ZeroHour
Story · 1 source · 1 articlefirst updated ()

US Agencies Allege Six Chinese AI Firms Distilled US Frontier Models; New Community Tracker Exposes AI Training-Data Staleness

mediumAI safety & securityexploited in the wildimportance 78
What's new: The core advisory story is unchanged from the previous summary. New since September 16, 2026: a community-built Show HN tool that tracks release dates and training cutoffs for 20 models across 8 labs — a separate development unrelated to the advisory, though Alibaba and DeepSeek (two of the six accused firms) appear among the tracked labs. No reports add new allegations, named firms, or updates…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint September 9, 2026 NSA, CISA, and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation of US frontier models (Claude, GPT, Gemini, Grok), alleging billions of tokens extracted across millions…

On September 9, 2026, NSA, CISA, and FBI jointly alleged that six Chinese AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — conducted industrial-scale distillation of US frontier models, extracting billions of tokens across millions of requests from Claude, GPT, Gemini, and Grok since at least late 2024, likely with Chinese government awareness (per Ars Technica). Dark Reading frames the alleged goal as covertly reducing the firms' own model development costs. DeepSeek reportedly ran an organized campaign against Claude, GPT, and Gemini between late 2024 and mid-2025 that aided development of its R1 and V3 models, including extraction of chain-of-thought reasoning. Security Affairs adds that Moonshot redirected extraction to a newly launched Claude model within 24 hours of its release, and that MiniMax allegedly used prompt injection that made Claude Code believe it was a MiniMax product. Reported techniques included bulk procurement of premium subscriptions with fraudulent accounts, shared premium accounts, gray-market proxy 'transfer stations' to evade geo-restrictions, automated failover, and prompt injection to force models to reveal hidden chain-of-thought reasoning. The agencies recommend stronger identity verification, monitoring of anomalous usage (24/7 multi-IP account usage and abnormal subscription-to-API ratios), and covertly degrading, downgrading, or adding noise to responses served to suspected distillers, while warning these mitigations could frustrate legitimate users; Dark Reading notes the US government is pushing coordinated defenses across the AI ecosystem. In a separate development, a community-built page shared via Show HN on September 16, 2026 tracks release dates and training cutoffs for 20 current models from 8 labs (OpenAI, Anthropic, Google DeepMind, Meta, Mistral AI, Alibaba, DeepSeek, and xAI), finding that only 10 of 20 models have lab-published cutoff dates, with data available as models.json — for example, GPT-6 Astra shipped September 3, 2026 with an April 30, 2026 cutoff. The page argues web search tools paper over, but never close, training-data staleness gaps; it is unrelated to the advisory except that Alibaba and DeepSeek, two of the six accused firms, are among the tracked labs.

  • Joint NSA, CISA, and FBI advisory published September 9, 2026 alleges industrial-scale distillation of US frontier models by six Chinese AI firms.
  • Firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
  • Alleged extraction: billions of tokens across millions of requests from Claude, GPT, Gemini, and Grok since at least late 2024.
  • Ars Technica reports the activity was likely conducted with Chinese government awareness; Dark Reading frames the goal as cutting the firms' own model development costs.
  • DeepSeek allegedly ran an organized campaign against Claude, GPT, and Gemini between late 2024 and mid-2025 that aided R1 and V3 development, including chain-of-thought extraction.
  • Moonshot allegedly redirected extraction to a newly launched Claude model within 24 hours of release; MiniMax allegedly used prompt injection that made Claude Code believe it was a MiniMax product.
  • Reported techniques: bulk fraudulent premium accounts, shared premium subscriptions, gray-market proxy 'transfer stations' to evade geo-restrictions, automated failover, and prompt injection to reveal hidden chain-of-thought reasoning.
  • Recommended mitigations: stronger identity verification, anomalous-usage monitoring (24/7 multi-IP usage, abnormal subscription-to-API ratios), and covertly degrading, downgrading, or adding noise to responses for suspected distillers —…

Coverage timeline

  1. · 7d ago
    Security Affairs· 74
    US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

    NSA, CISA, and FBI accuse six Chinese AI firms including DeepSeek and Alibaba of industrial-scale distillation of US frontier models.