Anthropic has disclosed that three Chinese AI laboratories — DeepSeek, Moonshot AI, and MiniMax — ran what it calls “industrial-scale” illicit distillation campaigns against its Claude models, generating over 16 million interactions via around 24,000 fraudulent accounts to extract Claude’s capabilities for training their own systems. The company argues that this capability siphoning not only violates its terms of service and regional access controls but also undermines AI safety by stripping away safeguards and potentially enabling national‑security‑relevant misuse.
According to Anthropic’s technical blog, the three labs used distillation, a standard AI technique in which a weaker model is trained on outputs from a stronger model, but applied it in a way Anthropic characterizes as “illicit” because it targeted a competitor’s proprietary system at scale rather than their own models. Anthropic reports that DeepSeek accounted for roughly 150,000 exchanges, Moonshot about 3.4 million, and MiniMax about 13 million, all routed through fake or misrepresented accounts and commercial proxy services designed to evade geographic and behavioral detection. The traffic allegedly focused on Claude’s most differentiated capabilities, including agentic reasoning, tool use, and coding, in some cases eliciting step‑by‑step “chain‑of‑thought” style reasoning that can be used as high‑value training data.
Anthropic warns that models distilled in this way can reproduce powerful capabilities without the original safety scaffolding, creating what it describes as “unprotected” systems that might be integrated into military, intelligence, surveillance, or offensive cyber operations. The company links these campaigns to broader policy debates on AI and semiconductor export controls, arguing that the scale of such distillation requires advanced chips and therefore strengthens the case for tight hardware controls. In response, Anthropic says it has deployed new detection classifiers, behavioral fingerprinting, stronger access controls, and product‑level countermeasures to make distillation attacks harder and to reduce the usefulness of outputs for illicit training, and is calling for coordinated action by AI providers, cloud platforms, and governments to share threat intelligence and align on defenses.
✨ AI-generated background, compiled from web sources — not editorial content.