Illicit model distillation · GTG-16008

Report's Allegations of Training Data Use by Xiaomi: Case GTG-16008

Source notice

This page is a Chinese-to-English translation of content from pages 151–152 of Anthropic's September 2026 report. Statements regarding Xiaomi are the publisher's allegations. The qualification that 'the report does not find that Claude's responses were used to directly serve users' must be retained.

According to an Anthropic report, Xiaomi replayed user conversations and programming sessions from its own MiMo model to Claude, often routed through third-party programming tools. The investigation did not show that Xiaomi used Claude's responses to directly serve its users; rather, it saved conversations between Xiaomi customers and its own model. Many sessions were routed through third-party routing services commonly used by US and European users. This case differs from the Moonshot / DeepSeek cases of 'substituting its own model's answers': Xiaomi did not use Claude responses to directly serve users, but saved the conversations.

What happened

We also discovered illicit distillation activity conducted by Xiaomi. Xiaomi replayed user conversations and programming sessions from its own MiMo model to Claude, typically running through OpenClaw and OpenCode coding tools. Our investigation did not show that Xiaomi used Claude's responses to serve its users; rather, it saved exchanges between Xiaomi customers and its model. Many of these exchanges were routed through third-party model routing services commonly used by US and European users.

Xiaomi saved the complete requests and responses of its own users and replayed these sessions to Claude to generate data for supervised fine-tuning (SFT) and reinforcement learning (RL). We observed over 400,000 Claude requests routed through proxy services to over 1,500 accounts.

Our investigation suggests that Xiaomi may have launched a free trial period — later extended — around the release of its MiMo-V2-Pro model, with the intent of exploiting the surge in international developer usage of the model to distill Claude's capabilities. Most of the distillation attacks against Claude began right as the trial period ended.

The forwarded traffic included sensitive data from users who accessed Xiaomi's model through third-party model routing platforms. We have no indication that Americans' data was exposed, but these platforms are commonly accessed by users in the US and Europe. These requests to Claude contained names, contact information, company data, and other sensitive data from hundreds of Xiaomi users in at least a dozen languages.

Xiaomi's illicit distillation activity used Claude to strengthen training data for future models. Claude was used to reconstruct developer environments from exchange records. It also converted multi-turn conversations into clearer exchanges. Claude was also used to generate input requests and returned responses, mimicking conversations between developers and the model. Finally, Xiaomi used Claude to judge the quality of certain answers.

Scale of the distillation attacks attributed to Xiaomi over 20 days from March to April 2026: over 400,000 exchanges observed.

What AI did in this case

Xiaomi replayed user conversations to Claude to generate training data for SFT and RL.

Claude was used to reconstruct developer environments, convert multi-turn conversations into clearer exchanges, generate request-response pairs, and judge answer quality.

What the report observed

The report confirms Xiaomi replayed user conversations to Claude to generate training data. The report confirms it did not show that Xiaomi used Claude's responses to directly serve users.

The report confirms many sessions were routed through third-party routing services commonly used by US and European users, and that the requests contained users' sensitive data.

The report confirms over 400,000 exchanges observed over 20 days from March to April 2026.

Confirmed & unknown

Confirmed

  • The report alleges Xiaomi replayed user conversations from its own MiMo model to Claude
  • The report did not show that Xiaomi used Claude's responses to directly serve users
  • The report alleges many sessions were routed through third-party programming and model routing services
  • The report confirms over 400,000 exchanges observed over 20 days from March to April 2026

Unknown

  • The report does not state whether Xiaomi notified users that their conversations were replayed to Claude
  • The report does not state whether the generated training data was used in the final training of the MiMo model
  • The report does not include Xiaomi's response to these allegations

Platform response

Anthropic states it has banned the relevant accounts and deployed measures to detect and disrupt future abuse.

Limits of response:Banning accounts cannot recover the user conversations that have already been saved; the report does not state whether Xiaomi has stopped its replay behavior.

Takeaways

  • User conversations may be replayed by model providers to other models for training without users' knowledge.
  • This case differs from request-forwarding cases: Xiaomi did not use Claude's responses to directly serve users, but saved conversations for training.
  • Third-party routing services can become channels for user data leakage.

Sources