NSA, CISA, and FBI Say Six Chinese AI Firms Systematically Distilled US Frontier Models
A joint NSA, CISA, and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation—extracting billions of tokens via millions of API requests from US frontier models including Claude, GPT-4/5, Gemini, and…
On 2026-09-09, the NSA, CISA, and FBI issued a joint advisory accusing six China-based AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—of systematically extracting billions of tokens across millions of API requests from US frontier models, including Claude, GPT-4/GPT-5, Gemini, and Grok 4, since at least late 2024. The agencies assess the distillation—whose output fed DeepSeek's R1 and V3 and Moonshot's Kimi-K2/K3 models—was a core Chinese development strategy likely conducted with Chinese government awareness, and describe it as a strategic economic threat to US technological leadership. Reported tactics include bulk procurement of premium subscriptions with fraudulent shared accounts, gray-market proxy 'transfer stations,' automated failover across providers, request metadata sanitization, and prompt injection used to force models to reveal hidden chain-of-thought reasoning; TTPs were mapped to MITRE ATLAS alongside additional novel techniques. Specific incidents cited include DeepSeek's organized campaign against Claude, GPT, and Gemini between late 2024 and mid-2025, Moonshot redirecting extraction to a new Claude model within 24 hours of its launch, and MiniMax allegedly using prompt injection that made Claude Code believe it was a MiniMax product. The advisory urges US AI firms to adopt countermeasures such as behavioral detection, stronger identity verification, differential privacy, monitoring for multi-IP 24/7 account usage and abnormal subscription-to-API ratios, intelligence sharing, targeted cost-imposing responses, and covertly degrading or adding noise to responses served to suspected distillers—while warning these mitigations could frustrate legitimate users.
- Joint NSA, CISA, and FBI advisory published 2026-09-09 (reported by SecurityWeek, BleepingComputer, Security Affairs, Dark Reading, and Ars Technica).
- Six Chinese AI firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
- Targeted US frontier models include Claude (Anthropic), GPT-4/GPT-5 (OpenAI), Gemini (Google), and Grok 4 (xAI).
- Scale: billions of tokens extracted via millions of API requests, beginning since at least late 2024.
- Extracted capabilities trained DeepSeek's R1 and V3 models and Moonshot's Kimi-K2/K3 models.
- DeepSeek reportedly ran an organized campaign against Claude, GPT, and Gemini between late 2024 and mid-2025 that aided R1 and V3 development.
- Tactics included fraudulent shared premium accounts, gray-market proxy 'transfer stations,' automated provider failover, request metadata sanitization, and chain-of-thought extraction via prompt injection.
- TTPs were mapped to MITRE ATLAS, with the agencies noting additional novel techniques such as subscription exploitation and metadata sanitization.
Coverage timelineoldest first · each row is one article
- · 7d agoUS Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
SecurityWeek· 84
NSA, CISA and FBI warn Chinese AI firms including DeepSeek and Moonshot systematically extracted billions of tokens from US frontier models since late 2024.