Anthropic counted 189.9 million distillation exchanges across five Chinese labs and printed no token count and no dollar figure. At the Opus card the campaign is worth between $5.7M and $40M, and every Kimi request Moonshot relayed to Opus would have lost 40 cents on the dollar if anyone had paid for it.
Anthropic published its first threat report of 2026 on Thursday, September 10. Pages 143 to 154 of the 154-page PDF are about distillation, and the sentence that travelled is the one about Moonshot: it "silently forwarded customer requests to Claude, instead of processing them using Kimi," almost 300,000 of them over ten days, through 5,380 accounts in Singapore and Japan. We read the section the way we read a pricing page. It has five per-lab counts of "exchanges observed," it never adds them up, and it has no tokens and no dollars anywhere in it. So we did the adding and the pricing, at the one card every Opus since 4.5 has shared, and we put Kimi K3's card next to it, which turns out to be Opus's times 0.6 on every line.

Photo by Lightsaber Collection on Unsplash
The numbers Anthropic gave, and the ones it did not
189.9M
exchanges across five labs, a sum the report never prints
0
token counts or dollar figures in 154 pages
0.6x
Kimi K3's card against Opus, input, cache and output alike
Five counts, one unit, no total
Each lab's section in the report ends with an italic line of the form "Scale of distillation attacks attributable to [lab] [window]: over [N] exchanges observed." The report says seven labs; five get a count. The windows are different lengths, the counts are floors, and nowhere does Anthropic put the five in one sentence. TechCrunch wrote "nearly 200 million"; the arithmetic says 189.9 million. Here they are side by side, with what each section says the traffic was for.
| Lab | Window | Exchanges | Accounts | Target and use |
|---|---|---|---|---|
| Alibaba | May to July 2026 | over 151,000,000 | nearly 5,000, then a second pool; more than 3,500 at peak | Opus 4.6 and 4.7 reasoning traces, into Qwen 3.5, 3.6 and 3.7 |
| Moonshot | May to July 2026 | over 23,000,000 | 5,380 | Relayed Kimi customers to Opus, saved the exchanges, extracted reasoning |
| DeepSeek | 14 days in July 2026 | over 12,100,000 | not given | Same relay and replay pattern as Moonshot, Opus reasoning traces |
| Zhipu | 17 days in June and July 2026 | over 3,400,000 | 273 | Opus 4.8 reasoning, Opus 4.6 for grading, one attempt on Fable |
| Xiaomi | 20 days in March and April 2026 | over 400,000 | more than 1,500 | Replayed its own users' sessions through Claude for SFT and RL |
| SenseTime, MiniMax | Named, described, no count | |||
The unit matters. An "exchange" is a request and a response, and Anthropic does not say how long either was. The February disclosure, which counted over 150,000 for DeepSeek, over 3.4 million for Moonshot and over 13 million for MiniMax across about 24,000 accounts, used the same unit and had the same gap. Between the two documents the disclosed volume went from 16.55 million to 189.9 million, 11.5x, though the windows do not line up and Alibaba, which is 79.5% of the new total, was not in the first one at all.
One more number that is in the report and worth holding onto: Alibaba's campaign "peaked at nearly 3 million exchanges per day." OpenRouter's chart for Claude Opus 5 shows 16,816,241 requests in the week to September 13, which is 2.40 million a day. Alibaba's peak, by Anthropic's count, was a quarter larger than every Opus 5 request OpenRouter carries today.
The version does not change the price
The report names Opus 4.6 and 4.7 for Alibaba, Opus 4.8 for Zhipu and just "Opus" for Moonshot and DeepSeek, which would be a problem for pricing except that Anthropic's pricing page lists Opus 4.5, 4.6, 4.7, 4.8 and 5 on five rows with one set of numbers: $5.00 per million input tokens, $6.25 to write a cache, $0.50 to read one, $25.00 output, and half of all that in batch. Whatever Opus a given exchange hit between March and July, it billed the same. So the only thing we have to assume is the shape of an exchange, and we would rather assume it three ways in the open than once in a footnote.
| Shape | Tokens per exchange | Opus, standard | Opus, batch | Where it comes from |
|---|---|---|---|---|
| Short | 1,000 in, 1,000 out | $0.030 | $0.015 | A floor. Nobody distils with less |
| Measured | 11,676 in, 60,799 cached, 1,462 out | $0.125 | $0.063 | The mean Opus 5 request on OpenRouter, September 7 to 13 |
| Reasoning dump | 2,000 in, 8,000 out | $0.210 | $0.105 | Our guess at a prompt that "forced Claude to write out its reasoning traces" |
The middle row is the only one anybody measured, and it is a measurement of the wrong traffic: OpenRouter's Opus 5 requests are coding agents with 84% of their input served from cache. Distillation traffic, as the report describes it, is short fixed prompts with long reasoning answers, which is the third row, and the third row costs seven times the first. Uncached, the measured shape would be $0.399 an exchange and more than three times the cached figure, so the caching assumption alone swings the total more than the difference between labs. We carry all three rows through. Pick the one you believe.
$5.7 million, $23.8 million or $39.9 million
| Lab | Exchanges | Short, $0.03 | Measured, $0.125 | Reasoning dump, $0.21 |
|---|---|---|---|---|
| Alibaba | 151,000,000 | $4,530,000 | $18,924,754 | $31,710,000 |
| Moonshot | 23,000,000 | $690,000 | $2,882,579 | $4,830,000 |
| DeepSeek | 12,100,000 | $363,000 | $1,516,487 | $2,541,000 |
| Zhipu | 3,400,000 | $102,000 | $426,120 | $714,000 |
| Xiaomi | 400,000 | $12,000 | $50,132 | $84,000 |
| All five | 189,900,000 | $5,697,000 | $23,800,072 | $39,879,000 |
List-price value of each lab's exchanges at the measured shape, millions of dollars
- Alibaba, 151M
- $18.92M
- Moonshot, 23M
- $2.88M
- DeepSeek, 12.1M
- $1.52M
- Zhipu, 3.4M
- $0.43M
- Xiaomi, 0.4M
- $0.05M
Exchange counts are Anthropic's floors. Per-exchange cost is the mean OpenRouter Opus 5 request in the week to September 13 at the $5 / $0.50 / $25 card. Moonshot is highlighted because the next section is about it.
Two ways to look at the middle column. TechCrunch's September 11 piece on Moonshot's revenue puts Anthropic's run rate at $65 billion a year, which is $7.42 million an hour. The entire disclosed campaign, at the measured shape, is 3.2 hours of Anthropic's revenue; at the reasoning-dump shape it is 5.4 hours; at the short shape, 46 minutes. Whatever the training value of 190 million Opus transcripts is to the labs that took them, and we have no way to price that, the retail value of the tokens is a rounding error to the company that sold them.
Except that it did not sell them, which is the second way to look at it. The report is explicit that the accounts were "created with stolen credit cards, login credentials, and API keys," that Alibaba's first pool used "residential proxies, disposable emails, and virtual-card payments," and that some of the stolen API credentials belonged "to legitimate companies or individuals." The dollar column is a counterfactual. It is what the traffic would have billed if it had been honest, and honest traffic from a Chinese-controlled entity has been off the table since Anthropic's September 4, 2025 restriction on anyone more than 50% owned from an unsupported region. What Anthropic actually lost is the compute, plus whatever chargebacks came through on the cards, and it publishes neither.
Kimi K3 is Opus times 0.6, to the cent
Here is the relay in the report's words: "In one instance, over a ten-day period, Moonshot relayed almost 300,000 customer requests to Anthropic, the vast majority of which were routed to Opus." That is 30,000 requests a day. The customers "thought they were using a Kimi model, but received responses from Claude instead," and Moonshot "captured and saved at least a portion" of the exchanges for training. The report does not say whether these were API customers or app users, and it does not say when in May to July the ten days fell. We priced it both ways.
| Per million tokens | Claude Opus 5 | Kimi K3 | Ratio | Kimi K2.6 | Ratio |
|---|---|---|---|---|---|
| Input | $5.00 | $3.00 | 0.600 | $0.95 | 0.190 |
| Cached input | $0.50 | $0.30 | 0.600 | $0.16 | 0.320 |
| Output | $25.00 | $15.00 | 0.600 | $4.00 | 0.160 |
| Measured shape, per request | $0.1253 | $0.0752 | 0.600 | $0.0267 | 0.213 |
We noticed the K3 column while building this table and went back to Moonshot's Kimi pricing page to make sure. $3.00 is 0.6 of $5.00, $0.30 is 0.6 of $0.50, $15.00 is 0.6 of $25.00, and both cards discount a cache hit to 10% of input. Because the ratio is the same on all three lines, it survives any token mix: a K3 request bills 60% of the identical request on Opus, whether it is a one-line chat or a 60,000-token cached agent turn. Which means a Kimi K3 API customer whose request was quietly sent to Opus paid Moonshot $0.0752 for something that would have cost Moonshot $0.1253 at Anthropic's list price. Forty cents lost on every dollar, on every request, by construction.
One relayed request at the measured shape, dollars
- What Opus bills Moonshot
- $0.1253
- What K3 bills the customer
- $0.0752
- What K2.6 bills the customer
- $0.0267
11,676 uncached input, 60,799 cached input, 1,462 output tokens, the OpenRouter Opus 5 mean. Over 300,000 requests: $37,599 billed by Opus against $22,559 collected at the K3 card or $8,000 at K2.6.
The K2.6 column is there because of a date. Kimi K3 went on sale on July 16 and the relay window is May to July, so for most of it the model a Kimi customer thought they were paying for was K2.6 or K2.7 Code, at $0.95 and $4.00. On that card Moonshot would have been selling $0.1253 of Opus for $0.0267, 21 cents on the dollar. There is no rate at which relaying Opus to a K2.6 customer is a business, and no rate at which relaying it to a K3 customer is one either. The economics only close if the Opus side costs nothing, and the report's explanation of how it cost nothing is the 5,380 accounts. The value Moonshot was after was never the margin on the request; it was the transcript that came back, which it kept, and which the report says it fed to a "CoT extraction pipeline."
If the customers were app users instead, the arithmetic gets worse for the customer and stays impossible for Moonshot. Kimi's consumer tiers run from $19 a month to $199, and the $99 Allegro tier is the cheapest whose row mentions "K3 extra-long chat capacity (up to 1M tokens)." A subscriber at 30 requests a day on the measured shape is $112.80 a month of Opus at list, on a $19 plan. Either way, the report's example of who was on the other end is "[a]n engineer at a major PRC SOE" who "revealed internal code and live credentials from multiple major PRC companies" and "had no way of knowing that their use of Kimi was being forwarded to Claude."
What the distilled models sell for
This is the part of the story that lands on a pricing site. Anthropic says the Alibaba transcripts went "into Qwen 3.5, 3.6, and 3.7," that Moonshot's went "to train its models," that Xiaomi's were "for both SFT and RL," and it does not name a Kimi, DeepSeek or GLM version. We are not going to either. What we can do is put each lab's current flagship card next to the card it was allegedly drawing from.
| Lab | Current flagship | Input / output | vs Opus $5 / $25 |
|---|---|---|---|
| Alibaba | Qwen3.8 Max | $2.00 / $6.00 | 0.40x / 0.24x |
| Moonshot | Kimi K3 | $3.00 / $15.00 | 0.60x / 0.60x |
| DeepSeek | DeepSeek V4 Pro, off-peak | $0.66 / $1.98 | 0.13x / 0.08x |
| Zhipu | GLM-5.3 | $1.40 / $4.40 | 0.28x / 0.18x |
| Xiaomi | MiMo-V2-Pro, under 256K | $1.00 / $3.00 | 0.20x / 0.12x |
MiMo-V2-Pro is on this list for a specific reason. The report says Xiaomi "may have launched its MiMo-V2-Pro model with a free trial period" that was "then extended" and did so "with the intent to use the surge in international developer use of the model to distill Claude capabilities," and that "[t]he bulk of the distillation attacks on Claude began just as the trial period was ending." A free tier as a transcript-collection device is a pricing decision, and it is the first time we have seen one described that way in a document like this.
One more data point landed the same day as the report. Cognition released SWE-2 on September 10, "post-trained from Kimi K3," and its headline claim is that on FrontierCode 1.1 it lands "within one point of Fable 5.1 while being 64% cheaper." The footnote gives Fable 5.1 Medium at $3.28 a task, which puts SWE-2 at about $1.18, and there is no API and no rate card, just Devin. So the chain now runs Opus transcripts, by Anthropic's account, into a Kimi base, into a Cognition post-train, sold as a per-task saving against Anthropic's own flagship. We are not in a position to say how much of K3 came from Claude. Neither, on the evidence of its own report, is Anthropic, which is why the document counts exchanges and not benchmark points.
What it changed for people who pay
The last two pages list the countermeasures, and three of them are things a paying developer will have felt. "Claude now summarizes its internal reasoning before responding," which is why you get a summary block and not the trace. "[W]ith Fable 5.1 we introduced preserved thinking, which stops new API accounts from altering the system prompt, tools, or messages that precede Claude's reasoning in multi-turn conversations," because "editing the context before it is a common technique attackers use to make Claude reveal it." And accounts that trip abuse signals, including "operating from unsupported countries like China, Russia, and Iran," can be made to verify identity or be banned. The mechanism Moonshot and DeepSeek used, saving the thinking signature and replaying it in a fresh session until Claude "convert[ed] the reasoning signature back into the full reasoning trace," is the one preserved thinking is built against.
None of this moved a price. Opus is $5 and $25 today, as it was in March. What moved is the product, and the reason is in a table that bills by the exchange.
Seven blanks in a 154-page report
- A token count, for any lab, in either the February or the September document. Every dollar figure above is ours.
- Which Opus the Moonshot and DeepSeek traffic hit. The report says "Opus"; the card is the same for 4.5 through 5, so it does not change the arithmetic, but it would change the story.
- Whether the 300,000 relayed requests came from API customers or app users, and which ten days they fell on.
- Whether any of the 5,380 accounts paid a real invoice. The report's language is stolen and virtual cards; it does not say all of them were.
- A response from Moonshot. CNBC says none of Alibaba, Moonshot, DeepSeek or Xiaomi "immediately respond[ed]" to its requests for comment, and we found nothing since. Moonshot's only statement in the window, on September 12, denied a rumour that its founder had been detained and called it "completely fabricated and malicious slander."
- A response from Alibaba, DeepSeek, Zhipu or Xiaomi. China's commerce ministry said on September 9 that distillation is "a normal technical and commercial issue in the AI industry," but that was a reply to the September 8 NSA, FBI and CISA advisory, not to Anthropic.
- The terms of the MiMo-V2-Pro free trial the report describes. Xiaomi's model page carries the $1 / $3 card for up to 256K and $2 / $6 above it, and nothing about a trial.
The Hacker News thread had 184 points and 243 comments when we checked, and the top-voted reply on the second thread was a version of "Claude took the whole internet, so what." That is an argument about ethics and we are not having it here. The argument we can have is that a report about tokens should say how many, and this one does not.
Where each number came from
- Anthropic: Detecting and countering misuse of AI: September 2026 - September 10, 2026. Distillation section pp. 143 to 154 of the full report PDF. Every per-lab count, account count, quoted sentence and countermeasure above
- Anthropic: Detecting and preventing distillation attacks - February 23, 2026. Over 150,000 exchanges for DeepSeek, over 3.4 million for Moonshot, over 13 million for MiniMax, about 24,000 accounts
- Anthropic: Updating restrictions of sales to unsupported regions - September 4, 2025. The 50% ownership rule and its distillation rationale
- Anthropic: Claude pricing - Opus 4.5, 4.6, 4.7, 4.8 and 5 at $5 / $6.25 / $0.50 / $25, batch half, read September 14
- Moonshot: Kimi API pricing - kimi-k3 at $3.00 / $0.30 / $15.00, kimi-k2.6 at $0.95 / $0.16 / $4.00, kimi-k2.7-code at $0.95 / $0.19 / $4.00, read September 14
- Kimi: Membership pricing - Moderato $19, Allegretto $39, Allegro $99, Vivace $199 a month
- OpenRouter: Claude Opus 5 - 16,816,241 requests, 1,218.7B prompt tokens of which 1,022.4B cached, 24.58B completion tokens, September 7 to 13, read from the model chart on September 14
- OpenRouter: Kimi K3 - 24,771,456 requests and 1,448.1B prompt tokens in the same week, about 210B tokens a day
- Alibaba Cloud: Model Studio pricing, DeepSeek pricing, Z.ai pricing - Qwen3.8 Max $2 / $6, DeepSeek V4 Pro $0.66 / $1.98 off-peak, GLM-5.3 $1.40 / $4.40, read September 14
- Cognition: SWE-2 - September 10, 2026. "Post-trained from Kimi K3"; 50.0% on FrontierCode 1.1 Main; "within one point of Fable 5.1 while being 64% cheaper," with Fable 5.1 Medium footnoted at $3.28 a task
- TechCrunch: Anthropic details distillation campaigns and Kimi maker Moonshot AI targets $2 billion in annual revenue - September 10 and 11, 2026. "Nearly 200 million"; a $2 billion target that is "double the company's reported revenue run rate for August"; Anthropic at $65 billion
- Moonshot's September 12 statement - The detention rumour denial, the only Moonshot statement in the window
- China.org.cn: MOFCOM on the US advisory - September 9, 2026. Distillation "a normal technical and commercial issue in the AI industry"
- Hacker News: Anthropic threat report - 184 points, 243 comments at the time of writing