ZeroHour
Story · 13 sources · 13 articlesfirst updated ()

US Agencies Accuse Six Chinese AI Firms of Industrial-Scale Model Distillation; Anthropic Details 200 Million Claude Exchanges

highAI safety & securityexploited in the wildimportance 84
What's new: New since the September 9 government advisory: Anthropic's September 10-11 threat intelligence report added campaign-level attribution and figures — five campaigns totaling nearly 200 million Claude exchanges, the 151-million-exchange Alibaba/Qwen campaign (May-July 2026, ~3,500 accounts, ~3M exchanges/day peak), the ~300,000-request Moonshot campaign against Opus with PLA-linked CCTV analysis,…
Merged summary · glm-5.3 · rewritten as coverage arrives

NSA, CISA and FBI advisory AA26-251A alleges DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens from Claude, GPT, Gemini and Grok since late 2024; Anthropic's follow-up report attributes nearly 200 million Claude exchanges,…

A joint advisory (AA26-251A) from NSA, CISA and FBI, issued September 9, 2026, accuses six China-based AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — of extracting billions of tokens across millions of API requests from US frontier models including Claude, GPT (reported as GPT-4/GPT-5 by SecurityWeek), Gemini and Grok (Grok 4 per SecurityWeek) since at least late 2024, likely with Chinese government awareness. Reported tactics include gray-market API proxies called 'transfer stations', fraudulent shared and bulk premium accounts, metadata sanitization, automated provider failover, and prompt injection or jailbreak-style prompts (including one that made Claude Code believe it was a MiniMax product) to force models to reveal hidden chain-of-thought reasoning; techniques were mapped to MITRE ATLAS plus novel ones like subscription exploitation. The agencies say the harvested outputs helped train DeepSeek's R1 and V3, Moonshot's Kimi-K2/K3 and Alibaba's Qwen families, dispute DeepSeek's $5.6 million training-cost claim as excluding the value of distilled data, and frame the activity as a strategic economic threat. Recommended mitigations include identity verification, monitoring of anomalous subscription-to-API ratios and 24/7 multi-IP usage, rate limiting, differential privacy, response variation or covertly serving degraded responses to suspected distillers, and cross-vendor intelligence sharing. On September 10-11, Anthropic published a threat report (covering December 2025-August 2026) detailing five distillation campaigns totaling nearly 200 million Claude exchanges: the largest, attributed to Alibaba, ran 151 million exchanges between May and July 2026 across roughly 3,500 accounts, peaking near three million exchanges per day to produce training material for Qwen (The Decoder cites Qwen 3.5, 3.6 and 3.7); a Moonshot campaign routed ~300,000 requests through 5,000 accounts over ten days, primarily targeting Opus, including PLA-linked analysis of CCTV footage; and DeepSeek reportedly routed 12.1 million exchanges to Claude Opus. Attackers used prompt tricks such as katakana-only Japanese translation requests to expose Claude's internal reasoning.

  • Advisory AA26-251A issued jointly by NSA, CISA and FBI on 2026-09-09 names six Chinese firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI
  • Alleged activity ran since at least late 2024, extracting billions of tokens from Claude, GPT, Gemini and Grok variants; agencies assess the Chinese government was likely aware
  • Tactics mapped to MITRE ATLAS plus novel techniques: 'transfer station' API proxies, account pools, bulk premium subscriptions, metadata sanitization, automated failover, prompt injection and jailbreaks to extract chain-of-thought reasoning
  • Distilled data reportedly trained DeepSeek R1/V3, Moonshot Kimi-K2/K3 and Alibaba's Qwen family; DeepSeek's disputed $5.6M training-cost figure is said to exclude the value of distilled data
  • DeepSeek allegedly ran an organized campaign against Claude, GPT and Gemini from late 2024 to mid-2025; Moonshot redirected extraction to a new Claude model within 24 hours of its launch; Z.AI reportedly distilled from GPT-5.5 and Claude…
  • Detection signals cited: 24/7 usage, multi-IP shared accounts, abnormal subscription-to-API ratios, max-quota new accounts; mitigations include identity checks, rate limits, differential privacy, response variation/noise, covert…
  • Anthropic report (2026-09-10) attributes nearly 200 million Claude exchanges across five distillation campaigns targeting agentic tool use, coding, data analysis and reasoning
  • Largest campaign attributed to Alibaba: 151 million exchanges May-July 2026 across ~3,500 accounts, peaking near 3 million exchanges per day, to train the Qwen family (The Decoder cites Qwen 3.5/3.6/3.7)

Coverage timeline

  1. · 6d ago
    GBHackers· 72
    DeepSeek, Alibaba and Chinese AI Firms Extract Billions of Tokens From U.S. AI Models

    NSA, CISA and FBI advisory AA26-251A accuses DeepSeek, Alibaba and four other Chinese AI firms of industrial-scale distillation of US frontier models.

  2. · 6d ago
    Cyber Security News· 72
    CISA Warns Chinese AI Firms Extract Billions of Tokens From Claude, GPT, Gemini and Grok

    CISA, NSA and FBI advisory says six Chinese AI firms extracted billions of tokens from Claude, GPT, Gemini and Grok via API proxies since late 2024.

  3. · 6d ago
    The Hacker News· 62
    U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

    NSA, CISA and FBI accuse Chinese AI firms including DeepSeek of industrial-scale distillation of Claude, GPT, Gemini and Grok since late 2024.

  4. · 6d ago
    Help Net Security· 70
    Chinese AI firms are siphoning capabilities from American models, CISA warns

    CISA, NSA and FBI warn Chinese AI firms including DeepSeek and Moonshot AI extracted billions of tokens from US frontier models via distillation campaigns.

  5. · 6d ago
    SecurityWeek· 84
    US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

    NSA, CISA and FBI warn Chinese AI firms including DeepSeek and Moonshot systematically extracted billions of tokens from US frontier models since late 2024.

  6. · 6d ago
    BleepingComputer· 78
    US says Chinese firms extracted billions of tokens from frontier AI models

    CISA, NSA, and FBI say six Chinese AI firms including DeepSeek industrial-scale distilled Anthropic, OpenAI, Google, and xAI frontier models.

  7. · 6d ago
    Security Affairs· 74
    US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

    NSA, CISA, and FBI accuse six Chinese AI firms including DeepSeek and Alibaba of industrial-scale distillation of US frontier models.

  8. · 6d ago
    Dark Reading· 72
    US Government Accuses Chinese AI Firms of Distilling Frontier Models

    US agencies allege Chinese AI firms covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and Grok models to cut development costs.

  9. · 6d ago
    Ars Technica · AI· 78
    Six Chinese AI firms accused of aggressively copying US frontier models

    NSA, CISA, and FBI accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation of US frontier models via API abuse.

  10. · 5d ago
    TechCrunch · AI· 78
    Anthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek

    Anthropic reports nearly 200 million Claude exchanges tied to distillation campaigns by Alibaba, Moonshot AI, and DeepSeek.

  11. · 4d ago
    Hacker News · AI· 35
    Moonshot serves Claude instead of Kimi and collects exchanges for model training

    Moonshot AI reportedly served users Anthropic's Claude instead of its own Kimi model and collected the exchanges for model training.

  12. · 4d ago
    Interconnects· 25
    Open-Source AI & Open Models Reading List

    Interconnects publishes a curated open-model reading list covering release strategy, US-China competition, adoption data, and a narrowed 4-6 month open-closed frontier gap.

  13. · 4d ago
    The Decoder· 80
    How hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data

    Anthropic's threat report details eight months of Claude misuse: AI-assisted espionage against 20+ organizations, self-rewriting malware, and Chinese labs distilling Claude via fraudulent accounts.