ZeroHour
BleepingComputerpublished ()ingested Bill Toulas
Part of a story covered by 13 sources: “US Agencies Accuse Six Chinese AI Firms of Industrial-Scale Model Distillation; Anthropic Details 200 Million Claude Exchanges” — merged summary and timeline →

US says Chinese firms extracted billions of tokens from frontier AI models

highAI safety & security exploited in the wildimportance 78
AI summary · glm-5.3-flash

CISA, NSA, and FBI say six Chinese AI firms including DeepSeek industrial-scale distilled Anthropic, OpenAI, Google, and xAI frontier models.

A joint CISA, NSA, and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from frontier models via millions of API requests since late 2024. The agencies assess the operations likely had Chinese government awareness and represent a core development strategy. Tactics included fraudulent shared accounts, provider failover, proxy routing, and chain-of-thought extraction across Claude, GPT, Gemini, and Grok models.

  • Six Chinese firms accused of industrial-scale distillation against US frontier AI models since late 2024
  • Agencies assess Chinese government likely aware of the campaigns
  • Tactics include shared accounts, transfer-station proxies, and automated failover to evade detection
  • Recommendations include behavioral detection, response modification, and intelligence sharing
Full article466 words · extracted from bleepingcomputer.com · click to collapse

US says Chinese firms extracted billions of tokens from frontier AI models

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024.

A joint advisory from CISA, NSA, and the FBI  states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI models from Anthropic, OpenAI, Google, and xAI.

The agencies assess that the scale and sophistication of the operations indicate Chinese government awareness, mentioning that this approach is likely a core development strategy for the offending firms.

AI model distillation is a legitimate technique in which a “student” model learns from the outputs of a well-trained model, helping researchers and developers reduce training costs and speed up AI deployment.

However, as Google warned in February, distillation attacks can occur outside these companies’ controlled environments, abusing API access to extract the knowledge and logic of powerful models and compete with them at a fraction of the training cost.

CISA’s advisory explains that Chinese firms distribute API requests across fraudulent or shared accounts, APIs, cloud services, aggregators, and “transfer station” proxies to bypass geographic restrictions, usage limits, and detection.

Some of the prompts used attempted to expose restricted chain-of-thought reasoning, while automated systems switched providers and checked whether defenders had degraded the responses.

“Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures,” the advisory explains.

“China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.”

DeepSeek and MoonShot AI were marked as the top offenders involved in distilling multiple Claude, GPT, Gemini, and Grok models, followed by MiniMax, which targeted Claude, Gemini, and GPT models.

Alibaba and StepFun are accused of targeting Claude and GPT models to improve their products, while Z.AI allegedly targeted GPT-5.5 and Claude Opus 4.8.

The advisory recommends that AI companies improve behavioral and infrastructure-level detection, modify responses when distillation operations are suspected, and share intelligence about these campaigns with all stakeholders.

Potential indicators include new accounts immediately reaching maximum usage, continuous activity without normal human idle periods, shared accounts accessed from numerous IP addresses or user agents, identical prompts across multiple providers, unusually high subscription-to-usage ratios, and coordinated switching between access routes.

BleepingComputer has contacted all six Chinese AI firms for a statement, and we will add their statements if we get them.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/