Two documents went up ten hours apart on September 10, and neither one mentions the other.
The first is Anthropic’s latest threat-intelligence report, covering harm it disrupted between December 2025 and August 2026 across seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Of those seven, exactly one ever touched Anthropic’s most capable model family. The report’s own words: “None of the misuse cases involved the use of Claude Fable or Mythos-class models, with the exception of one illicit distillation case.” Six ways to misuse a frontier model, and access controls held on all six. The seventh only needed an API key.
The second is Cognition’s release of SWE-2, a coding agent. Cognition says so itself, in the second paragraph of its own post: “SWE-2 is post-trained from Kimi K3, a 2.8T-parameter model that had already undergone extensive RL for agentic coding.” Kimi is Moonshot AI’s model line. Moonshot is one of the labs named in Anthropic’s report.
Anthropic’s own words: “Since we published our first disclosure in February, we have identified and disrupted additional distillation attacks against Claude from seven labs based in China. All of these attacks targeted our generally available models; we have not observed attempts against Mythos 5 or Mythos Preview, which are not accessible to the general public.” The named labs, across the report and the coverage of it: Alibaba, Moonshot, DeepSeek, Zhipu, Xiaomi, SenseTime, and MiniMax.
The volumes vary by an order of magnitude depending on the lab and the window measured. Alibaba is the largest single campaign Anthropic says it has caught: more than 151 million exchanges between May and July, peaking near 3 million a day from upward of 3,500 fraudulent accounts. DeepSeek is smaller and more compressed: more than 12.1 million exchanges inside a single 14-day window in July.
Moonshot’s case, in the report’s own telling, has two numbers because it describes two things: a specific instance, and a total. Anthropic says Moonshot silently rerouted customer requests to Claude instead of running them through its own Kimi model, and in one ten-day stretch relayed almost 300,000 of those requests through a proxy network of 5,380 fraudulent accounts, using a replay attack to extract Claude’s internal reasoning traces for training data. That’s the instance. Zoomed out, the report’s own tally for the full campaign reads: “Scale of distillation attacks attributable to Moonshot between May and July 2026: over 23 million exchanges observed.” Same case, one worked example and one aggregate. I misread it as two unreconciled figures on first pass; it isn’t.
Zhipu gets the same instance-plus-total treatment, and its case adds a detail that complicates this essay’s own argument. Over ten days in June, Anthropic counted 770,609 exchanges run through a chain-of-thought extraction pipeline targeting Claude Opus, with a separate tally of “over 3.4 million exchanges observed” attributed to Zhipu across a longer, 17-day window. Ahead of releasing its GLM 5.3 model, the report says, Zhipu also tried to distill the cyber capabilities specifically of Fable, Anthropic’s most capable generally accessible model, and gave up once Fable’s cyber safeguards held. Zhipu’s own researchers then switched to a weaker-defended target, Claude Opus 4.6, “because they assessed the safeguards were weaker.” That is a case where access controls did stop something, at least long enough to push the attacker toward an easier mark.
That point matters, because the report reads like an indictment and functions like one: Anthropic is naming specific companies based on activity it traced through proxies and fraudulent accounts on its own platform, not through anything Alibaba or Moonshot has confirmed. CNBC reported that Alibaba, Moonshot, DeepSeek, and Xiaomi did not respond to requests for comment, and that Moonshot declined to address the claims specifically. None of the four has denied it. None has confirmed it either. Silence is the whole record here, and it cuts no particular way.
None of that makes Cognition’s release improper. Kimi K3 is a real, openly-licensed model, 2.8 trillion parameters, released July 16 with weights following July 27, and post-training an open-weight base is ordinary, legal practice across the entire industry. Cognition says its own reinforcement learning “still finds substantial headroom, adding 5–6 points on many benchmarks and shifting K3’s entire cost–performance frontier,” and the released numbers back that up: SWE-2 gains roughly 4.5 to 5.8 points over the K3 base across the four benchmarks in its own release post, depending on which one you check.
Sit the two documents next to each other and the arithmetic gets uncomfortable. If Anthropic’s attribution is right, Kimi’s training data plausibly includes millions of exchanges harvested from Claude. Cognition’s own numbers say its post-training adds single-digit points on top of that base, which already carries most of the absolute score whatever SWE-2 knows how to do. If part of what the base knows came from an American frontier lab by way of an alleged distillation campaign against that same lab, then a capability that started at Anthropic has gone through a foreign base model and come back out the other side inside a product built in San Francisco. Nobody in either document draws that line. Anthropic’s report is about defending its own models. Cognition’s post is about what SWE-2 can do. The seam between the two documents is where the story lives, and it belongs to neither of them.
I don’t think this is “China stole American AI and now it’s back,” and I’d resist any version of this essay that reduces to that sentence. Attribution here is one party’s read of activity routed through fake accounts, not a confession, and building on an open-weight model is not a moral failing: it’s the entire premise of open-weight release. The narrower, less satisfying point is this: distillation is the one harm category access controls mostly fail to stop, because unlike cyber, bio, fraud, and surveillance, it doesn’t need anything a legitimate customer doesn’t already have. Zhipu’s abandoned run at Fable’s cyber capabilities shows the controls can work at the margin, forcing an attacker onto a weaker-defended target instead of stopping the attack outright. That’s a real result, and it’s also the exception: every other case in the report is a lab that got through. Once distillation is through, there’s no license or terms-of-service clause that reaches into whatever gets built three steps downstream.
References