Anthropic detects large-scale distillation attacks from three Chinese AI labs

23/02/2026

Anthropic has identified large-scale campaigns by DeepSeek, Moonshot and MiniMax to fraudulently extract capabilities from its Claude model and use them to train their own systems.

Anthropic detects large-scale distillation attacks from three Chinese AI labs

Anthropic has revealed that three Chinese artificial intelligence laboratories —DeepSeek, Moonshot and MiniMax— carried out organised campaigns to illicitly extract capabilities from its Claude model using a technique known as distillation. This practice involves training a less capable model on the outputs generated by a more advanced one. Although distillation is a common and legitimate training method in the industry, its fraudulent use allows third parties to acquire advanced capabilities in far less time and at a fraction of the cost of independent development.

According to the company, the three campaigns jointly generated more than 16 million conversations with Claude through approximately 24,000 fraudulent accounts, in clear violation of Anthropic's terms of service and regional access restrictions. To circumvent the commercial block preventing access from China, the laboratories used intermediary services that resold access to Claude's API, operating through networks of fake accounts that mixed distillation traffic with legitimate requests to hinder detection.

Each campaign had distinct objectives. DeepSeek, with over 150,000 recorded exchanges, focused on generating step-by-step reasoning data and obtaining responses that bypassed political censorship. Moonshot, with more than 3.4 million exchanges, primarily targeted agentic reasoning capabilities, tool use and computer vision. MiniMax was the largest operation, with over 13 million exchanges aimed at agentic coding and tool orchestration. In this last case, Anthropic detected the campaign while it was still active and observed that when it launched a new model, MiniMax redirected nearly half its traffic towards it within 24 hours.

Anthropic warns that models obtained through illicit distillation lack the safety systems that American companies incorporate to prevent dangerous uses, such as the development of bioweapons or cyberattacks. The company has announced measures including improved detection systems, strengthened access controls and intelligence sharing with other laboratories and authorities. However, it stresses that no single company can solve this problem alone and calls for a coordinated response from the industry, technology infrastructure providers and policymakers.

Key points

  • Anthropic detected fraudulent campaigns by DeepSeek, Moonshot and MiniMax to extract Claude's capabilities.
  • The three operations generated over 16 million conversations from around 24,000 fake accounts.
  • They used distillation: training their own models on the outputs of a more advanced model.
  • To gain access, they bypassed China's commercial block using intermediary services and fraudulent account networks.
  • MiniMax was the largest campaign, with 13 million exchanges; it redirected its traffic to Anthropic's new model within 24 hours.
  • Illicitly distilled models do not incorporate the safety systems of the original.
  • Anthropic calls for a coordinated response from the industry, infrastructure providers and governments.

Related AI

Anthropic

AI systems you can rely on

Anthropic develops reliable and interpretable artificial intelligence systems through a scientific approach to safety. The company integrates advanced research and multidisciplinary collaboration to ...

Claude

Create with Claude

Claude is a conversational AI system from Anthropic designed to process natural language and images, providing analysis, logical reasoning, code generation, and multilingual communication under ...

DeepSeek

Versatile and Efficient Open-Source AI

DeepSeek provides an open-source artificial intelligence model that includes mathematical computations, large and visual language models, APIs, and an advanced chatbot. It optimizes multitasking, ...

Minimax

Multimodal artificial intelligence platform

Company specialized in AI foundation models that develops multimodal technologies for text, audio, image, video and music processing. Provides API for developers and open source ...

Moonshot AI

Advanced Models for Reasoning and Analysis

Beijing-based AI company develops large language models. Its technology includes reasoning, coding, and multimodal analysis. Kimi, its model and chatbot, handles large volumes of text and visual ...

Lastest news

Trustpilot
This website uses technical, personalization and analysis cookies, both our own and from third parties, to facilitate anonymous browsing and analyze website usage statistics. We consider that if you continue browsing, you accept their use.