ZeroHour
Story · 1 source · 1 articlefirst updated ()

CISA, NSA and FBI Say Six Chinese AI Firms Distilled Billions of Tokens From Claude, GPT, Gemini and Grok

highAI safety & securityexploited in the wildimportance 84
What's new: First merged summary for this story: a new joint CISA-NSA-FBI advisory reported on 2026-09-09 publicly names six specific Chinese AI firms, ties industrial-scale distillation to concrete product outcomes (DeepSeek R1/V3, Kimi-K2/K3), maps the tactics to MITRE ATLAS, and introduces new countermeasure guidance including covert response degradation and differential privacy.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint CISA, NSA and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of industrial-scale distillation of US frontier models, extracting billions of tokens across millions of API requests since at least late 2024 via proxy…

A joint advisory from CISA, NSA and FBI, reported on 2026-09-09, alleges six China-based AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — ran industrial-scale knowledge distillation campaigns against US frontier models including Claude (Anthropic), GPT (OpenAI), Gemini (Google) and Grok (xAI), extracting billions of tokens across millions of exchanges since at least late 2024. The agencies assess the activity likely occurred with Chinese government knowledge, though The Hacker News characterizes it as likely government backing. Tactics allegedly included gray-market API proxies dubbed 'transfer stations', account pools, bulk or fraudulent shared premium subscriptions, VPNs and obfuscated accounts (some relays marketed on Taobao), automated failover across providers, and prompt injection or jailbreak-style requests to force models to reveal hidden chain-of-thought reasoning. The extracted data reportedly helped train DeepSeek's R1 and V3 and Moonshot's Kimi-K2/Kimi-K3 models. SecurityWeek reports the tactics were mapped to MITRE ATLAS alongside novel techniques like subscription exploitation and request metadata sanitization, and frames the activity as a strategic economic threat to US technological leadership. Recommended countermeasures include identity verification, monitoring of anomalous subscription-to-usage ratios, rate limiting, behavioral detection, differential privacy, indicator sharing across providers and clouds, and covertly degrading responses to suspected distillers — a step Ars Technica notes could frustrate legitimate users.

  • Six Chinese firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, accused of distilling US frontier models including Claude, GPT, Gemini and Grok (SecurityWeek specifies GPT-4/GPT-5 and Grok 4).
  • Billions of tokens were extracted across millions of API requests/exchanges since at least late 2024, per the joint CISA-NSA-FBI advisory.
  • Most reports say the campaigns ran likely with Chinese government awareness; The Hacker News says likely government backing.
  • Extracted data reportedly benefited DeepSeek's R1 and V3 models and Moonshot's Kimi-K2 and Kimi-K3 models.
  • Help Net Security reports Z.AI allegedly distilled data from GPT-5.5 and Claude Opus 4.8 for chain-of-thought reasoning.
  • Security Affairs reports DeepSeek ran an organized campaign against Claude, GPT and Gemini between late 2024 and mid-2025.
  • Moonshot allegedly redirected extraction to a newly launched Claude model within 24 hours of its release; MiniMax allegedly used prompt injection that made Claude Code believe it was a MiniMax product (Security Affairs).
  • Core tactics: gray-market API proxy 'transfer stations' (some Taobao-marketed), account pools, shared or fraudulent premium subscriptions, VPNs, obfuscated accounts, automated provider failover, and request metadata sanitization.

Coverage timeline

  1. · 7d ago
    Cyber Security News· 72
    CISA Warns Chinese AI Firms Extract Billions of Tokens From Claude, GPT, Gemini and Grok

    CISA, NSA and FBI advisory says six Chinese AI firms extracted billions of tokens from Claude, GPT, Gemini and Grok via API proxies since late 2024.