The modern security alert usually warns of a compromised password or a leaked email address, a personal breach that feels invasive but manageable. However, a new breed of industrial espionage has emerged that does not target individual identities, but rather the very intelligence of artificial intelligence. The target is no longer the user's data, but the latent reasoning capabilities of the models themselves. This shift from identity theft to intelligence theft has now reached a geopolitical scale, as revealed in a series of disclosures regarding the systematic exploitation of the Claude AI platform.

The Scale of the Extraction Campaign

Between April and June 2026, Anthropic identified a massive, coordinated effort to siphon the capabilities of its Claude models. The most intense period of this campaign occurred from April 22 to June 5, 2026, during which the platform recorded over 28.8 million exchanges. This was not the result of organic user growth, but the work of approximately 25,000 fraudulent accounts designed to mimic human interaction while harvesting model outputs at scale. By generating tens of thousands of fake identities and repeating millions of queries, the attackers sought to map the internal logic and performance boundaries of the model.

This activity was not limited to a single entity. In February 2026, Anthropic identified additional extraction campaigns conducted by several other Chinese AI research labs. DeepSeek recorded over 150,000 exchanges, while Moonshot AI and MiniMax were far more aggressive, with 3.4 million and 13 million exchanges respectively. These figures suggest a systemic, industry-wide effort within China to collect high-quality synthetic data from Claude to bolster their own domestic models.

The US government has responded by treating these incidents as industrial-scale threats rather than simple corporate security breaches. In April 2026, the White House officially condemned China for stealing intellectual property from American AI labs on an industrial scale. Simultaneously, the US Department of Defense added Alibaba to its list of Chinese military companies, signaling that the theft of AI capabilities is now viewed through the lens of national security and military readiness.

The Distillation Shortcut and the Security Fallout

To understand why millions of queries are valuable, one must look at the process of model distillation. Training a frontier model from scratch requires billions of dollars in compute resources and years of research. Distillation provides a shortcut: a smaller, less capable model is trained using the outputs of a more powerful "teacher" model as its training data. By treating Claude's responses as a gold standard, competing labs can effectively "distill" the reasoning capabilities of a high-end model into their own architectures without incurring the original training costs.

Anthropic specifically noted that these campaigns were designed to accelerate the development of capabilities equivalent to Mythos Preview, one of its most powerful models. This creates a dangerous asymmetry where the entity investing the capital and research into the original model essentially subsidizes the development of its competitors. The competitive advantage built over years of research can be eroded in a matter of weeks through unauthorized API access.

This realization led to a drastic intervention by the US government. On June 12, 2026, the US Department of Commerce imposed strict restrictions on Anthropic's latest models, Mythos and Fable. The government determined that these models posed a severe security risk if they were deployed by military intelligence users in China or other countries of concern. In direct response to these regulatory mandates, Anthropic took the unprecedented step of disabling access to the Mythos and Fable models globally.

The escalation from a series of fraudulent accounts to the total shutdown of flagship models illustrates a new reality in the AI race. The conflict is no longer just about who can build the smartest model, but who can prevent that intelligence from being weaponized or cloned by an adversary. The case of Alibaba and the Qwen research organization demonstrates that the API is now the primary front line of intellectual property warfare.

The focus of the global AI competition has shifted from raw performance to the ability to control and secure the distribution of intelligence. The future of the AI supply chain will now be defined by the government's power to restrict model access based on national security risks.