US Agencies Accuse Six Chinese AI Firms of Industrial-Scale Model Distillation; Anthropic Details 200 Million Claude Exchanges
NSA, CISA and FBI advisory AA26-251A alleges DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI extracted billions of tokens from Claude, GPT, Gemini and Grok since late 2024; Anthropic's follow-up report attributes nearly 200 million Claude exchanges,…
A joint advisory (AA26-251A) from NSA, CISA and FBI, issued September 9, 2026, accuses six China-based AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — of extracting billions of tokens across millions of API requests from US frontier models including Claude, GPT (reported as GPT-4/GPT-5 by SecurityWeek), Gemini and Grok (Grok 4 per SecurityWeek) since at least late 2024, likely with Chinese government awareness. Reported tactics include gray-market API proxies called 'transfer stations', fraudulent shared and bulk premium accounts, metadata sanitization, automated provider failover, and prompt injection or jailbreak-style prompts (including one that made Claude Code believe it was a MiniMax product) to force models to reveal hidden chain-of-thought reasoning; techniques were mapped to MITRE ATLAS plus novel ones like subscription exploitation. The agencies say the harvested outputs helped train DeepSeek's R1 and V3, Moonshot's Kimi-K2/K3 and Alibaba's Qwen families, dispute DeepSeek's $5.6 million training-cost claim as excluding the value of distilled data, and frame the activity as a strategic economic threat. Recommended mitigations include identity verification, monitoring of anomalous subscription-to-API ratios and 24/7 multi-IP usage, rate limiting, differential privacy, response variation or covertly serving degraded responses to suspected distillers, and cross-vendor intelligence sharing. On September 10-11, Anthropic published a threat report (covering December 2025-August 2026) detailing five distillation campaigns totaling nearly 200 million Claude exchanges: the largest, attributed to Alibaba, ran 151 million exchanges between May and July 2026 across roughly 3,500 accounts, peaking near three million exchanges per day to produce training material for Qwen (The Decoder cites Qwen 3.5, 3.6 and 3.7); a Moonshot campaign routed ~300,000 requests through 5,000 accounts over ten days, primarily targeting Opus, including PLA-linked analysis of CCTV footage; and DeepSeek reportedly routed 12.1 million exchanges to Claude Opus. Attackers used prompt tricks such as katakana-only Japanese translation requests to expose Claude's internal reasoning.
- Advisory AA26-251A issued jointly by NSA, CISA and FBI on 2026-09-09 names six Chinese firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI
- Alleged activity ran since at least late 2024, extracting billions of tokens from Claude, GPT, Gemini and Grok variants; agencies assess the Chinese government was likely aware
- Tactics mapped to MITRE ATLAS plus novel techniques: 'transfer station' API proxies, account pools, bulk premium subscriptions, metadata sanitization, automated failover, prompt injection and jailbreaks to extract chain-of-thought reasoning
- Distilled data reportedly trained DeepSeek R1/V3, Moonshot Kimi-K2/K3 and Alibaba's Qwen family; DeepSeek's disputed $5.6M training-cost figure is said to exclude the value of distilled data
- DeepSeek allegedly ran an organized campaign against Claude, GPT and Gemini from late 2024 to mid-2025; Moonshot redirected extraction to a new Claude model within 24 hours of its launch; Z.AI reportedly distilled from GPT-5.5 and Claude…
- Detection signals cited: 24/7 usage, multi-IP shared accounts, abnormal subscription-to-API ratios, max-quota new accounts; mitigations include identity checks, rate limits, differential privacy, response variation/noise, covert…
- Anthropic report (2026-09-10) attributes nearly 200 million Claude exchanges across five distillation campaigns targeting agentic tool use, coding, data analysis and reasoning
- Largest campaign attributed to Alibaba: 151 million exchanges May-July 2026 across ~3,500 accounts, peaking near 3 million exchanges per day, to train the Qwen family (The Decoder cites Qwen 3.5/3.6/3.7)
Coverage timelineoldest first · each row is one article
- · 6d agoDeepSeek, Alibaba and Chinese AI Firms Extract Billions of Tokens From U.S. AI Models
GBHackers· 72
NSA, CISA and FBI advisory AA26-251A accuses DeepSeek, Alibaba and four other Chinese AI firms of industrial-scale distillation of US frontier models.
- · 6d agoCISA Warns Chinese AI Firms Extract Billions of Tokens From Claude, GPT, Gemini and Grok
Cyber Security News· 72
CISA, NSA and FBI advisory says six Chinese AI firms extracted billions of tokens from Claude, GPT, Gemini and Grok via API proxies since late 2024.
- · 6d agoU.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
The Hacker News· 62
NSA, CISA and FBI accuse Chinese AI firms including DeepSeek of industrial-scale distillation of Claude, GPT, Gemini and Grok since late 2024.
- · 6d agoChinese AI firms are siphoning capabilities from American models, CISA warns
Help Net Security· 70
CISA, NSA and FBI warn Chinese AI firms including DeepSeek and Moonshot AI extracted billions of tokens from US frontier models via distillation campaigns.
- · 6d agoUS Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
SecurityWeek· 84
NSA, CISA and FBI warn Chinese AI firms including DeepSeek and Moonshot systematically extracted billions of tokens from US frontier models since late 2024.
- · 6d agoUS says Chinese firms extracted billions of tokens from frontier AI models
BleepingComputer· 78
CISA, NSA, and FBI say six Chinese AI firms including DeepSeek industrial-scale distilled Anthropic, OpenAI, Google, and xAI frontier models.
- · 6d agoUS Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
Security Affairs· 74
NSA, CISA, and FBI accuse six Chinese AI firms including DeepSeek and Alibaba of industrial-scale distillation of US frontier models.
- · 6d agoUS Government Accuses Chinese AI Firms of Distilling Frontier Models
Dark Reading· 72
US agencies allege Chinese AI firms covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and Grok models to cut development costs.
- · 6d agoSix Chinese AI firms accused of aggressively copying US frontier models
Ars Technica · AI· 78
NSA, CISA, and FBI accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation of US frontier models via API abuse.
- · 5d agoAnthropic details distillation campaigns from Alibaba, Moonshot AI, and DeepSeek
TechCrunch · AI· 78
Anthropic reports nearly 200 million Claude exchanges tied to distillation campaigns by Alibaba, Moonshot AI, and DeepSeek.
- · 4d agoMoonshot serves Claude instead of Kimi and collects exchanges for model training
Hacker News · AI· 35
Moonshot AI reportedly served users Anthropic's Claude instead of its own Kimi model and collected the exchanges for model training.
- · 4d agoOpen-Source AI & Open Models Reading List
Interconnects· 25
Interconnects publishes a curated open-model reading list covering release strategy, US-China competition, adoption data, and a narrowed 4-6 month open-closed frontier gap.
- · 4d agoHow hackers used Claude for missiles, drone swarms, and surveillance, while Chinese labs mined it for training data
The Decoder· 80
Anthropic's threat report details eight months of Claude misuse: AI-assisted espionage against 20+ organizations, self-rewriting malware, and Chinese labs distilling Claude via fraudulent accounts.