Anthropic Publishes 154-Page Threat Report: Claude Was Used for Bioweapons Research, Seven Chinese AI Companies Accused of Distilling Models More Than 150 Million Times

Anthropic's fourth threat intelligence report documents systematic misuse of Claude from December 2025 to August 2026, covering bioweapons-adjacent research and industrial-scale model distillation by seven named Chinese AI firms.

On September 11, 2026, Anthropic published a 154-page threat intelligence report detailing the full picture of systematic malicious exploitation of its Claude models between December 2025 and August 2026. The report covers seven major areas of abuse: cyberattacks, influence operations, surveillance, scams and fraud, bioweapons misuse, conventional weapons development, and — most striking in scale — unauthorized model distillation. The timing of the report's release is delicate: just two days earlier, a former Anthropic researcher publicly resigned, claiming AI "could kill all of us by the end of this decade." Under that external pressure, the report's significance as a gesture of transparency is as notable as its strategic PR intent.

The Bioweapons Cases: An AI Company Acknowledges Crossing a Capability Line for the First Time

The most striking part of the report is five cases involving biological research. According to Anthropic, several scientists — including researchers suspected of receiving state support — used Claude to draft research proposals involving chikungunya virus and orthopoxvirus. The former is a mosquito-borne virus that can cause months of persistent, severe pain; the latter is the family of viruses responsible for human infectious diseases such as smallpox.

These users employed two layers of evasion: first, bypassing the geographic access controls Anthropic set for "unsupported regions"; second, deliberately concealing the true purpose of their research to evade content safety guardrails. Anthropic said it ultimately identified these users' true intent and banned the relevant accounts, while folding its findings into continued iteration on its safety mechanisms. Notably, the company explicitly said it "does not assert harmful intent on the part of these individuals," and declined to disclose their names or affiliations on the grounds of protecting the scientists involved from undue exposure.

The report also contains one carefully worded but weighty judgment: the capabilities of frontier AI models such as Claude can no longer be assumed by default to fall below the threshold for "providing meaningful bioweapons assistance." This is the first time a mainstream AI company has made such a statement in the form of an official report.

According to The Guardian, Anthropic wrote in the report: "Biological misuse is one of the most severe risks of frontier AI models. Without the right safeguards, such capabilities could lead to catastrophic outcomes."

Industrial-Scale Distillation Attacks: Seven Chinese AI Companies Named

If the bioweapons cases are the most security-threatening content in the report, the unauthorized model distillation section carries greater commercial and geopolitical impact. Anthropic named seven Chinese AI companies in the report: Alibaba, Moonshot AI, DeepSeek, Zhipu AI (Zhipu/Z.ai), MiniMax, Xiaomi, and SenseTime, accusing them of conducting industrial-scale unauthorized distillation operations.

"Unauthorized distillation" refers to training one's own model by making massive numbers of calls to a target model's outputs — including its chain-of-thought — thereby systematically replicating its capabilities without authorization. The attackers used stolen credit cards, login credentials, and API keys to build networks of proxy accounts to mask their true identities and the scale of their operations.

According to The Hacker News, the scale of each case was as follows: Alibaba (designated GTG-16005) conducted the "largest distillation attack" to date, generating 151 million interactions with Claude between May and July 2026, peaking at roughly 3 million per day, and using more than 3,500 fraudulent accounts, specifically targeting the chain-of-thought reasoning records of Claude Opus 4.6 and 4.7. Moonshot AI (GTG-16002) generated 23 million interactions over the same period, and within a single 10-day window routed nearly 300,000 genuine user requests for its Kimi product through 5,380 proxy accounts based in Singapore and Japan to Claude, then presented Claude's replies to users as Kimi's own output — to unaware users, this was Kimi's own capability. DeepSeek (GTG-16001) generated more than 12.1 million interactions over 14 days in July 2026; Zhipu AI (GTG-16006) generated more than 3.4 million interactions between June and July through 273 rotating fraudulent accounts; Xiaomi (GTG-16008) generated more than 400,000 interactions between March and April.

Alibaba's case alone is unprecedented: 151 million is an order of magnitude above any previously known distillation incident. Moonshot's practice of quietly routing Claude into its own product while concealing this from users crossed two red lines at once: technical theft and consumer deception.

Weapons Software and Surveillance: A Toolbox for State Actors

Beyond the biological and distillation cases, the report also discloses multiple cases of Claude being used to develop software for conventional weapons, involving actors in Yemen, China, and Russia, targeting software systems required for lethal equipment including firearms, missiles, armed drones, and bombs.

On surveillance, the report documents a Chinese surveillance project targeting Uyghurs in Syria, as well as another surveillance system targeting domestic dissidents. Russian cyber-espionage operations and "smash-and-grab" cyberattacks are also included as cases. On influence operations, campaigns in Russia, Malaysia, Iran, and Bangladesh were named.

The report specifically notes that all recorded abuse cases used Claude Haiku, Sonnet, or Opus series models, with the sole exception of one unauthorized distillation case involving a Fable or Mythos-class model.

Anthropic's Response Mechanisms: From Account Bans to Encrypted Reasoning

Facing these threats, Anthropic took several kinds of countermeasures of differing nature. For individual abusive accounts, enforcement was relatively direct: ban on discovery, and fold identified abuse patterns into continued iteration on its safety guardrails. For large-scale distillation attacks, Anthropic introduced a "preserved thinking" feature at the technical level, encrypting internal reasoning before API accounts transmit it outward, cutting off systematic scraping of chain-of-thought at the root. In addition, the company shared threat intelligence with relevant government agencies and industry partners.

In historical terms, this is Anthropic's fourth threat report, following the previous three in March, August, and November 2025. Compared with the first three, this report shows significant improvements in scale (154 pages), precision of naming (listing specific company designations and interaction counts), and clarity of technical terminology — it is not only a transparency exercise but also a technical indictment addressed to regulators and industry peers.

The Real Impact on the Industry Landscape

For developers and enterprise users, the distillation allegations reveal a structural security blind spot: API calls are commercially open, but once their outputs are systematically aggregated, they can become a competitor's training data. The Moonshot case is especially worth watching — when end users interact with Kimi, they are in fact unwittingly supplying genuine "user request" raw material for a distillation attack on Claude. This means that even downstream customers of Anthropic can be drawn into an intellectual property dispute at the supply-chain level without knowing it.

For Chinese AI companies, the cost of being named goes beyond legal risk. The credibility of companies such as Alibaba and DeepSeek in international markets will come under direct pressure, especially as the EU AI Act is gradually being implemented and regulators in various countries tighten scrutiny of cross-border AI actors. If the fact that Moonshot passed off Claude's output as Kimi's own capability constitutes "misleading commercial practice" in Europe or the United States, its compliance handling will be far more complicated than a technical account ban.

For Anthropic itself, this report is a double-edged sword. Disclosing successful interventions — particularly blocking state-supported biological research — strongly supports its "responsible AI" narrative and strengthens its leverage in cooperation with government regulators. At the same time, publicly acknowledging that Claude has crossed the "threshold for bioweapons assistance capability" objectively provides ammunition for regulatory proposals to limit its model capabilities.

Analysis: What Is Most Likely to Happen Next

The following judgments are logical inferences based on the facts above and do not represent confirmed facts.

First, the follow-up to the distillation allegations will be a key point to watch. Anthropic named seven companies, but the report itself is not a legal complaint — none of the named companies have publicly responded so far. If any one of them chooses to deny the allegations outright and present counterevidence, it would place substantial pressure on the report's credibility; if all remain silent, that silence itself will become a reference benchmark in international AI regulatory discussions.

Second, the actual defensive effectiveness of the "preserved thinking" encryption feature is worth tracking. The core of a distillation attack is scraping reasoning outputs; if Anthropic's encryption mechanism can effectively block it, it will drive industry-level discussion of new technical standards for "chain-of-thought protection"; if attackers circumvent the encryption, the next round of reports will present an even more escalated cat-and-mouse game.

Third, the public statement on the bioweapons threshold will accelerate legislative progress in the United States and the European Union on capability assessment mechanisms for frontier models. It is reasonable to expect that this report will appear frequently in citations in various AI regulatory hearings over the next 6 to 12 months.

For enterprise technology teams currently evaluating API vendors, the practical signal from this report is this: in API procurement contracts, you need to explicitly require suppliers to commit to compliance on "pass-through behavior" and "output retraining"; the Moonshot case proves that your commercial SaaS vendor may itself be an unauthorized proxy for another AI company.

Sources: - [Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks](https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html) - [Chinese AI labs secretly used millions of Claude exchanges to train their models, Anthropic says](https://www.cnbc.com/2026/09/11/chinese-ai-labs-moonshot-deepseek-alibaba-anthropic.html) - [Anthropic claims that China's Alibaba used 25,000 fake accounts and 28.8 million exchanges](https://www.tomshardware.com/tech-industry/artificial-intelligence/anthropic-claims-that-chinas-alibaba-illicitly-distilled-its-models-from-april-to-june-2026-says-effort-involved-25-000-fake-accounts-and-28-8-million-exchanges-on-claude) - [Countering misuse of AI: September 2026 / Anthropic](https://www.anthropic.com/threat-intelligence-report-september-2026) - [Anthropic details bad actors' efforts to misuse its AI for bioweapons](https://www.theguardian.com/technology/2026/sep/11/anthropic-claude-ai-bioweapons-threat-report)