 5.6 requests per account per day [9][3]. On volume alone, that is ordinary usage.
The relay was also the smaller part of Moonshot's footprint. Anthropic attributed more than 23 million exchanges to the company across May, June and July [11], roughly 250,000 a day over those 92 days, against about 30,000 a day of relayed customer requests in the ten-day window, so the relay is something like an eighth of the total [4]. Alibaba's average over the same three months comes to about 1.6 million a day, which puts the near-3-million peak at close to double its own run rate [1]. DeepSeek's July burst ran at roughly 850,000 a day for a fortnight [5].
The privacy claim is the part with third parties in it. "Some of these exchanges included sensitive information, including from individual users, major multinational companies, and state-affiliated actors ... These practices are likely inconsistent with privacy laws and the labs' own terms of service," according to the report [3]. Moonshot showed Claude's answers to users who believed they were using Kimi [8], and Anthropic said it did not know whether those customers had been told their requests were being sent to Anthropic [12]. DeepSeek, on Anthropic's account, transferred exchanges without notifying its customers either [13].
Anthropic measured the traffic, terminated it, and published the volumes in a report covering activity disrupted between December 2025 and August 2026 across seven categories [14]. It did not put a price on the outputs, and the account of the report carries no lawsuit and no regulatory complaint [17].
Anthropic files a claim and the 151 million exchanges become a damages input; a privacy regulator picks up the notification question and the exposure lands on the intermediaries rather than on Anthropic; or nothing follows the account bans and the report does its work as deterrence and disclosure. The third is the one the evidence currently describes, because the only remedy in it is detection and disruption [1]. A filing with a number in it would replace that reading. So would any of the named labs documenting that its Claude access was licensed [6].
Alibaba, Moonshot, DeepSeek, Xiaomi and Anthropic did not immediately respond to CNBC's requests for comment [16].
What to watch
- Whether Anthropic converts the terms-of-service claim into a filing and attaches a dollar figure to the 151 million exchanges.
- Whether any Kimi or DeepSeek enterprise customer confirms it was told its requests were routed to Anthropic.
- Whether Alibaba, Moonshot or DeepSeek disputes Anthropic's attribution of the fraudulent account networks.