Anthropic has accused three Chinese AI labs—DeepSeek, Moonshot, and MiniMax—of conducting industrial-scale 'distillation' attacks against its Claude models. By using over 24,000 fraudulent accounts and proxy services, these labs allegedly extracted model capabilities to improve their own products, violating Anthropic's terms of service. Anthropic warns that these illicitly distilled models lack necessary safety guardrails, posing significant national security risks by potentially enabling offensive cyber operations, disinformation, and mass surveillance.
Anthropic said it identified large-scale campaigns that used fraudulent accounts and proxy services to generate high volumes of Claude interactions to extract model capabilities for competitor training ("distillation"). Anthropic attributed the activity to DeepSeek, Moonshot, and MiniMax and said it involved millions of exchanges across thousands of accounts, violating its terms and access restrictions. Anthropic described detection measures, account controls, and indicator-sharing in response.
Risk classification
- Primary risk domain: 2 Privacy & Security
- Primary risk subdomain: 2.2 AI system security vulnerabilities and attacks
The incident involves Chinese AI labs exploiting API access vulnerabilities through proxy networks and fraudulent accounts to conduct large-scale distillation attacks, extracting proprietary model capabilities.
Additional risk subdomains
- 6.4 Competitive dynamics: The distillation campaigns are driven by geopolitical and commercial competition to bypass export controls and rapidly advance Chinese AI capabilities at the expense of safety guardrails.
- 4.3 Fraud, scams, and targeted manipulation: The labs utilized 24,000 fraudulent accounts and proxy services to systematically evade detection and illicitly extract intellectual property for competitive advantage.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The incident was caused by human actors at Chinese AI labs intentionally executing coordinated distillation campaigns against Anthropic's deployed Claude models.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The Claude models and the distilled Chinese models are general-purpose AI systems and chatbots. Under the EU AI Act, chatbots and AI systems generating content are classified as Limited Risk (Level 3), requiring transparency obligations.
AI system and alleged parties
- AI system: Claude (Anthropic)
- AI purpose: Question Answering; Code Generation
- Behaviour type: Assistant
- Alleged developer: Anthropic
- Alleged deployer: Proxy reseller services, Moonshot AI, MiniMax, DeepSeek
- Alleged harmed parties: National security and intelligence stakeholders, Claude users, Anthropic customers, Anthropic
Harm severity
Highest direct severity in any category: Severe. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
People affected
Potential causes
Management
- Prioritizing Cheap Capability Growth: Labs used distillation as a shortcut instead of independent training.
- Underestimating API Abuse Scale: Management failed to anticipate coordinated multi-account campaigns.
- Delayed Countermeasure Deployment: Defensive classifiers were built after massive extraction occurred.
Technology
- Proxy Hydra Cluster Architectures: Sprawling proxy networks bypassed single-point API bans.
- Vulnerable Account Creation Pathways: Exploitation of educational and startup verification processes.
- Lack of Output Distillation Defenses: API returned raw reasoning traces without obfuscation or degradation.
Data Inputs
- Chain-of-Thought Elicitation Prompts: Prompts forced the model to output step-by-step reasoning data.
- Censorship-Safe Query Generation: Prompts generated politically safe data to train foreign models.
- Targeted High-Volume API Queries: 16 million queries focused on agentic reasoning and coding.
Human Factors
- Deliberate Terms of Service Evasion: Researchers knowingly used fake accounts to bypass restrictions.
- Hiding Traffic in Normal Usage: Actors mixed distillation requests with benign customer traffic.
- Bypassing Regional Access Bans: Users in restricted markets actively sought unauthorized access.
Process and Methods
- Weak Initial Account Verification: Verification steps failed to identify coordinated fraudulent setups.
- Delayed Detection of API Abuse: System failed to identify coordinated hydra networks in real-time.
- Absence of Industry Intel Sharing: Lack of early threat sharing enabled cross-platform exploitation.
Regulatory Environment
- Unenforceable Terms of Service: Legal terms carry little weight against foreign state-backed labs.
- API Gaps in Export Controls: Physical chip restrictions did not prevent remote API exploitation.
- Lack of Global AI Governance: No international framework exists to penalize model capability theft.
Information quality
- Classification confidence: High
- Reason for confidence: The reports from multiple sources provide highly detailed, consistent, and specific technical details about the distillation campaigns, including the number of accounts (24,000), exchanges (16 million), and the specific labs involved. There is little ambiguity about the facts of the accusations, though the accused Chinese labs have not publicly commented.
- Ambiguities identified: The Chinese labs have not responded to the allegations, so we only have the US firms' (Anthropic and OpenAI) side of the story. Additionally, the exact timeline of when these campaigns occurred is not fully specified.
- Alternative interpretations: The Chinese labs might argue that distillation is a standard, legitimate industry practice and does not constitute 'theft' or 'attacks' as characterized by Anthropic.
Coordinated, industrial-scale distillation campaigns by Chinese AI labs targeted Anthropic's Claude models, successfully extracting advanced capabilities. This represents a substantial technological security challenge, enabling foreign entities to bypass export controls and accelerate their own AI development using stolen US intellectual property.
- Overall national security impact: Substantial
- Response level: Substantial
- Scope: Multiple nations
- Primary target: United States
- Alleged perpetrator: Chinese AI laboratories (DeepSeek, Moonshot, and MiniMax)
Threat characteristics
- Imminence: Long-term. The incident represents a strategic, long-term capability transfer and competitive challenge rather than an immediate, active crisis requiring urgent operational response.
- Autonomy: Human-controlled. The distillation campaigns were manually planned, orchestrated, and executed by human researchers using automated API querying scripts and proxy networks.
- Novelty: Evolved capability. While model distillation is an established technique, the industrial scale, coordination, and sophisticated evasion methods (hydra clusters, 24,000 accounts) represent a significant evolution in capability.
Impact by dimension
- Physical security: Negligible. No physical security threats or critical infrastructure compromises were reported in connection with this model distillation incident.
- Information security: Minor. The extraction of advanced reasoning and coding capabilities poses potential future risks for automated cyber operations and information warfare, though no active campaigns were executed.
- Sovereignty: Negligible. The incident did not directly target or disrupt government decision-making, elections, or core sovereign operations.
- Economic security: Substantial. Substantial impact on technological security as foreign competitors used highly coordinated evasion techniques to illicitly extract proprietary frontier AI capabilities, undermining US competitive advantage and bypassing export controls.
- Societal stability: Negligible. No immediate or direct societal instability, mass surveillance implementation, or human rights violations occurred as a direct result of this API-scraping activity.