ZeroHour
Story · 1 source · 1 articlefirst updated ()1

NSA/CISA/FBI Advisory and Anthropic Reports Detail Chinese Firms' Industrial-Scale Distillation of US Frontier AI Models

highAI safety & securityimportance 84
What's new: No new allegations versus the previous summary; sources remain consistent on the core facts. This merge completes the previously truncated mitigation list and incorporates The Decoder's September 11 report on Anthropic's full threat intelligence report (December 2025–August 2026), which adds: DeepSeek routed 12.1 million exchanges to Claude Opus, including PLA-linked CCTV analysis; Xiaomi and…
Merged summary · glm-5.3 · rewritten as coverage arrives

Joint advisory AA26-251A accuses six Chinese AI firms of extracting billions of tokens from Claude, GPT, Gemini and Grok since late 2024; Anthropic's follow-up reports detail nearly 200 million Claude exchanges across five distillation campaigns, led by…

On September 9, 2026, the NSA, CISA and FBI issued joint advisory AA26-251A accusing six China-based AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — of industrial-scale knowledge distillation against US frontier models including Claude, GPT (GPT-4/GPT-5), Gemini and Grok 4 since at least late 2024, extracting billions of tokens across millions of API requests and exchanges. The agencies assess the operations likely proceeded with Chinese government awareness, describe distillation as a core development strategy that shortens Chinese AI timelines and cuts frontier training costs, and dispute DeepSeek's reported $5.6 million training-cost figure as excluding the value of distilled data. Tactics, mapped to MITRE ATLAS alongside novel techniques, include gray-market API proxies called 'transfer stations,' pools of premium accounts opened with fraudulent identities, bulk premium subscription exploitation, proxy routing to bypass geographic controls, automated provider failover, request metadata sanitization, and prompt injection or jailbreak-style prompts to force models to reveal hidden chain-of-thought reasoning. Specific allegations: DeepSeek ran an organized campaign against Claude, GPT and Gemini from late 2024 to mid-2025 aiding its R1 and V3 models; Moonshot AI distilled data to train Kimi-K2/K3 and redirected extraction to a new Claude model within 24 hours of its launch; MiniMax used prompt injection that made Claude Code believe it was a MiniMax product; and Z.AI allegedly distilled GPT-5.5 and Claude Opus 4.8 (per Help Net Security). On September 10, 2026, Anthropic published a report detailing five distillation campaigns totaling nearly 200 million Claude exchanges targeting agentic tool use, coding, data analysis and reasoning — the largest attributed to Alibaba, with 151 million exchanges across roughly 3,500 fraudulent accounts between May and July 2026, peaking near three million exchanges per day, allegedly to produce training material for the Qwen family (The Decoder specifies Qwen 3.5, 3.6 and 3.7). A Moonshot AI campaign routed roughly 300,000 requests over ten days through 5,000 accounts, primarily targeting Opus, including one CCTV-analysis task that appeared connected to the Chinese military. Attackers used prompt tricks such as katakana-only Japanese translation requests to expose Claude's internal reasoning traces. The Decoder's September 11 coverage of Anthropic's broader threat intelligence report (December…

  • NSA, CISA and FBI joint advisory AA26-251A (September 9, 2026) names six Chinese firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.
  • Alleged extraction of billions of tokens across millions of API requests from Claude, GPT-4/GPT-5, Gemini and Grok 4 since at least late 2024, likely with Chinese government awareness.
  • Tactics include 'transfer station' API proxies, fraudulent shared premium account pools, geo-restriction bypass via proxy routing, automated failover, metadata sanitization, and prompt injection/jailbreaks to extract hidden…
  • Distilled data reportedly trained DeepSeek R1/V3, Moonshot Kimi-K2/K3 and Alibaba's Qwen family; agencies dispute DeepSeek's $5.6 million training-cost claim as excluding the value of distilled data.
  • Anthropic (September 10, 2026): five distillation campaigns totaling nearly 200 million Claude exchanges; the largest, attributed to Alibaba, ran 151 million exchanges across ~3,500 accounts from May to July 2026, peaking near 3 million…
  • Moonshot AI campaign: ~300,000 requests over ten days via 5,000 accounts, primarily targeting Opus, including a CCTV-footage analysis task that appeared connected to the Chinese military.
  • Prompt tricks included katakana-only Japanese translation requests to expose Claude's reasoning traces; MiniMax allegedly used prompt injection that made Claude Code believe it was a MiniMax product.
  • Anthropic's broader report (December 2025–August 2026) adds that Xiaomi and Zhipu also relayed or replayed traffic to Claude, DeepSeek routed 12.1 million exchanges to Claude Opus including PLA-linked CCTV analysis, some users held…

Coverage timeline

  1. · 7d ago
    CyberScoop· 68
    Feds accuse China of ‘systematic’ distillation of U.S. AI models

    NSA, CISA, and FBI jointly accuse Chinese AI firms including DeepSeek and Moonshot AI of industrial-scale distillation of US frontier models.