China's Technological Playbook
Part 1: The Theft Economy
In 1978, China’s GDP per capita sat at around $157– poorer than most of sub-Saharan Africa. Then, from 1979-2018, it pulled off what the World Bank calls “the fastest sustained expansion by a major economy in history,” with an average GDP growth of 9.5% per year; the country also lifted nearly 800 million people out of poverty.
How did they do it?
Most of the standard sources on the topic cite market reforms, cheap land and labor, investments in infrastructure and education programs, and the rise of export-driven manufacturing.
These are all true. But there’s another input, one the NSA’s own director called “the greatest transfer of wealth in history.”
Theft of Intellectual Property (IP)
For the past two and a half decades, Chinese state-sponsored hacking groups have systematically broken into Western companies and stolen intellectual property, including R&D information, product designs, manufacturing processes, pricing sheets, and even legal strategy for trade disputes against China itself. The U.S. Senate Committee on the Judiciary cites estimates that “China steals between $400 billion and $600 billion of IP each year, or about $5,000 per American taxpayer.”
Chinese actors have stolen– or been credibly accused of stealing– trade secrets from Nortel, U.S. Steel, and SolarWorld, among many others; the CCP has also taken blueprints for “fighter jets, helicopters, and missiles” – technologies that have both military and commercial applications.
This piece walks through the CCP’s technological playbook, with case studies from the telecom, steel, solar, and agricultural industries, and ends with the early evidence in AI. It focuses mainly on the economic impacts of IP theft.
The next piece(s) in the series will cover who does the hacking, why this is China’s “golden age” of cyber espionage, how Beijing has pre-positioned inside American critical infrastructure, why this matters for national security, and what all of it implies for securing frontier AI.
Case Studies
Telecommunications Infrastructure
Nortel & Cisco
“Using seven passwords stolen from top Nortel executives, including the chief executive, the hackers—who appeared to be working in China—penetrated Nortel’s computers at least as far back as 2000 and over the years downloaded technical papers, research-and-development reports, business plans, employee emails and other documents, according to Brian Shields, a former 19-year Nortel veteran who led an internal investigation.”
Shields is blunt about who he believes benefited; Huawei denies it, and no forensic link has ever been published. However, Huawei was later caught using verifiably stolen code from Cisco.
Nortel went bankrupt in 2009; Huawei is now the world’s largest telecommunications equipment manufacturer and, at one point, was the “second-biggest smartphone seller in the world” – larger than Apple. In Q1 and Q2 of 2025, Huawei “captured about 31% of the global telecom equipment market.”
Steel
U.S. Steel, Allegheny Technologies, the United Steelworkers Union
“The Chinese industry has used its government to steal U.S. Steel’s closely guarded trade secrets and uses those trade secrets to produce advanced steel products it could not make on its own.”
—NPR, reporting language from U.S. Steel’s trade complaint with the ITC
As one specific example, The Hill reports that U.S. Steel spent millions of dollars on R&D “to pioneer a new, lighter, higher-grade steel product for use in automobiles and elsewhere,” but that Chinese hackers broke into the company’s computers and “stole the advanced formula.” Now, Chinese state-owned steelmaker ‘Baosteel’ appears to be selling similarly advanced formulations of steel for cut-rate prices.
It’s worth noting that U.S. Steel later withdrew their trade-secrets claim, saying trade law gave victims of state-sponsored hacking no workable way to prove it– so the allegation was never tested in court. However, a separate 2014 criminal indictment of five PLA officers still stands– but they remain in China, beyond the reach of U.S. courts, so its allegations were never tested at trial either. (The specifics of this indictment will be covered more in-depth in a future installment of this series, though some parts of it are also cited below.)
In addition to U.S. Steel, reporting from the New York Times describes how China stole “computer records containing trade policy strategies and discussions about rare earth metals and auto parts” from the United Steelworkers Union, according to an indictment released by the Justice Department.
Another victim was Allegheny Technologies (ATI), a Pittsburgh specialty metals manufacturer. In 2012, ATI was simultaneously partnered with, competing against, and involved in a trade dispute with Baosteel. The two had run a precision stainless joint venture together since 1995. One day after the joint venture’s board of directors met, PLA officer Wen Xinyu broke into ATI’s network and stole login credentials for at least 7,000 employees; those credentials were later used to steal information from the company.
Alcoa (note: aluminum, not steel)
A separate PLA officer, Sun Kailiang, stole nearly 3,000 emails from Alcoa. The emails included senior executives’ discussions of its partnership with state-owned Chinalco. Similarly to ATI’s case, the theft took place about three weeks after Alcoa’s partnership was announced.
Alcoa and ATI show that China hacks its business partners in addition to adversaries.
Solar Panels
SolarWorld
“SolarWorld Americas, the largest manufacturer of solar panels in the United States, has asked the Commerce Department to investigate claims that Chinese military personnel broke into the company’s computers and stole documents important to its business and its long-running trade dispute with China.”
As one example of how IP theft had enabled China to leapfrog competition, SolarWorld specifically pointed to Chinese companies’ rapid adoption of Passivated Emitter Rear Contact (PERC) solar cells, claiming that:
“[W]ere it not for their economic espionage and theft from SolarWord [sic] Americas, Chinese solar producers like JA Solar and Trina, would have taken far longer to make the leap into PERC technology.”
—SolarWorld CEO Juergen Stein, PV Magazine
SolarWorld was one of the first solar manufacturers to bring PERC technology to mass production. However, unable to compete with cheap– and heavily subsidized– solar panels from Chinese competitors, SolarWorld eventually filed for insolvency. While not the primary cause of their downfall, the theft of the company’s pricing, product, and legal strategy documents exacerbated an already difficult position.
A Note on Scope
The cases so far share a method: remote intrusion run by state-sponsored hackers. But cyber espionage is only one channel in a wider acquisition system. Sometimes, the theft is physical: an employee walking out with files, or digging proprietary seeds out of an Iowa field (as I’ll write about shortly!). Sometimes, it’s structural: for decades, foreign firms wanting access to China’s market were required to enter joint ventures with local partners, arrangements the U.S. Trade Representative found were used to pressure the transfer of technology.
The case studies included in this piece primarily focus on the cyber channel, because it scales the most easily, and it’s the one that matters most for what comes later in this series. However, the two remaining examples below include one theft that involved no computers at all. The playbook is defined by its goal, not its method. As I’ll write about in future installments, these cases show that cyber hardening alone is not enough to secure AI.
Agriculture
DuPont Pioneer & Monsanto
“A Chinese national sentenced last month in Iowa for stealing trade secrets wasn’t looting blueprints for military weapons, computer software, or high-tech electronics. Mo Hailong’s efforts were considerably more grounded—he was stealing corn.”
For five years, Mo stole proprietary corn seeds and sent them overseas to his employer, a Chinese corn seed company. The corn seeds he stole were valuable trade secrets from DuPont Pioneer and Monsanto.
Mo was not acting alone; the investigation of this case later expanded to “include five other conspirators… across six states and thousands of miles.” In one instance, Mo, along with two co-conspirators, attempted to send a staggering “250 pounds of corn seeds” to Hong Kong.
Why do these corn seeds matter so much?
Typically, the corn a farmer buys is hybrid seed. These seeds are high-yielding, but they don’t breed true; if farmers save and replant hybrid seeds, the next generation has less desirable genetic traits and a lower yield. Because of this, farmers have an incentive to buy new hybrid seeds each year.
This means that for seed companies like DuPont and Monsanto, the biggest value in the sector is in the inbred parent lines that get crossed to produce the hybrid. These lines are the actual intellectual property, the product of years of breeding, and companies guard them closely– they’re never sold to farmers directly, only planted in controlled fields.
Mo was stealing seeds from inbred parent lines, in a form that could be replanted indefinitely in China.
By DuPont Pioneer’s own estimate, losing one inbred line would mean forfeiting “five to eight years of research and at least $30 million.”
Artificial Intelligence
What do we know about AI so far?
Distillation
This newest channel doesn’t require breaking into anything. Distillation is a training method where a smaller, weaker model is built using the outputs of a stronger one– a user queries the powerful model at scale, collects its answers, and trains their own system to imitate them. It’s essentially a shortcut to creating high-quality synthetic data.
While distillation can be a legitimate technique if done with permission, if done against a competitor’s model, it’s a way to copy hard-won capabilities without having to spend millions of dollars and several months on the research that produced them– and it sits in a legal gray area that export controls, primarily written for chips and model weights, don’t clearly cover.
Some examples of recent accusations:
In February 2026, OpenAI said it had evidence that DeepSeek had distilled its models, and had uncovered “new, obfuscated methods” being used by the company in order to evade detection.
In February 2026, Anthropic reported that DeepSeek, Moonshot, and MiniMax had together run more than 16 million exchanges with Claude via ~24,000 fraudulent accounts, using commercial proxies to evade its China access restrictions.
Then, in a June 10, 2026 letter to the U.S. Senate Committee on Banking, Housing, and Urban Affairs, Anthropic accused actors linked to Alibaba and its Qwen AI lab of the largest distillation campaign it had seen– 28.8 million exchanges across ~25,000 fake accounts, over a 44-day window.
[Note: A related but distinct problem is chip smuggling (which I’ve written more about with Jason here), though that’s China acquiring hardware it can’t legally access, not necessarily stealing the IP behind it.]
United States v. Linwei Ding
In 2019, Google hired a software engineer named Linwei Ding to work on the software for supercomputing data centers that train its AI models. Over the course of a year (May 2022 - May 2023), he uploaded more than 1,000 confidential files to a personal cloud account.
According to the Justice Department:
“The [files] contain detailed information about the architecture and functionality of Google’s Tensor Processing Unit (TPU) chips and systems and Google’s Graphics Processing Unit (GPU) systems, the software that allows the chips to communicate and execute tasks, and the software that orchestrates thousands of chips into a supercomputer capable of training and executing cutting-edge AI workloads… [they] also pertain to Google’s custom-designed SmartNIC, a type of network interface card used to enhance Google’s GPU, high performance, and cloud networking products.”
To hide that he was frequently in China, a colleague badged him into the office to fake his presence in the U.S. All the while, Ding was secretly affiliated with two Chinese tech firms: he was discussing becoming CTO of one company and was founding another, where he acted as CEO. Ding had applied to a Beijing talent program, writing that he wanted to help China build computing infrastructure “on par with the international level.”
In January 2026, a federal jury convicted him on all fourteen counts, including seven of economic espionage.
Conclusion
The pattern that emerges from the above is that when the United States builds something valuable, China often finds a way to acquire it, and to skip the years of research and the billions in cost that building it honestly would have required. Many of the companies in these case studies learned the pattern the hard way, after the fact.
Theft was rarely the sole reason an American company fell; subsidies, scale, and price wars did much of that work. But across these industries, the apparent objective was remarkably consistent: acquire technical and commercial knowledge that could compress years of research, reduce development costs, and help Chinese firms close the gap faster.
The playbook that targeted Nortel, SolarWorld, and Allegheny Technologies is now pointed at the most valuable technology America has ever produced. This time, we get to read it in advance.
Reminder: The next piece(s) in the series will cover who does the hacking, why this is China’s “golden age” of cyber espionage, how Beijing has pre-positioned inside American critical infrastructure, why this matters for national security, and what all of it implies for securing frontier AI.


