CISA, NSA, and FBI say six Chinese AI firms extracted billions of tokens from US frontier models in industrial-scale distillation campaign
A joint CISA, NSA, and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from US frontier models (Claude, GPT, Gemini, Grok) via millions of API requests since late 2024, likely with Chinese…
On 2026-09-09, BleepingComputer, Security Affairs, Dark Reading, and Ars Technica reported on a joint advisory from CISA, NSA, and FBI alleging that six Chinese AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — conducted industrial-scale distillation of US frontier AI models, including Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok, extracting billions of tokens across millions of API requests since at least late 2024. The agencies assess the operations likely had Chinese government awareness and represent a core development strategy that shortens Chinese development timelines and cuts frontier training costs. Reported tactics include bulk procurement of premium subscriptions with fraudulent shared accounts, gray-market proxy 'transfer stations' to evade geo-restrictions, automated failover to other providers to evade detection, and prompt injection to extract hidden chain-of-thought reasoning — including an alleged MiniMax prompt injection that made Claude Code believe it was a MiniMax product. Security Affairs reports DeepSeek ran an organized campaign against Claude, GPT, and Gemini between late 2024 and mid-2025 that aided R1 and V3 development, and that Moonshot redirected extraction to a newly launched Claude model within 24 hours of its release. The advisory recommends behavioral detection (e.g., 24/7 multi-IP account usage, abnormal subscription-to-API ratios), stronger identity verification, intelligence sharing, and covertly degrading or adding noise to responses served to suspected distillers, while warning these mitigations could frustrate legitimate users.
- Joint advisory issued by CISA, NSA, and FBI, reported 2026-09-09 by BleepingComputer, Security Affairs, Dark Reading, and Ars Technica.
- Six named Chinese firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
- Billions of tokens extracted via millions of API requests from US frontier models: Claude (Anthropic), GPT (OpenAI), Gemini (Google), and Grok (xAI).
- Extraction campaigns ran since at least late 2024; agencies assess Chinese government was likely aware and treat distillation as a core development strategy.
- Security Affairs: DeepSeek reportedly ran an organized campaign against Claude, GPT, and Gemini from late 2024 to mid-2025 that aided R1 and V3 development.
- Security Affairs: Moonshot allegedly redirected extraction to a newly launched Claude model within 24 hours of its release.
- Security Affairs: MiniMax allegedly used prompt injection that made Claude Code believe it was a MiniMax product.
- Tactics include fraudulent shared premium accounts, gray-market proxy 'transfer stations,' proxy routing to evade geo-restrictions, automated provider failover, and chain-of-thought extraction.
Coverage timelineoldest first · each row is one article
- · 6d agoUS says Chinese firms extracted billions of tokens from frontier AI models
BleepingComputer· 78
CISA, NSA, and FBI say six Chinese AI firms including DeepSeek industrial-scale distilled Anthropic, OpenAI, Google, and xAI frontier models.
- · 6d agoUS Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
Security Affairs· 74
NSA, CISA, and FBI accuse six Chinese AI firms including DeepSeek and Alibaba of industrial-scale distillation of US frontier models.
- · 6d agoUS Government Accuses Chinese AI Firms of Distilling Frontier Models
Dark Reading· 72
US agencies allege Chinese AI firms covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and Grok models to cut development costs.
- · 6d agoSix Chinese AI firms accused of aggressively copying US frontier models
Ars Technica · AI· 78
NSA, CISA, and FBI accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation of US frontier models via API abuse.