ZeroHour
Story · 1 source · 1 articlefirst updated ()

NSA, CISA, and FBI Accuse Six Chinese AI Firms of Industrial-Scale Distillation of US Frontier Models

highAI safety & securityimportance 84
What's new: Initial merged summary — no previous story. Seven reports from 2026-09-09 all cover the same newly issued joint NSA/CISA/FBI advisory. Sources agree on the named firms, the late-2024 start, and the billion-token scale; minor discrepancies exist in the framing of government involvement ('knowledge/awareness' vs. 'backing') and in the specific frontier model versions cited (GPT-4/5 and Grok 4 in…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint NSA, CISA, and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from Claude, GPT, Gemini, and Grok since late 2024 via shared premium accounts, gray-market proxy 'transfer stations,' and…

Seven same-day reports (2026-09-09) cover a joint advisory from the NSA, CISA, and FBI accusing six China-based AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — of systematic, industrial-scale knowledge distillation of US frontier models, including Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok. The agencies say billions of tokens were extracted across millions of API requests since at least late 2024, assessing the campaigns as a core Chinese development strategy likely conducted with government knowledge (The Hacker News frames this as likely government 'backing'). Alleged tactics included shared and fraudulent premium subscription accounts, Taobao-marketed proxy relays called 'transfer stations,' VPNs and obfuscated accounts, automated failover between providers, request metadata sanitization, and prompt injection to extract hidden chain-of-thought reasoning. The distilled data reportedly aided DeepSeek's R1/V3 and Moonshot's Kimi models. The agencies mapped the TTPs to MITRE ATLAS, described the activity as a strategic economic threat to US technological leadership, and recommended identity verification, behavioral monitoring, differential privacy, indicator sharing, and covertly degrading responses to suspected distillers.

  • A joint NSA, CISA, and FBI advisory reported on 2026-09-09 names six China-based firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
  • Targeted US frontier models include Claude, GPT, Gemini, and Grok; SecurityWeek cites GPT-4/GPT-5 and Grok 4 specifically.
  • Billions of tokens were allegedly extracted across millions of API requests since at least late 2024, likely with Chinese government knowledge/awareness (The Hacker News says 'backing').
  • Distilled capabilities allegedly trained DeepSeek's R1 and V3 models and Moonshot's Kimi models (Kimi-K2/K3 per SecurityWeek).
  • Tactics included shared/fraudulent premium subscription accounts across developer teams, gray-market proxy 'transfer stations' (including Taobao-marketed relays), VPNs and obfuscated accounts, automated failover between providers, and…
  • Security Affairs reports MiniMax allegedly used prompt injection that made Claude Code believe it was a MiniMax product, and that Moonshot redirected extraction to a newly launched Claude model within 24 hours of its release.
  • Help Net Security reports Z.AI distilled data from GPT-5.5 and Claude Opus 4.8 for chain-of-thought reasoning.
  • DeepSeek reportedly ran an organized campaign against Claude, GPT, and Gemini between late 2024 and mid-2025 that aided R1 and V3 development; the agencies challenge DeepSeek's reported $5.6 million training cost (Help Net Security).

Coverage timeline

  1. · 7d ago
    The Hacker News· 62
    U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

    NSA, CISA and FBI accuse Chinese AI firms including DeepSeek of industrial-scale distillation of Claude, GPT, Gemini and Grok since late 2024.