ZeroHour
Story · 4 sources · 4 articlesfirst updated ()

CISA, NSA, and FBI say six Chinese AI firms extracted billions of tokens from US frontier models in industrial-scale distillation campaign

highAI safety & securityexploited in the wildimportance 78
What's new: Initial merged summary for this story, consolidating four same-day reports (BleepingComputer, Security Affairs, Dark Reading, Ars Technica). No prior coverage to compare against; Security Affairs contributed the most specific details (DeepSeek's late-2024-to-mid-2025 campaign tied to R1/V3, Moonshot's 24-hour model redirect, MiniMax's Claude Code prompt injection), while Dark Reading's account…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint CISA, NSA, and FBI advisory accuses DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from US frontier models (Claude, GPT, Gemini, Grok) via millions of API requests since late 2024, likely with Chinese…

On 2026-09-09, BleepingComputer, Security Affairs, Dark Reading, and Ars Technica reported on a joint advisory from CISA, NSA, and FBI alleging that six Chinese AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — conducted industrial-scale distillation of US frontier AI models, including Anthropic's Claude, OpenAI's GPT, Google's Gemini, and xAI's Grok, extracting billions of tokens across millions of API requests since at least late 2024. The agencies assess the operations likely had Chinese government awareness and represent a core development strategy that shortens Chinese development timelines and cuts frontier training costs. Reported tactics include bulk procurement of premium subscriptions with fraudulent shared accounts, gray-market proxy 'transfer stations' to evade geo-restrictions, automated failover to other providers to evade detection, and prompt injection to extract hidden chain-of-thought reasoning — including an alleged MiniMax prompt injection that made Claude Code believe it was a MiniMax product. Security Affairs reports DeepSeek ran an organized campaign against Claude, GPT, and Gemini between late 2024 and mid-2025 that aided R1 and V3 development, and that Moonshot redirected extraction to a newly launched Claude model within 24 hours of its release. The advisory recommends behavioral detection (e.g., 24/7 multi-IP account usage, abnormal subscription-to-API ratios), stronger identity verification, intelligence sharing, and covertly degrading or adding noise to responses served to suspected distillers, while warning these mitigations could frustrate legitimate users.

  • Joint advisory issued by CISA, NSA, and FBI, reported 2026-09-09 by BleepingComputer, Security Affairs, Dark Reading, and Ars Technica.
  • Six named Chinese firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
  • Billions of tokens extracted via millions of API requests from US frontier models: Claude (Anthropic), GPT (OpenAI), Gemini (Google), and Grok (xAI).
  • Extraction campaigns ran since at least late 2024; agencies assess Chinese government was likely aware and treat distillation as a core development strategy.
  • Security Affairs: DeepSeek reportedly ran an organized campaign against Claude, GPT, and Gemini from late 2024 to mid-2025 that aided R1 and V3 development.
  • Security Affairs: Moonshot allegedly redirected extraction to a newly launched Claude model within 24 hours of its release.
  • Security Affairs: MiniMax allegedly used prompt injection that made Claude Code believe it was a MiniMax product.
  • Tactics include fraudulent shared premium accounts, gray-market proxy 'transfer stations,' proxy routing to evade geo-restrictions, automated provider failover, and chain-of-thought extraction.

Coverage timeline

  1. · 6d ago
    BleepingComputer· 78
    US says Chinese firms extracted billions of tokens from frontier AI models

    CISA, NSA, and FBI say six Chinese AI firms including DeepSeek industrial-scale distilled Anthropic, OpenAI, Google, and xAI frontier models.

  2. · 6d ago
    Security Affairs· 74
    US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

    NSA, CISA, and FBI accuse six Chinese AI firms including DeepSeek and Alibaba of industrial-scale distillation of US frontier models.

  3. · 6d ago
    Dark Reading· 72
    US Government Accuses Chinese AI Firms of Distilling Frontier Models

    US agencies allege Chinese AI firms covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and Grok models to cut development costs.

  4. · 6d ago
    Ars Technica · AI· 78
    Six Chinese AI firms accused of aggressively copying US frontier models

    NSA, CISA, and FBI accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation of US frontier models via API abuse.